> NAME security-tilted builder · chess on the clock · flag chaser
> LOC Dubai
> ROLE Senior AI Engineer · Security @ Deriv
> DEGREE CS — BITS Pilani, Dubai Campus (’21–’25)
> SIDE QUESTS CVEs · HackerOne · agent / MCP hardening · CTFs
If you’re human: I like systems that misbehave in interesting ways, agent boundaries, and competitions where the clock is honest.
Longer form (selected work, research writeups, receipts): rushit-portfolio-theta.vercel.app
| Go | You’ll find |
|---|---|
| Published CVEs | Electron · OpenImageIO — coordinated disclosure |
| Scoreboard exports | CTF numbers, vendor finals, no slideshow |
| What I actually do | Work, OSS, bounty — one breath each |
| Upstream merges | VulnHunter · DefenseClaw |
| Stack + shields | Boring but honest |
| Say hi | Mail · LinkedIn · portfolio |
| ID | Target | Signal |
|---|---|---|
| CVE-2026-70606 | Electron | Session-isolation / cache reuse via ProtocolResponse.url · Medium · CVSS 5.9 · CWE-668 |
| CVE-2026-59956 | OpenImageIO | Heap-buffer-overread in IFF decoder when Z-buffer is set · CWE-125 |
[+] cat ./ctf/ledger.tsv — merged results
| When | What | Signal |
|---|---|---|
| 2026 | HTB Project Nightfall · Global Cyber Skills Benchmark | Global 23rd · UAE 3rd · 122 / 126 chals · 75,200 pts |
| 2026 | HTB Cyber Apocalypse | 294 / 6,744 teams · 83 / 136 chals · 3-person team |
| 2026-02 | Snyk Fetch the Flag | 56 / 1539 · 2100 pts · 6 / 22 chals |
| 2025-10 | GITEX — UAE CSC CTF (CTF.ae world) | 3rd · finals · tracks: web, pwn, DFIR, RE, coding, AI/ML-adjacent |
| 2025-08 | Kaspersky CTF · 24h (UAE CSC adjacency) | 12 / 415 (MEA, TR, Africa) · 2nd UAE · 660 pts · web · RE · crypto · forensics · pwn · AI |
| — | Dubai Police CTF · academic track | 1st UAE |
| — | Internal AI / agent build-off | 2nd · $5k · NL → agents + tools · OpenAI Agents SDK |
[+] ls ./ctf/archive/ — older loot
- NASA Space Apps 2023 — UAE winner · global nominee
- IEEE Xtreme 17.0 — UAE section lead
- GDG on Campus BITS Dubai — tech lead
- Chess — FIDE rated · NYU inter-college 3rd · Lichess @rush21
- Paper — ChatGPT and the Social Media Echo: A Sentiment Analysis (MoSICom 2023)
- Past gigs — JetSynthesys · Cybage · Force Motors
| Bucket | Contents |
|---|---|
| 9–5-shaped | Senior AI Engineer in Security @ Deriv — agent-security controls, supply-chain defenses, SOC / AI-assisted testing, DLP, anomaly detection. |
| Vuln research | Coordinated disclosure into upstream (Electron, OpenImageIO). Niche over noise. |
| Public goods | LobsterLock — host-level policy layer for autonomous agents (OpenClaw runtime boundary: cmd / net / fs). DefenseClaw — scan and govern agent surfaces: skills, MCP, tool calls. |
| Solo queue | HackerOne — real bounties, real scopes, real consequences. |
| Repo | What landed |
|---|---|
| Capital One / VulnHunter#21 | Fixed repository-basename collisions in batch scans — preserve owner/repo identity across checkout, logs, results, resume state. |
| Cisco AI Defense / DefenseClaw | Structured network-egress telemetry: query filters, blocked-call counts, OTel counters, optional Splunk forwarding (#58, #86). |
Languages: Python · Java · C / C++ · Go · TypeScript · SQL
AI / agents: RAG · evaluation · OpenAI / Anthropic · LangChain · agent guardrails
Security: SOC · DLP · LLM/agent abuse cases · vuln research · automation without theater
Backend & data: FastAPI · Flask · Spring · Postgres · MySQL · SQL Server · Neo4j · vector stores · Kafka · RabbitMQ · Pub/Sub
Platform: Docker · Linux · Git
palesharushit@gmail.com · f20210010@dubai.bits-pilani.ac.in · LinkedIn · Portfolio
Good DMs: odd agentic trust bugs, CVE / disclosure edge cases, CTF war stories, bounty weirdness, chess panic moments.
This README’s threat model: markdown injection (you), recruiter copy-paste (them), and my future self forgetting to update the TSV.



