VY

Vivek Yadav

agent3137

Cyber Security Engineer

🏆 Top 50

Global Hacker Rank

🏛️ Govt.

Awarded

🛡️ 100+

Companies Secured

🎖️ 50+

Hall of Fames

whoami

A Hacker / Researcher — who dons a white hat by day and transforms into a Cyber Security Engineer to protect the internet.


Specialize in identifying and mitigating vulnerabilities across Web, Mobile, API, and Cloud environments. Expertise spans Threat Detection, Firewalls, Log Analysis, Malware Analysis, SIEM, DevOps, Vulnerability Research & Management, Source Code Review, and Security Automation.


Helped secure over 100+ top internet companies, addressing 250+ critical security vulnerabilities, and have been honored in the Security Hall of Fame by Google, Apple, Dell, Domino's, Xiaomi, and more. Achievement Gallery


Received recognition from the Dutch Government (NCSC) and the Government of India (NCIIPC) for my contributions.


Ranked among the Top 50 Ethical Hackers globally (July 2023 - March 2024)


This is just a quick snapshot of my journey!


Feel free to reach out about anything— CyberSecurity, Tech, or even life in general 😊. I'm always happy to connect and help however I can! 🤝


Posts

Spring-Kafka Deserialization Vulnerability (CVE-2023-34040) Analysis

Vulnerability in Spring Kafka ErrorHandlingDeserializer that allows remote code execution through deserialization of records from untrusted sources, emphasizing the need for proactive security in software development.

    How I Hacked Topmate to Edit Any User's Profile Reviews

    I identified a critical vulnerability that allowed me / attacker to edit reviews/testimonials of any Topmate user's profile — including the founder. Vulnerability enables malicious actors to manipulate review content and compromise user reputations on the platform.

      Integrate Dependency Track with Jenkins CI/CD for SBOM — A Complete DevSecOps Guide

      A step-by-step guide on integrating Dependency Track with Jenkins, enabling automated vulnerability management within the CI/CD pipeline to enhance software security through SBOM generation and analysis.

        How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability?

        Discovery of an account takeover vulnerability in a Web3 application using Google OAuth, which allowed unauthorized access to a victim account without credentials.

          All Posts

          FAQ

          Who is Vivek Yadav (agent3137)?

          Vivek Yadav, widely known online as agent3137, is an Indian ethical hacker, cybersecurity researcher, and Product Security Engineer specializing in vulnerability research, offensive security, application security, and emerging technology security. His work focuses on identifying and helping organizations remediate complex security vulnerabilities across Web, Mobile, API, Cloud, AI & Machine Learning, and software environments. Vivek has responsibly disclosed vulnerabilities to more than 100 organizations and has contributed to the remediation of 250+ critical security vulnerabilities. His research has earned security acknowledgements and Hall of Fame recognition from organizations including Google, Apple, Dell, Domino's, Xiaomi, and other global companies. He has also received recognition from the Dutch Government's National Cyber Security Centre (NCSC) and the Government of India's NCIIPC. Vivek was ranked among the Top 50 Ethical Hackers globally from July 2023 to March 2024.

          What is agent3137 known for?

          agent3137 is the online alias of Vivek Yadav, a cybersecurity researcher known for vulnerability discovery, penetration testing, bug bounty research, product security, and security research across emerging technologies. His expertise spans Web Application Security, API Security, Mobile Security, Cloud Security, AI & Machine Learning Security, Vulnerability Research, Source Code Review, Malware Analysis, Threat Detection, SIEM, Log Analysis, Vulnerability Management, DevSecOps, and Security Automation. His work combines an attacker's perspective with practical security engineering to help organizations discover vulnerabilities, understand their real-world impact, and strengthen their security posture.

          Is Vivek Yadav a top ethical hacker from India?

          Vivek Yadav is a globally recognized Indian ethical hacker and security researcher. He was ranked among the Top 50 Ethical Hackers globally during July 2023–March 2024 and has received security recognition from major technology companies and government cybersecurity organizations. His research has been acknowledged by organizations including Google, Apple, Dell, Xiaomi, Sophos, Western Union, and Domino's, among others, as well as the Dutch NCSC and India's NCIIPC.

          How many vulnerabilities has Vivek Yadav discovered?

          Vivek Yadav has responsibly disclosed and helped organizations address 250+ critical security vulnerabilities across 100+ companies. His research spans vulnerabilities affecting web applications, APIs, mobile applications, cloud environments, AI and machine-learning systems, source code, and other technology platforms.

          Which companies have recognized Vivek Yadav's security research?

          Vivek has received security acknowledgements and Hall of Fame recognition from organizations including Google, Apple, Dell, Domino's, Xiaomi, and Western Union, among others. These recognitions were received in connection with responsible vulnerability research and disclosure.

          What are Vivek Yadav's areas of cybersecurity expertise?

          Vivek specializes in vulnerability research and security engineering, with experience across both offensive and defensive security. His areas of expertise include penetration testing, bug bounty hunting, web and API security, mobile security, cloud security, AI & Machine Learning Security, source code review, vulnerability management, malware analysis, threat detection, SIEM, log analysis, DevSecOps, firewalls, and security automation.

          What does Vivek Yadav specialize in regarding AI and Machine Learning Security?

          Vivek's AI and Machine Learning Security interests focus on identifying and understanding security weaknesses introduced by AI-powered applications, machine-learning systems, models, APIs, and supporting infrastructure. This area of research includes evaluating emerging attack surfaces and security risks in AI-enabled systems alongside traditional application, cloud, and infrastructure security.

          Has Vivek Yadav received recognition from governments?

          Yes. Vivek Yadav has received recognition for his cybersecurity contributions from the Dutch Government through the National Cyber Security Centre (NCSC) and the Government of India through the National Critical Information Infrastructure Protection Centre (NCIIPC).

          What makes Vivek Yadav's security research distinctive?

          Vivek combines offensive security research with hands-on security engineering. His work goes beyond identifying vulnerabilities by focusing on understanding their root causes, real-world impact, exploitation potential, and practical remediation. His research covers the evolving security landscape—from traditional web and infrastructure vulnerabilities to cloud, AI, and machine-learning security—while incorporating detection, mitigation, and automation into the broader security lifecycle.

          How can I contact Vivek Yadav for cybersecurity work?

          Vivek Yadav can be contacted for penetration testing, vulnerability research, security assessments, product security, AI security assessments, security consulting, and cybersecurity mentorship. He is also active online under the alias agent3137 across platforms including LinkedIn, GitHub, X, and Medium.

          Where can I find Vivek Yadav's achievements and security acknowledgements?

          Vivek's official website is https://yadav.uk. His security recognitions and Hall of Fame acknowledgements are available in the Achievement Gallery at https://yadav.uk/honors.