Skip to content
View richeeta's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.

Block or report richeeta

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
richeeta/README.md

I'm an offensive security engineer and security researcher at Pindrop.

Talks

Siri-ously Leaky: Overlooked Attack Surfaces Across Apple's Ecosystem

  • First delivered at DEF CON 33 Main Stage (August 2025)
  • Updated presentation delivered at HOU.SEC.CON 2025 (September 2025)

Hacker v. Triage: Inside the Bug Bounty Battleground

  • Co-presented with @deni at DEF CON 33 Bug Bounty Village (August 2025)

Research & Contributions

  • ≥ 21 credited reports from Apple, including:
    • CVE-2024-44235
    • CVE-2025-24198
    • CVE-2025-24225
    • CVE-2025-30468
    • CVE-2025-24133
    • CVE-2025-43452
    • CVE-2026-20655
    • Multiple web server security acknowledgements throughout 2024 and 2025
  • Top 25 Researcher in OpenAI's Bug Bounty Program (2025)
  • Multiple security acknowledgements from Microsoft Security Response Center, Google VRP, BBC
  • Authored the Platform-Specific Guidance for iOS and iPadOS in OWASP's Mobile Application Security Cheat Sheet
  • CompTIA Subject Matter Expert (2022, 2023, 2025)
  • Cybersecurity instructional specialist for Rice University's cybersecurity boot camp (2022–2024)

Pinned Loading

  1. AIAuditor AIAuditor Public archive

    Lightweight BApp that seamlessly integrates powerful LLM-scanning capabilities into Burp's built-in Scanner with improved accuracy. Supports the latest LLMs from OpenAI (gpt-4o, o1), Anthropic (Cla…

    Java 40 11

  2. DEFCON33-Siriously-Leaky DEFCON33-Siriously-Leaky Public

    Slides and PoCs for my DEF CON 33 & HOU.SEC.CON 2025 talk on overlooked attack surfaces across Apple's ecosystem.

    Python 8 3

  3. 0xGUIDScanner 0xGUIDScanner Public

    Burp Suite Pro extension for finding insecure UUIDs (predictable, reversible, or MAC-based) in HTTP flows

    Java 1

  4. ipatool ipatool Public

    Go 1