hackwither_

About

I break AI agents at work, and teach teenagers to hack outside it.

I started early: at 16 I found a government system exposing personal and financial data of ~399k Indian officers and reported it to NCIIPC, then watched it stay exposed after the acknowledgement (what happened). Today I’m a Security Research Engineer at APISec Research Labs, finding where AI agents and the protocols around them break.

Outside work, I make security content for teenagers on Instagram (70.1K followers), run Threat Model Thursdays, and volunteer as a NICE Cybersecurity Career Ambassador. I’ve represented young people on cybersecurity policy with the UN IGF Dynamic Teen Coalition. All of it is for the same thing: a cyberspace that’s liveable for all.

Portrait of Bandana Kaur

Roles

2025–nowSecurity Research Engineer, APISec Research Labs
2024–nowIndependent security researcher, hackwither
2024–nowNICE Cybersecurity Career Ambassador (volunteer), NIST
2026Research Fellow, SPAR (Supervised Program for Alignment Research) · LLM guardrail robustness, constitutional classifiers, formal verification for NLP safety systems
2025Board Member and Cybersecurity Lead, UN IGF Dynamic Teen Coalition
2024Guest lecturer at government CISO training program, Indian Institute of Public Administration · OSINT and social engineering

Recognition

2026Two CVE IDs assigned, CVE Program (MITRE) · vulnerabilities in MCP server implementations, records pending publication
2026#17, Top 35 Ethical Hacking Influencers worldwide, FeedSpot
2026Distinction Award, GTBIT · international research and speaking
2025#26, Top 35 Ethical Hacking Influencers worldwide, FeedSpot
2025Most Engaged Delegate, 12th International Youth Conference, New York · International Organisation of Youth
2025Certificate of Appreciation, Women in Cyber Security Middle East · Black Hat MEA panel
2025Ambassador of the Month (April 2025), NIST NICE · live sessions reaching 2,000+ students
2024Special Memento, awarded twice, Indian Institute of Public Administration · government CISO training
2024Certificate of Appreciation, U.S. Department of Education · responsible vulnerability disclosure

Work

  • Research: two arXiv preprints, on what AI red-team evaluations can prove and BOLA in bug bounty disclosures. A third paper is embargoed pending coordinated disclosure.
  • Vulnerability research: forged A2A control metadata in Google’s Agent Development Kit, security-label forgery in Microsoft’s FIDES middleware, argument injection in MCP servers (featured in AI Cyber Magazine, Fall 2026).
  • Disclosures: two reserved CVEs in MCP server implementations; a disclosure to the U.S. Department of Education, acknowledged and appreciated by its CISO; and, at 16, my report to India’s NCIIPC covering data of ~399k government officers (what happened next).
  • Talks: three tracks at Black Hat MEA (technical briefing, campus keynote, WiCSME panel); a keynote at Gautam Buddha University; UNIDIR AISE26 in Geneva, GISEC Global in Dubai (live hacking demo, panel and fireside chat), the NIST FISSEA forum, BSides Jaipur.
  • REAP and reap-range: open-source agent recon tooling.