Destawell is a cybersecurity research organization founded by Niranj R. Mahaswar (Founder, Lead Security Researcher) and Shifana (Co-Founder, Brand Strategy).
We operate at the intersection of Android penetration testing infrastructure, LLM safety validation, and automated mobile red team deployments. Our research and tooling are purpose-built for Termux, Kali NetHunter, and ARM64-based mobile environments, enabling no-root offensive security workflows where traditional desktop tooling fails.
Mission: To democratize mobile-first offensive security through stable, open-source, and automation-ready tooling.
Discovered and disclosed a path traversal / zip-slip vulnerability in termux-sync.
| Detail | Value |
|---|---|
| Severity | CVSS 7.1 (High) |
| Weakness | CWE-22 (Path Traversal) |
| CVE | CVE-2026-86046 |
| Advisory | GHSA-259w-wmqg-fp76 |
| Status | Patched upstream in v1.2.4 |
A full technical writeup is published, covering root cause, exploitation path, and the fix.
Active researcher on NASA's VDP, conducting vulnerability research on Earthdata Search and related NASA properties. This work was formally recognized with a Letter of Recognition from NASA, signed by Kelvin Taylor, Senior Agency Information Security Officer, NASA OCIO (September 2026).
Identified a safety alignment bypass in Gemini 2.5 Pro that resulted in the generation of functional exploit primitives for CVE-2023-32233 — a Linux kernel race condition in nf_tables.
Comparative validation was performed against Claude 3, GPT-4o, Llama 3, and GitHub Copilot, all of which demonstrated correct refusal behavior under the same prompts.
| Detail | Value |
|---|---|
| Vulnerability context | CVE-2023-32233 — Linux kernel nf_tables use-after-free |
| Finding | LLM safety alignment bypass — exploit code generation |
| Disclosure | Google IssueTracker #889286 |
| Reported to | Google AI Vulnerability Reward Program (VRP) |
| Final determination | Marked out of scope — model behavior |
| Documentation | Public case study, disclosure complete |
This research contributes to the ongoing discourse on LLM security, AI red teaming, and generative AI safety alignment.
All Destawell tools are engineered for Termux on Android ARM64, with a focus on environment stability, toolchain portability, and automation.
| Tool | Primary Function | Environment |
|---|---|---|
| Termux-fixer | Automated error resolution and environment stabilization for Termux | Termux |
| Kali-Termux-Pro | No-root Kali Linux toolchain deployment and management on Android | Termux / ARM64 |
| Wraith-Scanner | Lightweight, fast network discovery and reconnaissance for mobile ops | Termux |
| Kali_Critic | Output stream parsing and analysis for Kali Linux tools | Kali / Termux |
|
Niranj R. Mahaswar Founder, Lead Security Researcher & Developer Security Researcher · AI Red Teamer · Certified LLM Security Professional (CLLMSP) · Android Pentesting · Termux & Kali NetHunter · CVE Research · NASA VDP · Google VRP GitHub • LinkedIn |
Shifana Co-Founder & Brand Strategy Brand Architecture · Community & Communications · Research Operations |
Lead Researcher Certified: Certified LLM Security Professional (CLLMSP) — issued by Red Team Leaders (Founder: Joas A. Santos), July 16, 2026.
Verification: https://courses.redteamleaders.com/exam-completion/6561111759bddf91
Expertise validated: LLM Security, Prompt Injection Defense, Jailbreak Prevention, AI Red Teaming, LLM Vulnerability Assessment.
- Research & Disclosures:
research@destawell.io - Community & General:
community@destawell.io - Official Instagram: @destawell_off