TumarOne platform (official channel)
Open in Telegram
Platform for rewarding the discovery of vulnerabilities in information systems and resources. Platform: https://tumar.one Support: @TumarOneSupportBot Queries: info@tumar.one
Show moreThe country is not specifiedThe category is not specified
290
Subscribers
No data24 hours
+77 days
+2930 days
Data loading in progress...
Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
October '26Oct '26
October '26
+8
in 0 channels
September '26
+30
in 1 channels
Get PRO
August '26
+13
in 0 channels
Get PRO
July '26
+8
in 0 channels
Get PRO
June '26
+3
in 0 channels
Get PRO
May '26
+13
in 1 channels
Get PRO
April '26
+19
in 2 channels
Get PRO
March '26
+237
in 4 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 07 October | 0 | |||
| 06 October | +2 | |||
| 05 October | 0 | |||
| 04 October | +2 | |||
| 03 October | 0 | |||
| 02 October | 0 | |||
| 01 October | +4 |
Channel Posts
Season IV Leaderboard
Right after KazHackStan, it's time to celebrate the Top 3 of the final season of the year, 2026 Season 4!
š„ Timur
š„ KUFFO
š„ bvtyr
Thank you to everyone! 2027 Season 1 runs from October to December, and we can't wait to see you at the top š
Hunt Now š
| 2 | š KazHackStan 2026 аŃŃŃŠ½Š“аŅŃ TUMAR.ONE жаŃŃŃŃŠ½ŃŅ£ ŅÆŠ·Š“ŃŠŗ 10 багŃ
Š°Š½ŃŠµŃŃ Š±ŠµŠ»Š³ŃŠ»Ń болГŃ!
ŅŠ°ŃŃŃŃŃŃŠ»Š°ŃŠ“Ń Š½ÓŃŠøŠ¶ŠµŠ»ŠµŃŃŠ¼ŠµŠ½ ŅұŃŃŃŅŃŠ°Š¹Š¼ŃŠ·! Ņ®Š·Š“ŃŠŗ онГŃŅŠæŠµŠ½ каŃŃŃŠµŠ»ŃГен ŃŠ°Š½ŃŃŃŅ£ŃŠ· š
š
29ā30 ŅŃŃŠŗŅÆŠ¹ŠµŠŗ
š ŠŃŃŠ°Š½Š°, Š¢ÓŃŠµŠ»ŃŃŠ·Š“ŃŠŗ ŃŠ°ŃайŃ
š kazhackstan.com
š ŠŠæŃеГелена ГеŃŃŃŠŗŠ° Š»ŃŃŃŠøŃ
багŃ
Š°Š½ŃŠµŃов TUMAR.ONE на KazHackStan 2026!
ŠŠ¾Š·Š“ŃŠ°Š²Š»Ńем ŃŃŠ°ŃŃŠ½ŠøŠŗŠ¾Š² Ń ŃŠµŠ·ŃŠ»ŃŃŠ°Ńами! ŠŠøŃŃŠ°Š¹Ńе каŃŃŃŠµŠ»Ń, ŃŃŠ¾Š±Ń ŃŠ²ŠøŠ“еŃŃ Š²ŠµŃŃ ŃŠ¾Šæ-10 š
š
29ā30 ŃŠµŠ½ŃŃŠ±ŃŃ
š ŠŃŃŠ°Š½Š°, ŠŠ²Š¾ŃŠµŃ ŠŠµŠ·Š°Š²ŠøŃимоŃŃŠø
š kazhackstan.com
š The TUMAR.ONE top 10 bug hunters at KazHackStan 2026 have been announced!
Congratulations to everyone who made the list! Swipe to see the full top 10 š
š
September 29ā30
š Astana, Palace of Independence
š kazhackstan.com | 135 |
| 3 | Freedom Holding Corp. Raises the StakesĀ
The moment so many of you have been waiting for: a reward raise! š°
But that's not all:
šÆ +10 new wildcard targets, so there is plenty of room to explore
š Updated program rules: please read them carefully before you unleash your agents and tools, so your reports don't get rejected!
Have fun catching those vulnerabilities! šāāļø
Start Now š | 1 518 |
| 4 | August was a reminder that old security habits die hard.
Ā
SQL injections in REST APIs and CMS cores, unverified digital signatures handing over full account takeovers, and .git repositories left wide open in web roots. Nearly 85% of critical findings this month boiled down to two simple mistakes: trusting client-supplied input and leaving exposed metadata in the web root.
Ā
Full breakdown - in the cards above. š
Ā
Stay ahead with tumar.one š | 277 |
| 5 | https://app.zoom.us/wc/84211805294/join?ref_from=launch&tk=2SOFr38VyLs_u6GW0JWR8qhh14WRaSyYZ_XB3f1HZG8.DQkAAAATm2osbhZBcThRUWh6T1JkV21FUGNMel9iWjN3AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&pwd=7hbXhrukYKn6a6NaLMDAEfZ78PvmQq.1&_x_zm_rtaid=2iUT17-QRZyZ145piIe4TA.1789476953924.c0798a40d2a505eaa7e3f55decfe1fef&_x_zm_rhtaid=891&fromPWA=1 | 1 |
| 6 | Limited time only! š„
Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT
September is National Cybersecurity Month in Kazakhstan, and Kcell is marking it in the way researchers appreciate most.
From September 1 to 30, the maximum reward for an eligible critical vulnerability on the Tumar.One platform doubles to 1,000,000 KZT. The scope stays wide open: all Kcell and activ domains and subdomains.
Reports must be submitted by September 30. Payouts follow the program terms: the reward applies to a confirmed vulnerability that meets the program conditions, and the final amount is set on triage.
Start hunting! | 1 724 |
| 7 | š New on Tumar.One: Report Limits
Ā
We are rolling out report submission limits across the platform.
Ā
Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down.
Ā
Once a report moves out of New status, a slot opens up and you can submit again.
Hunt smart! | 297 |
| 8 | š New on Tumar.One: Report Limits
Ā
We are rolling out report submission limits across the platform.
Ā
Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down.
Ā
Once a report moves out of New status, a slot opens up and you can submit again.
Hunt smart. | 1 |
| 9 | Hey researcher š
Ā
We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together over 6,000 attendees, top security researchers, and leading experts in information security.
Ā
The Top 10 researchers of Tumar.One will be invited on stage at KazHackStan - where they will be awarded with merch and named awards!
Ā
Reports are accepted through and including September 15th.
Ā
š Exclusive Promo Code
8DNLG0SN3B
Ā
50% discount on tickets - limited to 50 users. First come, first served. | 266 |
| 10 | KazHackStan 2026 Executive Sponsor - Tumar.One š„
Tumar.One - ŠŃŃŠ°Š»ŃŅ ŠŠ·ŠøŃГаŅŃ 4 000-нан аŃŃŠ°Š¼ ŃŃŠøŠŗŠ°Š»ŃŅ Ń
Š°ŠŗŠµŃŠ“Ń Š±ŃŃŃŠŗŃŃŃŠµŃŃŠ½ ең ŃŃŃ Š±Š°Š³-Š±Š°ŃŠ½ŃŠø плаŃŃŠ¾ŃмаŃŃ.
ŠŠ»Š°ŃŃŠ¾Ńма CyberKumbez ŅÆŃŃŠ½ ŠµŃŠµŠæŃŠµŃŠ“Ń ŅŠ°Š±ŃŠ»Š“Š°Ń Š¼ŠµŠ½ Š¼Š¾Š“ŠµŃŠ°ŃŠøŃŠ»Š°ŃŠ“Ń ŅŠ°Š¼ŃамаŃŃŠ· ŠµŃŠµŠ“Ń, ŃŠ¾Š½Š“ай-Š°Ņ 2027 Š¶ŃŠ»ŅŃ ŠŗŠøŠ±ŠµŃŅŠ°ŃŃŠæŃŃŠ·Š“ŃŠŗ Š±Š¾Š¹ŃŠ½Ńа ICO Ń
алŃŅŠ°ŃалŃŅ Š¾Š»ŠøŠ¼ŠæŠøŠ°Š“Š°ŃŃŠ½Š° ŅŠ°Š·Š°ŅŃŃŠ°Š½ ŅŅ±ŃŠ°Š¼Š°ŃŃŠ½ ұлŃŃŃŅ ŃŃŃŠŗŃŠµŃŠ“ен Ó©ŃŠŗŃŠ·Ń ŅÆŃŃŠ½ T1CTF плаŃŃŠ¾ŃмаŃŃŠ½ ұŃŃŠ½Š°Š“Ń.
KazHackStan 2026-ŅŠ° ŅŠ¾Š»Š“Š°Ń ŠŗÓ©ŃŃŠµŃŠŗŠµŠ½Ń ŅÆŃŃŠ½ Tumar.One-ŅŠ° алŅŃŃŃŠ¼ŃŠ·Š“Ń Š±ŃŠ»Š“ŃŃŠµŠ¼ŃŠ· š
KazHackStan 2026 Executive Sponsor - Tumar.One š„
Tumar.One - ŠŗŃŃŠæŠ½ŠµŠ¹ŃŠ°Ń баг-Š±Š°ŃŠ½ŃŠø плаŃŃŠ¾Ńма ЦенŃŃŠ°Š»Ńной ŠŠ·ŠøŠø, Š¾Š±ŃŠµŠ“инŃŃŃŠ°Ń более 4 000 ŃŃŠøŃнŃŃ
Ń
Š°ŠŗŠµŃŠ¾Š².
ŠŠ»Š°ŃŃŠ¾Ńма Š¾Š±ŠµŃŠæŠµŃŠøŠ²Š°ŠµŃ ŠæŃŠøŃм Šø Š¼Š¾Š“ŠµŃŠ°ŃŠøŃ Š¾ŃŃŃŃŠ¾Š² Š“Š»Ń CyberKumbez, а ŃŠ°ŠŗŠ¶Šµ ŠæŃŠµŠ“оŃŃŠ°Š²Š»ŃŠµŃ ŠæŠ»Š°ŃŃŠ¾ŃŠ¼Ń T1CTF Š“Š»Ń Š½Š°ŃŠøŠ¾Š½Š°Š»Ńного Š¾ŃбоŃа в ŃŠ±Š¾ŃнŃŃ ŠŠ°Š·Š°Ń
ŃŃŠ°Š½Š° на ŠŠµŠ¶Š“ŃŠ½Š°ŃоГнŃŃ Š¾Š»ŠøŠ¼ŠæŠøŠ°Š“Ń ŠæŠ¾ ŠŗŠøŠ±ŠµŃŠ±ŠµŠ·Š¾ŠæŠ°ŃноŃŃŠø ICO 2027.
ŠŠ»Š°Š³Š¾Š“Š°ŃŠøŠ¼ Tumar.One за ŠæŠ¾Š“Š“ŠµŃŠ¶ŠŗŃ KazHackStan 2026 š
KazHackStan 2026 Executive Sponsor - Tumar.One š„
Tumar.One is Central Asiaās largest bug bounty platform, bringing together more than 4,000 ethical hackers.
The platform handles report submission and moderation for CyberKumbez and also provides the T1CTF platform for Kazakhstanās national selection process for the team that will represent the country at the 2027 International Cybersecurity Olympiad (ICO).
We thank Tumar.One for supporting KazHackStan 2026 š | 193 |
| 11 | The vulnerabilities in June and July weren't clever...
Ā
Because they didn't need to be. Unverified signatures, client-supplied prices, open Redis instances, outdated CMS handing out root shells. 89% of critical findings this cycle came from systems that simply trusted the wrong input.
Ā
This digest covers June and July combined. Full breakdown - categories, hunter checklist, developer checklist - in the cards above. š
Ā
Stay tuned tumar.one š | 260 |
| 12 | Important Rules Update
Ā
We have updated the Tumar.One platform rules - and there are quite a few changes.š„
Ā
Before your next submission, please make sure you're up to date.
Ā
š check here. | 237 |
| 13 | May broke the pattern.
For two months, the story was the same - .env files, debug modes, open databases. You know, basic negligence. In May, the attack surface shifted: AI infrastructure, secrets buried in React bundles, JWT confusion across microservices, and fresh CVEs being weaponized the same week they drop.
Full breakdown - top incident categories, critical cases, and checklists for both hunters and developers - all in the cards above. š
Stay tuned with tumar.one š | 245 |
| 14 | 2026 Season 3 is over!
Here are the hunters who came out on top:
š„ mukh4w
š„ nov3mber
š„ plrF
Thank you all for the relentless hunting and the support.
Can't wait to see who will dominate Season 4 š
š Hunt now | 419 |
| 15 | QazNet Monthly Cyber Threat Analytics Digest: April Edition
April had it all ā .env files in web roots, debug modes left on in prod, open database dumps.
Month two, pattern holds ā critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist ā both in the cards above. š
š As always, stay tuned with tumar.one. | 197 |
| 16 | You've been waiting for this š
Wake up researchers, the Kaspi.kz program's bounty just got doubled.
500 000 KZT is now on the table.
No excuse not to hunt.
š Start Now | 445 |
| 17 | One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming.
Over the past month, we analyzed a large number of reports from the Kazakhstan internet segment and spotted some clear trends we'll now be sharing regularly. And, oh boy, the majority of critical issues come not from sophisticated cyberattacks, but from basic negligence during development and server configuration.
The full breakdown ā top vulnerability categories, examples, and a developer checklist ā is in the cards above. š
Remember, cyber hygiene is not a one-time campaign, but a continuous process.
Stay safe and stay tuned with tumar.one. | 500 |
| 18 | The Department of Digital Technologies of the Aktobe Region has joined Tumar.One.
The Department is a state body of the Republic of Kazakhstan responsible for leadership in informatization, digitalization, communications, and access to information across the Aktobe region, with a mission to accelerate economic development, improve the quality of life of the population through digital technologies, and lay the groundwork for Kazakhstan's transition to a digital economy.
With this program, the Department reinforces its approach to cybersecurity across the region's digital services.
š Start Now | 266 |
| 19 | ⨠Bughunter profile update is here!
Your Tumar.One profile is no longer just an account ā it's your public bug bounty portfolio. Think of it as a CV you can actually show off.
Fill it in, share it around, and let your skills speak for themselves.
Update your profile now! | 302 |
| 20 | New Program Launch: National Center of Expertise
We are pleased to welcome the National Center of Expertise to the Tumar.One.
The NCE is a national public health authority under the Committee of Sanitary and Epidemiological Control of the Ministry of Health of the Republic of Kazakhstan. It ensures the sanitary and epidemiological welfare of the population through laboratory research, environmental factor measurements, disinfection services, and professional training programs.
The program reflects NCE's commitment to protecting the digital systems that serve its public health mission.
š Start Now | 335 |
