en
Feedback

Don't get caught by a cheater! Telemetrio finds and tags such channels šŸ‘‰ If you want to see the tag, subscribe šŸ‘ˆ

TumarOne platform (official channel)

TumarOne platform (official channel)

Open in Telegram

Platform for rewarding the discovery of vulnerabilities in information systems and resources. Platform: https://tumar.one Support: @TumarOneSupportBot Queries: info@tumar.one

Show more
The country is not specifiedThe category is not specified
290
Subscribers
No data24 hours
+77 days
+2930 days

Data loading in progress...

Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
Oct '26
October '26
+8
in 0 channels
September '26
+30
in 1 channels
Get PRO
August '26
+13
in 0 channels
Get PRO
July '26
+8
in 0 channels
Get PRO
June '26
+3
in 0 channels
Get PRO
May '26
+13
in 1 channels
Get PRO
April '26
+19
in 2 channels
Get PRO
March '26
+237
in 4 channels
Date
Subscriber Growth
Mentions
Channels
07 October0
06 October+2
05 October0
04 October+2
03 October0
02 October0
01 October+4
Channel Posts
Season IV Leaderboard Right after KazHackStan, it's time to celebrate the Top 3 of the final season of the year, 2026 Season
Season IV Leaderboard Right after KazHackStan, it's time to celebrate the Top 3 of the final season of the year, 2026 Season 4!   šŸ„‡ Timur 🄈 KUFFO šŸ„‰ bvtyr   Thank you to everyone! 2027 Season 1 runs from October to December, and we can't wait to see you at the top 😃   Hunt Now 😃

2
šŸ† KazHackStan 2026 Š°ŃŃŃ‹Š½Š“Š°Ņ“Ń‹ TUMAR.ONE жарысының үзГік 10 багхантері белгілі болГы! ŅšŠ°Ń‚Ń‹ŃŃƒŃˆŃ‹Š»Š°Ń€Š“Ń‹ нәтижелерімен құттықтаймыз+1
šŸ† KazHackStan 2026 Š°ŃŃŃ‹Š½Š“Š°Ņ“Ń‹ TUMAR.ONE жарысының үзГік 10 багхантері белгілі болГы! ŅšŠ°Ń‚Ń‹ŃŃƒŃˆŃ‹Š»Š°Ń€Š“Ń‹ нәтижелерімен құттықтаймыз! ҮзГік онГықпен ŠŗŠ°Ń€ŃƒŃŠµŠ»ŃŒŠ“ен танысыңыз šŸ‘€ šŸ“… 29–30 қыркүйек šŸ“ Астана, Š¢Ó™ŃƒŠµŠ»ŃŃ–Š·Š“Ń–Šŗ сарайы šŸ”— kazhackstan.com šŸ† ŠžŠæŃ€ŠµŠ“ŠµŠ»ŠµŠ½Š° Š“ŠµŃŃŃ‚ŠŗŠ° Š»ŃƒŃ‡ŃˆŠøŃ… багхантеров TUMAR.ONE на KazHackStan 2026! ŠŸŠ¾Š·Š“Ń€Š°Š²Š»ŃŠµŠ¼ ŃƒŃ‡Š°ŃŃ‚Š½ŠøŠŗŠ¾Š² с Ń€ŠµŠ·ŃƒŠ»ŃŒŃ‚Š°Ń‚Š°Š¼Šø! Листайте ŠŗŠ°Ń€ŃƒŃŠµŠ»ŃŒ, чтобы ŃƒŠ²ŠøŠ“ŠµŃ‚ŃŒ весь топ-10 šŸ‘€ šŸ“… 29–30 ŃŠµŠ½Ń‚ŃŠ±Ń€Ń šŸ“ Астана, Дворец ŠŠµŠ·Š°Š²ŠøŃŠøŠ¼Š¾ŃŃ‚Šø šŸ”— kazhackstan.com šŸ† The TUMAR.ONE top 10 bug hunters at KazHackStan 2026 have been announced! Congratulations to everyone who made the list! Swipe to see the full top 10 šŸ‘€ šŸ“… September 29–30 šŸ“ Astana, Palace of Independence šŸ”— kazhackstan.com
135
3
Freedom Holding Corp. Raises the Stakes The moment so many of you have been waiting for: a reward raise! šŸ’° But that's not al
Freedom Holding Corp. Raises the StakesĀ  The moment so many of you have been waiting for: a reward raise! šŸ’° But that's not all: šŸŽÆ +10 new wildcard targets, so there is plenty of room to explore šŸ“œ Updated program rules: please read them carefully before you unleash your agents and tools, so your reports don't get rejected! Have fun catching those vulnerabilities! šŸƒā€ā™‚ļø Start Now 😃
1 518
4
August was a reminder that old security habits die hard. SQL injections in REST APIs and CMS cores, unverified digital signat+8
August was a reminder that old security habits die hard. Ā  SQL injections in REST APIs and CMS cores, unverified digital signatures handing over full account takeovers, and .git repositories left wide open in web roots. Nearly 85% of critical findings this month boiled down to two simple mistakes: trusting client-supplied input and leaving exposed metadata in the web root. Ā  Full breakdown - in the cards above. šŸ‘† Ā  Stay ahead with tumar.one 😃
277
5
https://app.zoom.us/wc/84211805294/join?ref_from=launch&tk=2SOFr38VyLs_u6GW0JWR8qhh14WRaSyYZ_XB3f1HZG8.DQkAAAATm2osbhZBcThRUWh6T1JkV21FUGNMel9iWjN3AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&pwd=7hbXhrukYKn6a6NaLMDAEfZ78PvmQq.1&_x_zm_rtaid=2iUT17-QRZyZ145piIe4TA.1789476953924.c0798a40d2a505eaa7e3f55decfe1fef&_x_zm_rhtaid=891&fromPWA=1
1
6
Limited time only! šŸ”„ Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT September is Nationa
Limited time only! šŸ”„ Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT September is National Cybersecurity Month in Kazakhstan, and Kcell is marking it in the way researchers appreciate most. From September 1 to 30, the maximum reward for an eligible critical vulnerability on the Tumar.One platform doubles to 1,000,000 KZT. The scope stays wide open: all Kcell and activ domains and subdomains. Reports must be submitted by September 30. Payouts follow the program terms: the reward applies to a confirmed vulnerability that meets the program conditions, and the final amount is set on triage. Start hunting!
1 724
7
šŸ“‹ New on Tumar.One: Report Limits We are rolling out report submission limits across the platform. Your limit is individual
šŸ“‹ New on Tumar.One: Report Limits Ā  We are rolling out report submission limits across the platform. Ā  Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down. Ā  Once a report moves out of New status, a slot opens up and you can submit again. Hunt smart!
297
8
šŸ“‹ New on Tumar.One: Report Limits Ā  We are rolling out report submission limits across the platform. Ā  Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down. Ā  Once a report moves out of New status, a slot opens up and you can submit again. Hunt smart.
1
9
Hey researcher šŸ‘‹ We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together o
Hey researcher šŸ‘‹ Ā  We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together over 6,000 attendees, top security researchers, and leading experts in information security. Ā  The Top 10 researchers of Tumar.One will be invited on stage at KazHackStan - where they will be awarded with merch and named awards! Ā  Reports are accepted through and including September 15th. Ā  šŸŽŸ Exclusive Promo Code 8DNLG0SN3B Ā  50% discount on tickets - limited to 50 users. First come, first served.
266
10
KazHackStan 2026 Executive Sponsor - Tumar.One šŸ”„ Tumar.One - ŠžŃ€Ń‚Š°Š»Ń‹Ņ› ŠŠ·ŠøŃŠ“Š°Ņ“Ń‹ 4 000-нан астам ŃŃ‚ŠøŠŗŠ°Š»Ń‹Ņ› хакерГі біріктіретін
KazHackStan 2026 Executive Sponsor - Tumar.One šŸ”„ Tumar.One - ŠžŃ€Ń‚Š°Š»Ń‹Ņ› ŠŠ·ŠøŃŠ“Š°Ņ“Ń‹ 4 000-нан астам ŃŃ‚ŠøŠŗŠ°Š»Ń‹Ņ› хакерГі біріктіретін ең ірі баг-Š±Š°ŃƒŠ½Ń‚Šø платформасы. ŠŸŠ»Š°Ń‚Ń„Š¾Ń€Š¼Š° CyberKumbez ŅÆŃˆŃ–Š½ есептерГі Ņ›Š°Š±Ń‹Š»Š“Š°Ńƒ мен Š¼Š¾Š“ŠµŃ€Š°Ń†ŠøŃŠ»Š°ŃƒŠ“Ń‹ қамтамасыз етеГі, сонГай-ақ 2027 жылғы ŠŗŠøŠ±ŠµŃ€Ņ›Š°ŃƒŃ–ŠæŃŃ–Š·Š“Ń–Šŗ Š±Š¾Š¹Ń‹Š½ŃˆŠ° ICO халықаралық олимпиаГасына ŅšŠ°Š·Š°Ņ›ŃŃ‚Š°Š½ құрамасын ұлттық Ń–Ń€Ń–ŠŗŃ‚ŠµŃƒŠ“ŠµŠ½ Ó©Ń‚ŠŗŃ–Š·Ńƒ ŅÆŃˆŃ–Š½ T1CTF платформасын ұсынаГы. KazHackStan 2026-ға Ņ›Š¾Š»Š“Š°Ńƒ көрсеткені ŅÆŃˆŃ–Š½ Tumar.One-ға алғысымызГы білГіреміз šŸ” KazHackStan 2026 Executive Sponsor - Tumar.One šŸ”„ Tumar.One - ŠŗŃ€ŃƒŠæŠ½ŠµŠ¹ŃˆŠ°Ń баг-Š±Š°ŃƒŠ½Ń‚Šø платформа Š¦ŠµŠ½Ń‚Ń€Š°Š»ŃŒŠ½Š¾Š¹ Азии, Š¾Š±ŃŠŠµŠ“ŠøŠ½ŃŃŽŃ‰Š°Ń более 4 000 ŃŃ‚ŠøŃ‡Š½Ń‹Ń… хакеров. ŠŸŠ»Š°Ń‚Ń„Š¾Ń€Š¼Š° обеспечивает приём Šø Š¼Š¾Š“ŠµŃ€Š°Ń†ŠøŃŽ отчётов Š“Š»Ń CyberKumbez, а также ŠæŃ€ŠµŠ“Š¾ŃŃ‚Š°Š²Š»ŃŠµŃ‚ ŠæŠ»Š°Ń‚Ń„Š¾Ń€Š¼Ńƒ T1CTF Š“Š»Ń Š½Š°Ń†ŠøŠ¾Š½Š°Š»ŃŒŠ½Š¾Š³Š¾ отбора в ŃŠ±Š¾Ń€Š½ŃƒŃŽ ŠšŠ°Š·Š°Ń…ŃŃ‚Š°Š½Š° на ŠœŠµŠ¶Š“ŃƒŠ½Š°Ń€Š¾Š“Š½ŃƒŃŽ олимпиаГу по кибербезопасности ICO 2027. БлагоГарим Tumar.One за ŠæŠ¾Š“Š“ŠµŃ€Š¶ŠŗŃƒ KazHackStan 2026 šŸ” KazHackStan 2026 Executive Sponsor - Tumar.One šŸ”„ Tumar.One is Central Asia’s largest bug bounty platform, bringing together more than 4,000 ethical hackers. The platform handles report submission and moderation for CyberKumbez and also provides the T1CTF platform for Kazakhstan’s national selection process for the team that will represent the country at the 2027 International Cybersecurity Olympiad (ICO). We thank Tumar.One for supporting KazHackStan 2026 šŸ”
193
11
The vulnerabilities in June and July weren't clever... Because they didn't need to be. Unverified signatures, client-supplied+8
The vulnerabilities in June and July weren't clever... Ā  Because they didn't need to be. Unverified signatures, client-supplied prices, open Redis instances, outdated CMS handing out root shells. 89% of critical findings this cycle came from systems that simply trusted the wrong input. Ā  This digest covers June and July combined. Full breakdown - categories, hunter checklist, developer checklist - in the cards above. šŸ‘† Ā  Stay tuned tumar.one 😃
260
12
Important Rules Update We have updated the Tumar.One platform rules - and there are quite a few changes.šŸ’„ Before your next s
Important Rules Update Ā  We have updated the Tumar.One platform rules - and there are quite a few changes.šŸ’„ Ā  Before your next submission, please make sure you're up to date. Ā  😃 check here.
237
13
May broke the pattern. For two months, the story was the same - .env files, debug modes, open databases. You know, basic negl+9
May broke the pattern. For two months, the story was the same - .env files, debug modes, open databases. You know, basic negligence. In May, the attack surface shifted: AI infrastructure, secrets buried in React bundles, JWT confusion across microservices, and fresh CVEs being weaponized the same week they drop. Full breakdown - top incident categories, critical cases, and checklists for both hunters and developers - all in the cards above. šŸ‘† Stay tuned with tumar.one 😃
245
14
2026 Season 3 is over! Here are the hunters who came out on top: šŸ„‡ mukh4w 🄈 nov3mber šŸ„‰ plrF Thank you all for the relentle
2026 Season 3 is over! Here are the hunters who came out on top: šŸ„‡ mukh4w 🄈 nov3mber šŸ„‰ plrF Thank you all for the relentless hunting and the support. Can't wait to see who will dominate Season 4 😃 šŸ”— Hunt now
419
15
QazNet Monthly Cyber Threat Analytics Digest: April Edition April had it all – .env files in web roots, debug modes left on i+9
QazNet Monthly Cyber Threat Analytics Digest: April Edition April had it all – .env files in web roots, debug modes left on in prod, open database dumps. Month two, pattern holds – critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist – both in the cards above. šŸ‘† 😃 As always, stay tuned with tumar.one.
197
16
You've been waiting for this šŸ‘€ Wake up researchers, the Kaspi.kz program's bounty just got doubled. 500 000 KZT is now on th
You've been waiting for this šŸ‘€ Wake up researchers, the Kaspi.kz program's bounty just got doubled. 500 000 KZT is now on the table. No excuse not to hunt. 😃 Start Now
445
17
One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming. Over the past month, we ana+8
One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming. Over the past month, we analyzed a large number of reports from the Kazakhstan internet segment and spotted some clear trends we'll now be sharing regularly. And, oh boy, the majority of critical issues come not from sophisticated cyberattacks, but from basic negligence during development and server configuration. The full breakdown — top vulnerability categories, examples, and a developer checklist — is in the cards above. šŸ‘† Remember, cyber hygiene is not a one-time campaign, but a continuous process. Stay safe and stay tuned with tumar.one.
500
18
The Department of Digital Technologies of the Aktobe Region has joined Tumar.One. The Department is a state body of the Repub
The Department of Digital Technologies of the Aktobe Region has joined Tumar.One. The Department is a state body of the Republic of Kazakhstan responsible for leadership in informatization, digitalization, communications, and access to information across the Aktobe region, with a mission to accelerate economic development, improve the quality of life of the population through digital technologies, and lay the groundwork for Kazakhstan's transition to a digital economy. With this program, the Department reinforces its approach to cybersecurity across the region's digital services. šŸ”— Start Now
266
19
✨ Bughunter profile update is here! Your Tumar.One profile is no longer just an account — it's your public bug bounty portfol
✨ Bughunter profile update is here! Your Tumar.One profile is no longer just an account — it's your public bug bounty portfolio. Think of it as a CV you can actually show off. Fill it in, share it around, and let your skills speak for themselves. Update your profile now!
302
20
New Program Launch: National Center of Expertise We are pleased to welcome the National Center of Expertise to the Tumar.One.
New Program Launch: National Center of Expertise We are pleased to welcome the National Center of Expertise to the Tumar.One. The NCE is a national public health authority under the Committee of Sanitary and Epidemiological Control of the Ministry of Health of the Republic of Kazakhstan. It ensures the sanitary and epidemiological welfare of the population through laboratory research, environmental factor measurements, disinfection services, and professional training programs. The program reflects NCE's commitment to protecting the digital systems that serve its public health mission. šŸ”— Start Now
335