TumarOne platform (official channel)
رفتن به کانال در Telegram
Platform for rewarding the discovery of vulnerabilities in information systems and resources. Platform: https://tumar.one Support: @TumarOneSupportBot Queries: info@tumar.one
نمایش بیشترکشور مشخص نشده استدسته بندی مشخص نشده است
290
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+77 روز
+2930 روز
آرشیو پست ها
🌸 Spring is here — and with it, a new chapter.
The sun is out, the birds are singing, and we're celebrating the Top 3 of 2026 Season 2.
🥇 nov3mber
🥈 m0rse
🥉 t0x4
Congratulations to all three — you earned it!
And to the rest of the community: good luck in Season 3, running Apr – Jun 2026.
🔗 Start now
New Program Launch: Freedom Telecom Operations
We are pleased to welcome Freedom Telecom Operations to the Tumar.One platform.
Freedom Telecom Operations is a telecommunications operator developing high-speed connectivity and public Wi-Fi infrastructure across major cities in Kazakhstan. By launching a Bug Bounty program, the company is strengthening its proactive approach to cybersecurity and the protection of its digital services.
🏔 Think you've reached peak bug hunting?
The Akimat of the Ulytau District just went public — and the scope is now open for all bughunters. See you at the top.
Good luck :)
Fresh Scope, Fresh Finds
February is officially in full swing — hope you’re fully locked in and back in the game. Perfect timing, because MBank updated their scope 👀
+3 mobile apps
+16 new web targets
Send your reports at Tumar.One!
Tumar.One is a sponsor at Jeanne d'Hack CTF 🇫🇷
Tumar.One is heading to France as an official sponsor of the 3rd edition of Jeanne d’Hack CTF. We are proud to support this international event bringing together the brightest minds to solve complex security challenges.
Taking place January 30th in Rouen, this Jeopardy-style CTF is a premier gathering for testing technical depth in Web, Pwn, Crypto, and Reverse Engineering. CTF skills are the foundation of professional bug hunting; the persistence required to capture a flag is the same drive needed to secure global ecosystems. Our mission is to help researchers transition from simulated challenges to real-world security impact.
Check out the event and start your hunt:
Jeanne d'Hack CTF
We are preparing the launch of a major new program 🤫
But while we finalize everything, we want to hear from you.
If you could pick ONE company to launch a program on Tumar.One, who would it be?
👇 Tag them in the comments. We might just make it happen.
The hunt just got more rewarding! 🏆
To keep the competition fresh, our leaderboard year now runs from October to September each year, divided into 4 intense Seasons.
The 2026 Season Calendar:
• Season 1: Oct 2025 – Dec 2025
• Season 2: Jan 2026 – Mar 2026
• Season 3: Apr 2026 – Jun 2026
• Season 4: Jul 2026 – Sep 2026
To kick things off, we want to celebrate the elite bughunters who dominated 2026 Season 1:
🥇 zeus
🥈 Mayakovsky
🥉 n1ghth7r1can6xcenti
And here’s the twist: From now on, we aren’t just giving away bragging rights. The Top 3 hunters of every single season will now receive exclusive Tumar.One branded merch! 👕🔥
As for the rest of the community: Season 2 is already underway. The question is... will we see your name next?
Hunt Now
+8
🎉 Here is a recap of what we've done!
What an incredible year for our community!
Your combined efforts made 2025 our biggest year ever, successfully defending our clients' ecosystems from thousands of threats.
To every researcher: Thank you for securing our clients and advancing our field.
See you in 2026 on tumar.one!
Fresh look for Report & Payout Statuses
To streamline the user experience, we have updated the naming conventions for both Report and Payout statuses on the platform.
These changes are designed to make your dashboard clearer and more intuitive. The underlying workflows and processes remain exactly the same.
For a complete overview of the new status names and their definitions, please check our updated rules.
Starting today, all reward amounts on the platform are displayed as Gross.
This means the numbers you see in the "Payouts" section now represent the full reward amount before any applicable tax or fee deductions.
Why? Because it’s important to see the full worth of your finding before any tax deductions.
Everything else works exactly the same. You hunt, you report, you get paid. Simple as that! 🚀
Kcell Expands Its Bug Bounty Program on the Tumar.One Platform: Up to $1,000 per Vulnerability and Full Access to All Subdomains
In its first year participating in the Bug Bounty program, Kcell received around 60 vulnerability reports from security researchers—each one contributing to the strengthening of the company’s digital infrastructure.
Following this successful start, the program is now entering a new phase. Kcell has expanded the scope of assets eligible for testing to include all Kcell and activ subdomains. This significantly broadens the range of targets available to researchers and increases the potential for meaningful impact.
The maximum reward has also been raised: up to $1,000 for critical vulnerabilities, and up to $500 for issues found in subdomains. This move aims to attract more experienced researchers and incentivize deeper analysis.
Learn more on our website.
