ru
Feedback

Не попадитесь на канал ботавода! Telemetrio находит и помечает такие каналы 👉 Хотите видеть метку — оформите подписку 👈

TumarOne platform (official channel)

TumarOne platform (official channel)

Открыть в Telegram

Platform for rewarding the discovery of vulnerabilities in information systems and resources. Platform: https://tumar.one Support: @TumarOneSupportBot Queries: info@tumar.one

Больше
Страна не указанаКатегория не указана
290
Подписчики
Нет данных24 часа
+77 дней
+2930 дней
Архив постов
Season IV Leaderboard Right after KazHackStan, it's time to celebrate the Top 3 of the final season of the year, 2026 Season
Season IV Leaderboard Right after KazHackStan, it's time to celebrate the Top 3 of the final season of the year, 2026 Season 4!   🥇 Timur 🥈 KUFFO 🥉 bvtyr   Thank you to everyone! 2027 Season 1 runs from October to December, and we can't wait to see you at the top 😃   Hunt Now 😃

Repost from KazHackStan
🏆 KazHackStan 2026 аясындағы TUMAR.ONE жарысының үздік 10 багхантері белгілі болды! Қатысушыларды нәтижелерімен құттықтаймыз
+1
🏆 KazHackStan 2026 аясындағы TUMAR.ONE жарысының үздік 10 багхантері белгілі болды! Қатысушыларды нәтижелерімен құттықтаймыз! Үздік ондықпен карусельден танысыңыз 👀 📅 29–30 қыркүйек 📍 Астана, Тәуелсіздік сарайы 🔗 kazhackstan.com 🏆 Определена десятка лучших багхантеров TUMAR.ONE на KazHackStan 2026! Поздравляем участников с результатами! Листайте карусель, чтобы увидеть весь топ-10 👀 📅 29–30 сентября 📍 Астана, Дворец Независимости 🔗 kazhackstan.com 🏆 The TUMAR.ONE top 10 bug hunters at KazHackStan 2026 have been announced! Congratulations to everyone who made the list! Swipe to see the full top 10 👀 📅 September 29–30 📍 Astana, Palace of Independence 🔗 kazhackstan.com

Freedom Holding Corp. Raises the Stakes The moment so many of you have been waiting for: a reward raise! 💰 But that's not al
Freedom Holding Corp. Raises the Stakes  The moment so many of you have been waiting for: a reward raise! 💰 But that's not all: 🎯 +10 new wildcard targets, so there is plenty of room to explore 📜 Updated program rules: please read them carefully before you unleash your agents and tools, so your reports don't get rejected! Have fun catching those vulnerabilities! 🏃‍♂️ Start Now 😃

August was a reminder that old security habits die hard. SQL injections in REST APIs and CMS cores, unverified digital signat
+8
August was a reminder that old security habits die hard.   SQL injections in REST APIs and CMS cores, unverified digital signatures handing over full account takeovers, and .git repositories left wide open in web roots. Nearly 85% of critical findings this month boiled down to two simple mistakes: trusting client-supplied input and leaving exposed metadata in the web root.   Full breakdown - in the cards above. 👆   Stay ahead with tumar.one 😃

Limited time only! 🔥 Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT September is Nationa
Limited time only! 🔥 Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT September is National Cybersecurity Month in Kazakhstan, and Kcell is marking it in the way researchers appreciate most. From September 1 to 30, the maximum reward for an eligible critical vulnerability on the Tumar.One platform doubles to 1,000,000 KZT. The scope stays wide open: all Kcell and activ domains and subdomains. Reports must be submitted by September 30. Payouts follow the program terms: the reward applies to a confirmed vulnerability that meets the program conditions, and the final amount is set on triage. Start hunting!

📋 New on Tumar.One: Report Limits We are rolling out report submission limits across the platform. Your limit is individual
📋 New on Tumar.One: Report Limits   We are rolling out report submission limits across the platform.   Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down.   Once a report moves out of New status, a slot opens up and you can submit again. Hunt smart!

📋 New on Tumar.One: Report Limits   We are rolling out report submission limits across the platform.   Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down.   Once a report moves out of New status, a slot opens up and you can submit again. Hunt smart.

Hey researcher 👋 We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together o
Hey researcher 👋   We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together over 6,000 attendees, top security researchers, and leading experts in information security.   The Top 10 researchers of Tumar.One will be invited on stage at KazHackStan - where they will be awarded with merch and named awards!   Reports are accepted through and including September 15th.   🎟 Exclusive Promo Code 8DNLG0SN3B   50% discount on tickets - limited to 50 users. First come, first served.

Repost from KazHackStan
KazHackStan 2026 Executive Sponsor - Tumar.One 🔥 Tumar.One - Орталық Азиядағы 4 000-нан астам этикалық хакерді біріктіретін
KazHackStan 2026 Executive Sponsor - Tumar.One 🔥 Tumar.One - Орталық Азиядағы 4 000-нан астам этикалық хакерді біріктіретін ең ірі баг-баунти платформасы. Платформа CyberKumbez үшін есептерді қабылдау мен модерациялауды қамтамасыз етеді, сондай-ақ 2027 жылғы киберқауіпсіздік бойынша ICO халықаралық олимпиадасына Қазақстан құрамасын ұлттық іріктеуден өткізу үшін T1CTF платформасын ұсынады. KazHackStan 2026-ға қолдау көрсеткені үшін Tumar.One-ға алғысымызды білдіреміз 🔐 KazHackStan 2026 Executive Sponsor - Tumar.One 🔥 Tumar.One - крупнейшая баг-баунти платформа Центральной Азии, объединяющая более 4 000 этичных хакеров. Платформа обеспечивает приём и модерацию отчётов для CyberKumbez, а также предоставляет платформу T1CTF для национального отбора в сборную Казахстана на Международную олимпиаду по кибербезопасности ICO 2027. Благодарим Tumar.One за поддержку KazHackStan 2026 🔐 KazHackStan 2026 Executive Sponsor - Tumar.One 🔥 Tumar.One is Central Asia’s largest bug bounty platform, bringing together more than 4,000 ethical hackers. The platform handles report submission and moderation for CyberKumbez and also provides the T1CTF platform for Kazakhstan’s national selection process for the team that will represent the country at the 2027 International Cybersecurity Olympiad (ICO). We thank Tumar.One for supporting KazHackStan 2026 🔐

The vulnerabilities in June and July weren't clever... Because they didn't need to be. Unverified signatures, client-supplied
+8
The vulnerabilities in June and July weren't clever...   Because they didn't need to be. Unverified signatures, client-supplied prices, open Redis instances, outdated CMS handing out root shells. 89% of critical findings this cycle came from systems that simply trusted the wrong input.   This digest covers June and July combined. Full breakdown - categories, hunter checklist, developer checklist - in the cards above. 👆   Stay tuned tumar.one 😃

Important Rules Update We have updated the Tumar.One platform rules - and there are quite a few changes.💥 Before your next s
Important Rules Update   We have updated the Tumar.One platform rules - and there are quite a few changes.💥   Before your next submission, please make sure you're up to date.   😃 check here.

May broke the pattern. For two months, the story was the same - .env files, debug modes, open databases. You know, basic negl
+9
May broke the pattern. For two months, the story was the same - .env files, debug modes, open databases. You know, basic negligence. In May, the attack surface shifted: AI infrastructure, secrets buried in React bundles, JWT confusion across microservices, and fresh CVEs being weaponized the same week they drop. Full breakdown - top incident categories, critical cases, and checklists for both hunters and developers - all in the cards above. 👆 Stay tuned with tumar.one 😃

2026 Season 3 is over! Here are the hunters who came out on top: 🥇 mukh4w 🥈 nov3mber 🥉 plrF Thank you all for the relentle
2026 Season 3 is over! Here are the hunters who came out on top: 🥇 mukh4w 🥈 nov3mber 🥉 plrF Thank you all for the relentless hunting and the support. Can't wait to see who will dominate Season 4 😃 🔗 Hunt now

QazNet Monthly Cyber Threat Analytics Digest: April Edition April had it all – .env files in web roots, debug modes left on i
+9
QazNet Monthly Cyber Threat Analytics Digest: April Edition April had it all – .env files in web roots, debug modes left on in prod, open database dumps. Month two, pattern holds – critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist – both in the cards above. 👆 😃 As always, stay tuned with tumar.one.

You've been waiting for this 👀 Wake up researchers, the Kaspi.kz program's bounty just got doubled. 500 000 KZT is now on the table. No excuse not to hunt. 😃 Start Now

One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming. Over the past month, we ana
+8
One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming. Over the past month, we analyzed a large number of reports from the Kazakhstan internet segment and spotted some clear trends we'll now be sharing regularly. And, oh boy, the majority of critical issues come not from sophisticated cyberattacks, but from basic negligence during development and server configuration. The full breakdown — top vulnerability categories, examples, and a developer checklist — is in the cards above. 👆 Remember, cyber hygiene is not a one-time campaign, but a continuous process. Stay safe and stay tuned with tumar.one.

The Department of Digital Technologies of the Aktobe Region has joined Tumar.One. The Department is a state body of the Repub
The Department of Digital Technologies of the Aktobe Region has joined Tumar.One. The Department is a state body of the Republic of Kazakhstan responsible for leadership in informatization, digitalization, communications, and access to information across the Aktobe region, with a mission to accelerate economic development, improve the quality of life of the population through digital technologies, and lay the groundwork for Kazakhstan's transition to a digital economy. With this program, the Department reinforces its approach to cybersecurity across the region's digital services. 🔗 Start Now

✨ Bughunter profile update is here! Your Tumar.One profile is no longer just an account — it's your public bug bounty portfol
✨ Bughunter profile update is here! Your Tumar.One profile is no longer just an account — it's your public bug bounty portfolio. Think of it as a CV you can actually show off. Fill it in, share it around, and let your skills speak for themselves. Update your profile now!

New Program Launch: National Center of Expertise We are pleased to welcome the National Center of Expertise to the Tumar.One.
New Program Launch: National Center of Expertise We are pleased to welcome the National Center of Expertise to the Tumar.One. The NCE is a national public health authority under the Committee of Sanitary and Epidemiological Control of the Ministry of Health of the Republic of Kazakhstan. It ensures the sanitary and epidemiological welfare of the population through laboratory research, environmental factor measurements, disinfection services, and professional training programs. The program reflects NCE's commitment to protecting the digital systems that serve its public health mission. 🔗 Start Now