TumarOne platform (official channel)
258 subscribers
74 photos
25 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
Уважаемые багхантеры платформы TumarOne!

Напоминаем, что до самой масштабной конференции по кибербезопасности «KazHackStan Toitarys» осталось всего 5 дней! В рамках этой конференции будут не только крутейшие доклады от лучших специалистов по ИБ по всему миру, но и, киберполигон, где сразятся команды хакеров, воркшопы от экспертов ИБ, а также награждение лучших багхантеров благодарственными грамотами от вышестоящих органов страны!

В рамках проведения конференции команда разработчиков TumarOne создали новый, совершенно уникальный функционал, который дает возможность багхантерам объединяться в команды. Еще много другими интересными новостями мы поделимся на неделе конференции KazHackStan Toitarys.

Но это еще не единственная хорошая новость! Команда TumarOne сообщает о том, что параллельно с неделей KazHackStan Toitarys, мы объявляем неделю «Уязвимости в АСУ ТП в ресурсах QazNet». Это означает, что очки за отчеты по уязвимостям, обнаруженным в АСУ ТП в программе QazNet на платформе TumarOne, будут оцениваться в два раза больше в неделю конференции KazHackStan Toitarys с 12.09.2022 по 16.09.2022.

Не упустите данную возможность, поскольку не только очки, но и дальнейшие вознаграждения за эти уязвимости будут оцениваться вдвое больше.

Если вы еще не являетесь исследователем платформы TumarOne, скорее регистрируйтесь на сайте tumar.one.

Также не забудьте стать участником крутейшей конференции по ИБ во всей Центральной Азии – kazhackstan.kz.
💩6🔥31
Hello, Dear TumarOne Researchers!
We have great news for you!

Our platform is gaining even greater momentum and is being updated with new foreign programs. Starting today, the program of QIWI Company joins to our TumarOne international platform.

The QIWI brand is a family brand that combines several areas: kiosks, wallet, bank.

In the program, you will find a table with approved reward amounts for each type of vulnerability. Now it will become even more interesting to search for vulnerabilities!

Register now and take part!

Let's make the world safer together!

Sincerely, TumarOne team!
🔥3
Dear TumarOne researchers!

We would like to remind you of our active programs on TumarOne:

QIWI: Bounty up to 2000$
Kaspi.kz: Bounty up to 1000$
Commercial Bank KYRGYZSTAN
: Bounty up to 500$
PS Internet Company: Bounty up to 500$
QazNet & QazNet Financial Sector: Bounty up to 500$
NITEC: Bounty up to 200$
Kolesa Group: Bounty up to 200$

We invite you to participate and get awarded for the vulnerabilities found.

Check out more detailed information about the programs here: TumarOne Programs!

By the way, we are always open to your feedback! After your request, we have added a new (small, but quite important) feature in the "Reports" tab. You have the opportunity to revoke the report in case of an incorrect description of the report, a decision to cancel the report, etc. This function is available only until the report has been sorted by the moderator.

Stay tuned for the future updates!
🔥10👍4
Dear TumarOne Researchers!

We would like to present our new Support Bot, which will facilitate the process of technical assistance on TumarOne.

@TumarOneSupportBot

The implementation of Support Bot will help the development and administrative teams to respond to your queries (technical issues, triage of reports, feedback and suggestions) in an efficient way.

Please, contact us through the bot to hassle-free help in no time!
👍2❤‍🔥1🔥1🤝1
Dear TumarOne researchers!

Good news, want to get doubled, or even tripled bounties?

Check out the program of Development Bank of Kazakhstan and get your desired bounty 2-3 times higher than usual (only this month!). We invite you to participate and get awarded for the vulnerabilities found.

Low severity: up to $320
Medium severity: $320-$850
High severity: $850 and higher

Check out more detailed information about the programs here: TumarOne Programs!
2🔥1
OneBug or OnePiece, whatever it is 🪲

🏴‍☠️Luffy wanted to be the King of the Pirates, but you can become the King of the BugHunters!

What may be common between the two of you - having the highest bounty.
Check out our programs and get your first bounty in no time!
🔥9🤔1
Kcell has enhanced the security of its systems and services.

Kcell, a mobile operator in Kazakhstan, has joined the BugBounty research programme and is inviting 'white hat hackers' to identify bugs and errors in its digital systems and services. Kcell is willing to pay a monetary reward for each vulnerability found.

In Kazakhstan, Tumar.One is one of the first and well-known BugBounty platforms. Earlier this year, Kcell tested one of its systems using this platform. Independent cybersecurity researchers registered on Tumar.One can prove themselves and receive monetary rewards for confirmed bugs and gaps in information systems.

Kcell highlights the benefits of BugBounty platforms in reducing information security risks in the long term. While the company has ample in-house expertise and human resources, involving external researchers in BugBounty programmes enables more thorough product testing and enhances security levels.

Researchers can get acquainted with program rules on tumar.one!
🔥71👏1
Dear TumarOne Bughunters!

We're thrilled to announce that Kcell's public BugBounty program is expanding its scope of research objects!

Please review the updated program guidelines and scope documentation available on our platform to familiarize yourself with the new research objects.

We're excited to see the innovative ways you'll approach these new challenges and look forward to continuing our partnership in making Kcell's systems more secure.

Thank you for being part of our bughunting community!
🔥71
💥 Новости, от которых у багхантеров Tumar.One загорятся глаза! 💥

🔓 TBC Bank & Payme из Узбекистана и Kompanion Bank CJSC из Кыргызстана теперь на публичной программе! Теперь каждый из вас может испытать свои силы в поиске уязвимостей и получить за это достойное вознаграждение. 💪 Пора проверить, где прячутся баги и забрать свою награду!

💰 А еще кое-что про Kcell — тут стало еще интереснее!
Максимальные выплаты теперь выросли до 500 000 тенге! 💸
Это тот самый случай, когда найти баг — значит заработать по-крупному! Так что готовьте свои инструменты, включайте режим охотника и вперед на поиски! 🚀

🎯 Не упустите момент: покажите свои хакерские способности и зарабатывайте крутые деньги. А если повезет — в следующий раз это ваш банковский баланс порадует!
🔥7
Kcell Expands Its Bug Bounty Program on the Tumar.One Platform: Up to $1,000 per Vulnerability and Full Access to All Subdomains

In its first year participating in the Bug Bounty program, Kcell received around 60 vulnerability reports from security researchers—each one contributing to the strengthening of the company’s digital infrastructure.

Following this successful start, the program is now entering a new phase. Kcell has expanded the scope of assets eligible for testing to include all Kcell and activ subdomains. This significantly broadens the range of targets available to researchers and increases the potential for meaningful impact.

The maximum reward has also been raised: up to $1,000 for critical vulnerabilities, and up to $500 for issues found in subdomains. This move aims to attract more experienced researchers and incentivize deeper analysis.

Learn more on our website.
4🔥3
Starting today, all reward amounts on the platform are displayed as Gross.

This means the numbers you see in the "Payouts" section now represent the full reward amount before any applicable tax or fee deductions.

Why? Because it’s important to see the full worth of your finding before any tax deductions.

Everything else works exactly the same. You hunt, you report, you get paid. Simple as that! 🚀
🔥411
Fresh look for Report & Payout Statuses

To streamline the user experience, we have updated the naming conventions for both Report and Payout statuses on the platform.

These changes are designed to make your dashboard clearer and more intuitive. The underlying workflows and processes remain exactly the same.

For a complete overview of the new status names and their definitions, please check our updated rules.
🔥41👨‍💻1
🎉 Here is a recap of what we've done!

What an incredible year for our community!
Your combined efforts made 2025 our biggest year ever, successfully defending our clients' ecosystems from thousands of threats.

To every researcher: Thank you for securing our clients and advancing our field.

See you in 2026 on tumar.one!
🔥11🥰53🎉3👏2👨‍💻1