TumarOne platform (official channel)
259 subscribers
74 photos
25 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
Dear TumarOne Bughunters!

We're thrilled to announce that Kcell's public BugBounty program is expanding its scope of research objects!

Please review the updated program guidelines and scope documentation available on our platform to familiarize yourself with the new research objects.

We're excited to see the innovative ways you'll approach these new challenges and look forward to continuing our partnership in making Kcell's systems more secure.

Thank you for being part of our bughunting community!
🔥71
💥 Новости, от которых у багхантеров Tumar.One загорятся глаза! 💥

🔓 TBC Bank & Payme из Узбекистана и Kompanion Bank CJSC из Кыргызстана теперь на публичной программе! Теперь каждый из вас может испытать свои силы в поиске уязвимостей и получить за это достойное вознаграждение. 💪 Пора проверить, где прячутся баги и забрать свою награду!

💰 А еще кое-что про Kcell — тут стало еще интереснее!
Максимальные выплаты теперь выросли до 500 000 тенге! 💸
Это тот самый случай, когда найти баг — значит заработать по-крупному! Так что готовьте свои инструменты, включайте режим охотника и вперед на поиски! 🚀

🎯 Не упустите момент: покажите свои хакерские способности и зарабатывайте крутые деньги. А если повезет — в следующий раз это ваш банковский баланс порадует!
🔥7
Kcell Expands Its Bug Bounty Program on the Tumar.One Platform: Up to $1,000 per Vulnerability and Full Access to All Subdomains

In its first year participating in the Bug Bounty program, Kcell received around 60 vulnerability reports from security researchers—each one contributing to the strengthening of the company’s digital infrastructure.

Following this successful start, the program is now entering a new phase. Kcell has expanded the scope of assets eligible for testing to include all Kcell and activ subdomains. This significantly broadens the range of targets available to researchers and increases the potential for meaningful impact.

The maximum reward has also been raised: up to $1,000 for critical vulnerabilities, and up to $500 for issues found in subdomains. This move aims to attract more experienced researchers and incentivize deeper analysis.

Learn more on our website.
4🔥3
Starting today, all reward amounts on the platform are displayed as Gross.

This means the numbers you see in the "Payouts" section now represent the full reward amount before any applicable tax or fee deductions.

Why? Because it’s important to see the full worth of your finding before any tax deductions.

Everything else works exactly the same. You hunt, you report, you get paid. Simple as that! 🚀
🔥411
Fresh look for Report & Payout Statuses

To streamline the user experience, we have updated the naming conventions for both Report and Payout statuses on the platform.

These changes are designed to make your dashboard clearer and more intuitive. The underlying workflows and processes remain exactly the same.

For a complete overview of the new status names and their definitions, please check our updated rules.
🔥41👨‍💻1
🎉 Here is a recap of what we've done!

What an incredible year for our community!
Your combined efforts made 2025 our biggest year ever, successfully defending our clients' ecosystems from thousands of threats.

To every researcher: Thank you for securing our clients and advancing our field.

See you in 2026 on tumar.one!
🔥11🥰53🎉3👏2👨‍💻1
The hunt just got more rewarding! 🏆

To keep the competition fresh, our leaderboard year now runs from October to September each year, divided into 4 intense Seasons.

The 2026 Season Calendar:
• Season 1: Oct 2025 – Dec 2025
• Season 2: Jan 2026 – Mar 2026
• Season 3: Apr 2026 – Jun 2026
• Season 4: Jul 2026 – Sep 2026

To kick things off, we want to celebrate the elite bughunters who dominated 2026 Season 1:
🥇 zeus
🥈 Mayakovsky
🥉 n1ghth7r1can6xcenti

And here’s the twist: From now on, we aren’t just giving away bragging rights. The Top 3 hunters of every single season will now receive exclusive Tumar.One branded merch! 👕🔥

As for the rest of the community: Season 2 is already underway. The question is... will we see your name next?

Hunt Now
🔥9🎉5🏆3
We are preparing the launch of a major new program 🤫

But while we finalize everything, we want to hear from you.

If you could pick ONE company to launch a program on Tumar.One, who would it be?

👇 Tag them in the comments. We might just make it happen.
🔥11🎉32❤‍🔥1
Tumar.One is a sponsor at Jeanne d'Hack CTF 🇫🇷

Tumar.One is heading to France as an official sponsor of the 3rd edition of Jeanne d’Hack CTF. We are proud to support this international event bringing together the brightest minds to solve complex security challenges.

Taking place January 30th in Rouen, this Jeopardy-style CTF is a premier gathering for testing technical depth in Web, Pwn, Crypto, and Reverse Engineering. CTF skills are the foundation of professional bug hunting; the persistence required to capture a flag is the same drive needed to secure global ecosystems. Our mission is to help researchers transition from simulated challenges to real-world security impact.

Check out the event and start your hunt:
Jeanne d'Hack CTF
🔥113🎉2😁1🤯1💩1🐳1
Fresh Scope, Fresh Finds

February is officially in full swing — hope you’re fully locked in and back in the game. Perfect timing, because MBank updated their scope 👀

+3 mobile apps
+16 new web targets

Send your reports at Tumar.One!
🔥16❤‍🔥62🎉2
🏔 Think you've reached peak bug hunting?

The Akimat of the Ulytau District just went public — and the scope is now open for all bughunters. See you at the top.

Good luck :)
🔥9😁32🤡2💯2❤‍🔥1
New Program Launch: Freedom Telecom Operations

We are pleased to welcome Freedom Telecom Operations to the Tumar.One platform.

Freedom Telecom Operations is a telecommunications operator developing high-speed connectivity and public Wi-Fi infrastructure across major cities in Kazakhstan. By launching a Bug Bounty program, the company is strengthening its proactive approach to cybersecurity and the protection of its digital services.
🔥9🤯32