TumarOne platform (official channel)
259 subscribers
74 photos
25 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
We are preparing the launch of a major new program 🀫

But while we finalize everything, we want to hear from you.

If you could pick ONE company to launch a program on Tumar.One, who would it be?

πŸ‘‡ Tag them in the comments. We might just make it happen.
πŸ”₯11πŸŽ‰3❀2❀‍πŸ”₯1
Tumar.One is a sponsor at Jeanne d'Hack CTF πŸ‡«πŸ‡·

Tumar.One is heading to France as an official sponsor of the 3rd edition of Jeanne d’Hack CTF. We are proud to support this international event bringing together the brightest minds to solve complex security challenges.

Taking place January 30th in Rouen, this Jeopardy-style CTF is a premier gathering for testing technical depth in Web, Pwn, Crypto, and Reverse Engineering. CTF skills are the foundation of professional bug hunting; the persistence required to capture a flag is the same drive needed to secure global ecosystems. Our mission is to help researchers transition from simulated challenges to real-world security impact.

Check out the event and start your hunt:
Jeanne d'Hack CTF
πŸ”₯11❀3πŸŽ‰2😁1🀯1πŸ’©1🐳1
Fresh Scope, Fresh Finds

February is officially in full swing β€” hope you’re fully locked in and back in the game. Perfect timing, because MBank updated their scope πŸ‘€

+3 mobile apps
+16 new web targets

Send your reports at Tumar.One!
πŸ”₯16❀‍πŸ”₯6❀2πŸŽ‰2
πŸ” Think you've reached peak bug hunting?

The Akimat of the Ulytau District just went public β€” and the scope is now open for all bughunters. See you at the top.

Good luck :)
πŸ”₯9😁3❀2🀑2πŸ’―2❀‍πŸ”₯1
New Program Launch: Freedom Telecom Operations

We are pleased to welcome Freedom Telecom Operations to the Tumar.One platform.

Freedom Telecom Operations is a telecommunications operator developing high-speed connectivity and public Wi-Fi infrastructure across major cities in Kazakhstan. By launching a Bug Bounty program, the company is strengthening its proactive approach to cybersecurity and the protection of its digital services.
πŸ”₯9🀯3❀2
🌸 Spring is here β€” and with it, a new chapter.

The sun is out, the birds are singing, and we're celebrating the Top 3 of 2026 Season 2.

πŸ₯‡ nov3mber

πŸ₯ˆ m0rse

πŸ₯‰ t0x4

Congratulations to all three β€” you earned it!

And to the rest of the community: good luck in Season 3, running Apr – Jun 2026.

πŸ”— Start now
πŸ”₯6❀5❀‍πŸ”₯2πŸŽ‰2
New Program Launch: National Center of Expertise

We are pleased to welcome the National Center of Expertise to the Tumar.One.

The NCE is a national public health authority under the Committee of Sanitary and Epidemiological Control of the Ministry of Health of the Republic of Kazakhstan. It ensures the sanitary and epidemiological welfare of the population through laboratory research, environmental factor measurements, disinfection services, and professional training programs.

The program reflects NCE's commitment to protecting the digital systems that serve its public health mission.

πŸ”— Start Now
πŸ”₯8🍾7❀2
✨ Bughunter profile update is here!

Your Tumar.One profile is no longer just an account β€” it's your public bug bounty portfolio. Think of it as a CV you can actually show off.

Fill it in, share it around, and let your skills speak for themselves.

Update your profile now!
πŸ”₯10❀4πŸŽ‰2
The Department of Digital Technologies of the Aktobe Region has joined Tumar.One.

The Department is a state body of the Republic of Kazakhstan responsible for leadership in informatization, digitalization, communications, and access to information across the Aktobe region, with a mission to accelerate economic development, improve the quality of life of the population through digital technologies, and lay the groundwork for Kazakhstan's transition to a digital economy.

With this program, the Department reinforces its approach to cybersecurity across the region's digital services.

πŸ”— Start Now
πŸŽ‰9πŸ”₯4❀‍πŸ”₯3😁1
One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming.

Over the past month, we analyzed a large number of reports from the Kazakhstan internet segment and spotted some clear trends we'll now be sharing regularly. And, oh boy, the majority of critical issues come not from sophisticated cyberattacks, but from basic negligence during development and server configuration.

The full breakdown β€” top vulnerability categories, examples, and a developer checklist β€” is in the cards above. πŸ‘†

Remember, cyber hygiene is not a one-time campaign, but a continuous process.
Stay safe and stay tuned with tumar.one.
❀‍πŸ”₯5πŸ‘4πŸŽ‰2πŸ”₯1πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
You've been waiting for this πŸ‘€

Wake up researchers, the Kaspi.kz program's bounty just got doubled.
500 000 KZT is now on the table.

No excuse not to hunt.
πŸ˜ƒ Start Now
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯7πŸ’Š6❀‍πŸ”₯2❀1😁1πŸŽ‰1🍌1πŸ‘»1πŸ‘€1
QazNet Monthly Cyber Threat Analytics Digest: April Edition

April had it all – .env files in web roots, debug modes left on in prod, open database dumps.

Month two, pattern holds – critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist – both in the cards above. πŸ‘†

πŸ˜ƒ As always, stay tuned with tumar.one.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘5πŸ”₯3❀‍πŸ”₯2❀1πŸ‘1