TumarOne platform (official channel)
259 subscribers
74 photos
25 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
One day, vibe coders will learn not to push .env files. Until then - we'll keep the stats coming.

Over the past month, we analyzed a large number of reports from the Kazakhstan internet segment and spotted some clear trends we'll now be sharing regularly. And, oh boy, the majority of critical issues come not from sophisticated cyberattacks, but from basic negligence during development and server configuration.

The full breakdown — top vulnerability categories, examples, and a developer checklist — is in the cards above. 👆

Remember, cyber hygiene is not a one-time campaign, but a continuous process.
Stay safe and stay tuned with tumar.one.
❤‍🔥5👍4🎉2🔥1👏1
This media is not supported in your browser
VIEW IN TELEGRAM
You've been waiting for this 👀

Wake up researchers, the Kaspi.kz program's bounty just got doubled.
500 000 KZT is now on the table.

No excuse not to hunt.
😃 Start Now
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥7💊6❤‍🔥21😁1🎉1🍌1👻1👀1
QazNet Monthly Cyber Threat Analytics Digest: April Edition

April had it all – .env files in web roots, debug modes left on in prod, open database dumps.

Month two, pattern holds – critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist – both in the cards above. 👆

😃 As always, stay tuned with tumar.one.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍5🔥3❤‍🔥21👏1
2026 Season 3 is over!

Here are the hunters who came out on top:

🥇 mukh4w
🥈 nov3mber
🥉 plrF

Thank you all for the relentless hunting and the support.

Can't wait to see who will dominate Season 4 😃

🔗 Hunt now
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥133👍2🐳1
May broke the pattern.

For two months, the story was the same - .env files, debug modes, open databases. You know, basic negligence. In May, the attack surface shifted: AI infrastructure, secrets buried in React bundles, JWT confusion across microservices, and fresh CVEs being weaponized the same week they drop.

Full breakdown - top incident categories, critical cases, and checklists for both hunters and developers - all in the cards above. 👆

Stay tuned with tumar.one 😃
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥63👏2👍1