TumarOne platform (official channel)
259 subscribers
74 photos
25 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
QazNet Monthly Cyber Threat Analytics Digest: April Edition

April had it all – .env files in web roots, debug modes left on in prod, open database dumps.

Month two, pattern holds – critical incidents rooted not in zero-days, but in configurations that should have been locked down on day one. This month we're also adding two new sections: a breakdown of critical cases and a bug hunter checklist – both in the cards above. 👆

😃 As always, stay tuned with tumar.one.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍5🔥3❤‍🔥21👏1
2026 Season 3 is over!

Here are the hunters who came out on top:

🥇 mukh4w
🥈 nov3mber
🥉 plrF

Thank you all for the relentless hunting and the support.

Can't wait to see who will dominate Season 4 😃

🔗 Hunt now
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥133👍2🐳1
May broke the pattern.

For two months, the story was the same - .env files, debug modes, open databases. You know, basic negligence. In May, the attack surface shifted: AI infrastructure, secrets buried in React bundles, JWT confusion across microservices, and fresh CVEs being weaponized the same week they drop.

Full breakdown - top incident categories, critical cases, and checklists for both hunters and developers - all in the cards above. 👆

Stay tuned with tumar.one 😃
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥63👏2👍1
Important Rules Update
 
We have updated the Tumar.One platform rules - and there are quite a few changes.💥
 
Before your next submission, please make sure you're up to date.
 
😃 check here.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤡14🔥52👍2
The vulnerabilities in June and July weren't clever...
 
Because they didn't need to be. Unverified signatures, client-supplied prices, open Redis instances, outdated CMS handing out root shells. 89% of critical findings this cycle came from systems that simply trusted the wrong input.
 
This digest covers June and July combined. Full breakdown - categories, hunter checklist, developer checklist - in the cards above. 👆
 
Stay tuned tumar.one 😃
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
5👏2🙊1