366 days to come. The only way to unlock god mode and tap to that higher power is to relentlessly attack your goals, consistently show up and have top tier accountability.That's my plan, best of luck and happy new year see you at the top.⚡️
Day 25 of documenting the road to $10K in bug bounty.
📥 Reports Submitted: 0
🟡 Triaged: 4
🔵 Pending Review: 4
⚪ Informative: 3
🟣 New: 5
💰 Paid: $1,600 / $10,000
💻 Hunted: 2 HOURS
3 reports moved to pending program review today.
They're all the exact same bug across different subdomains lol.
Also had another VDP closed as Info.
#bugbounty
Taking @LoganOpSec’s advice and locking in on Portswigger. I’ll use T.H.M and H.T.B as practice resources rather than learning resources. Been everywhere and nowhere this past quarter. Will be documenting my journey on here. Time to exploit the fundamentals.
Taking @LoganOpSec’s advice and locking in on Portswigger. I’ll use T.H.M and H.T.B as practice resources rather than learning resources. Been everywhere and nowhere this past quarter. Will be documenting my journey on here. Time to exploit the fundamentals.
read the whole bounty policy. scope, accepted impacts, known issues, exclusions, reward formula. I check every finding against that before submitting. yes every one. the policy is the contract you're getting paid under.
Working with frontier LLMs for vulnerability research lately has made me feel like I woke up one day and found the solid walls of my house were all made of paper. I knew humans were not good at secure software but having fistfuls of Chrome vulnerabilities makes it very real
I earned a modest $29,441 in Bug Bounty since 2025🤑
Now I'm sharing my knowledge with others🤝
Write-ups, vulnerability report template, research tools, and documentation here 👉https://t.co/0uXMMooszY
#TogetherWeHitHarder#CVE#CVSS#HackerOne#BugCrowd
$250,000 for a Chrome exploit chain.
first Chrome full-chain exploit bounty of 2026.
This involves chaining vulnerabilities together, bypassing Chrome's security measures, and transforming an initial foothold at the browser level into a complete exploit chain.
Browser exploitation is a completely different game
I used to avoid hunting on public bug bounty programs that had been around for a while.
I figured they’d be picked over and not have many findings left.
I was wrong. Don’t be discouraged.
i hate security disclosure so much. the number of companies that take our work for granted is insane. how about you talk to us collaboratively from the start instead of being asinine about it?
like, give us some respect, bro. we worked on this shit for weeks/months and showed you something that could have become a massive disaster if a bad guy finds it, and you don’t even seem to give a fuck and see us like some villains?
There’s something uniquely powerful about being a Security Researcher.
Just a laptop, a few hours, and the ability to uncover something that can make a billion-dollar company stop everything and listen.
That’s the rush which makes you go deep in this field including money ofcourse.