CyberSafe Network

CyberSafe Network Ethical Hacker | Pe*******on testing | Bug bounty | Network security | Cyber threat intelligence | Security tools ( Wireshark, Kali linux, Metasploit)

I responsibly disclosed a security vulnerability that was acknowledged and validated by the company. As a result, I was ...
30/07/2026

I responsibly disclosed a security vulnerability that was acknowledged and validated by the company. As a result, I was awarded a €500 bug bounty for my contribution.

Beyond the reward, what matters most is helping organizations strengthen their security and protect their users. Every responsibly disclosed vulnerability is a step toward making the internet safer.

A big thank you to the team for their professionalism, recognition, and support throughout the disclosure process.

Looking forward to discovering and responsibly reporting more security issues in the future.

I’m happy to share that one of my responsibly disclosed security vulnerability reports has been successfully fixed and d...
30/07/2026

I’m happy to share that one of my responsibly disclosed security vulnerability reports has been successfully fixed and deployed to production. The CTO personally confirmed that the remediation has been completed and also shared that my bug bounty reward is currently going through the internal approval process.

It’s always a great feeling to know that responsible disclosure helps improve the security of real-world applications before attackers can exploit these issues.

Thank you to the team for the professional communication, transparency, and appreciation for security research. Looking forward to continuing to help organizations strengthen their security through responsible disclosure.

Happy to share that I have finally received a $100 bug bounty reward from QNAP Systems for responsibly reporting a secur...
30/07/2026

Happy to share that I have finally received a $100 bug bounty reward from QNAP Systems for responsibly reporting a security vulnerability through their Security Bounty Program.

Every recognized report is another step forward in my cybersecurity journey and motivates me to continue helping organizations improve their security through responsible disclosure.

Thank you, QNAP Security Team, for the recognition!

Alhamdulillah! Successfully identified and responsibly disclosed a 2FA Authentication Bypass vulnerability in TeamViewer...
10/07/2026

Alhamdulillah!
Successfully identified and responsibly disclosed a 2FA Authentication Bypass vulnerability in TeamViewer Germany GmbH (Germany).
My report was accepted and I was awarded a €740 Bug Bounty for helping improve the platform’s security.
Every accepted report is another step forward in the cybersecurity journey.

Proud to be recognized in the Hall of Fame by Barco  (Belgium), a global leader in digital visualization and enterprise ...
22/06/2026

Proud to be recognized in the Hall of Fame by Barco (Belgium), a global leader in digital visualization and enterprise solutions.
My name has been officially published on the company’s website as a recognition of responsibly reporting a security vulnerability and contributing to improving their system security.
This achievement highlights my dedication to cybersecurity, ethical hacking, and responsible disclosure practices.
I am passionate about identifying vulnerabilities and helping organizations strengthen their security posture on a global scale.

Happy to share that I received a bug bounty reward for responsibly disclosing a valid security vulnerability related to ...
26/05/2026

Happy to share that I received a bug bounty reward for responsibly disclosing a valid security vulnerability related to 2FA/TOTP implementation.

The issue was successfully validated and fixed by the security team. Grateful for the recognition and continuously learning in the field of cybersecurity & bug bounty hunting.

Vulnerability Accepted – Security Research UpdateI’m pleased to share that my recently reported vulnerability has been o...
25/05/2026

Vulnerability Accepted – Security Research Update

I’m pleased to share that my recently reported vulnerability has been officially accepted for further assessment and remediation through a structured security review process.

This vulnerability was identified in an account lifecycle and session management flow within a cloud-based system.



Vulnerability Details:

The issue was related to improper data handling after account deletion. It was observed that:

• After account deletion, user session remained active under certain conditions
• User-related data (such as contact entries and Gmail/contact information) was still accessible
• Data added before deletion remained visible even after the account was deleted
• In some cases, new data could still be added and persisted after deletion

This behavior indicates that user data was not being fully cleared or invalidated upon account deletion, leading to potential data persistence and privacy exposure risks.



Security Impact:

Under specific authenticated scenarios, this could potentially lead to:

* Unauthorized access to residual user data
* Privacy exposure of stored contact information
* Incomplete account data removal behavior

From a security standpoint, this aligns with a medium to high severity (P2-level) issue depending on impact assessment.



💰 Bug Bounty Context:

In the Company , vulnerabilities of this nature in cloud and application systems are typically rewarded under structured bug bounty programs, where payouts can range from $100 up to $5,000 or more, depending on severity, scope, and impact.

Given the nature of this issue and the fact that it has now been accepted and moved into the remediation phase, I appreciate the structured handling of security reports and hope for a fair evaluation and reward aligned with the impact.



Looking forward to the final resolution and continuing my journey in responsible vulnerability research.

Reported multiple authentication & session vulnerabilities (2FA, OTP, JWT)✅ Key issues successfully mitigated and deploy...
21/05/2026

Reported multiple authentication & session vulnerabilities (2FA, OTP, JWT)
✅ Key issues successfully mitigated and deployed
One risk accepted by the team
💬 Reward discussions currently in progress

Critical Security Vulnerability Identified (P1 Severity)I discovered multiple authentication and session management issu...
19/05/2026

Critical Security Vulnerability Identified (P1 Severity)

I discovered multiple authentication and session management issues in an application that, when combined, could potentially lead to full 2FA bypass and account takeover.

Summary of Findings:

The system was vulnerable to:

* Replay of 2FA disable requests
* Acceptance of old OTPs
* Bypass of password re-authentication for sensitive actions
* Improper JWT/session revocation after logout
* Lack of anti-replay protection on critical endpoints

⚠️ Impact:

These issues together could allow an attacker to:

* Reuse previously intercepted 2FA disable requests
* Disable 2FA without proper verification
* Maintain access even after logout
* Potentially achieve full account compromise

Testing Approach:

Conducted responsible security testing using a test account
*Intercepted requests via Burp Suite
* Performed controlled proof-of-concept replay testing
* Full PoC workflow was documented and recorded

Status:

The issue was reported responsibly to the security team.
They acknowledged the finding and confirmed that a fix is currently in progress.



This experience highlights the importance of strong controls around:

* Authentication
* Session management
* Token invalidation
* Anti-replay mechanisms
* Secure 2FA lifecycle implementation

I identified and reported a security vulnerability related to missing session invalidation after password change/reset i...
13/05/2026

I identified and reported a security vulnerability related to missing session invalidation after password change/reset in the customer account system. During testing, I observed that active sessions remain valid even after a password update, which could potentially allow unauthorized continued access if a session is compromised.
The issue was carefully analyzed and reported with a detailed proof of concept (PoC). It was reviewed and reproduced by the internal security team, and based on their assessment, the vulnerability was treated as a high severity / critical security issue internally and scheduled for remediation in the next deployment.
According to the company’s internal evaluation criteria, the issue was accepted, and I have been confirmed as eligible for a reward for this responsible disclosure. A demonstration of the vulnerability was also shared to assist with validation and fixing the issue.




*******onTesting

Address

Gilgit Baltistan
Gilgit
15100

Website

Alerts

Be the first to know and let us send you an email when CyberSafe Network posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share