Me and my friend @Ibrahim58733058 have been hacking on the BMW bug bounty on Intigriti for ~4 months.
2X on the BMW leaderboard and earned $$,$$$ 💰
Thanks @intigriti & @BMW 🙌
🚨 Just got a CRITICAL on HackerOne!
Didn’t even know that there is something called "PayPal API Key/Secret Key",
**Secret Hunter** detected them instantly and boosted the report impact 🔥
Thanks @kassem_s94!
Order Secret_hunter at: t.me/apesofficial
Submitted a critical ATO last year but it was marked out-of-scope.
Today the program added the asset into scope and reopened my report.
Appreciate the honesty — not every program does this.
Integrity matters. 🙏
#hackerone#BugBounty
I didn’t suddenly start finding criticals.
I just changed my mindset.
A month ago, I decided to focus only on P1s.
Mediums still get reported, but they’re not the goal.
When you aim for criticals, you’ll find mediums, but when you aim for mediums, crits stay out of reach.
Just got a reward for a high vulnerability submitted on @yeswehack -- Information Disclosure (CWE-200).
Found 2 bugs on a program — info disclosure + follow-up issue discovered during analysis. Nice response from the team — fast and professional.
#YesWeRHackers
🔥 New tool alert for bug hunters: zero‑payload XSS finder that scans source code for reflections — bypasses noisy payloads and reduces false positives. Must-try for recon.
Download : cybersecurity.tabbeqai.com/Cybersecurity/
Creator: @kassem_S94