Hi, I'm Yunus Emre Öztaş — bug bounty hunter recognized by Apple, Microsoft, Meta & IBM. Intigriti Top Hacker. Building offensive tools and finding critical vulnerabilities before the bad guys do.
Hall of Fame
Recognized by industry leaders for responsible vulnerability disclosure.
Intigriti
Bug Bounty PlatformRanked among the platform's highest-performing security researchers across multiple programs.
Apple
Security Research HOFAcknowledged for responsible disclosure of vulnerabilities affecting Apple products and services.
Microsoft
MSRC — Security Response CenterRecognized for identifying vulnerabilities across Microsoft's products and cloud infrastructure.
Meta
Facebook / Instagram / WhatsAppListed for reporting critical security issues across Meta's broader platform ecosystem.
IBM
IBM Security Hall of FameInducted for disclosing critical vulnerabilities affecting IBM's enterprise products.
…and many more recognitions across global organizations
Offensive Tools
Purpose-built security tools — live from GitHub, shuffled on every visit.
Skills & Expertise
Skill Radar
🔴 Offensive Security
🟢 Development
Toolbox
CVE & Vulnerability Timeline
Security vulnerabilities researched, exploited, and reported.
Remote Code Execution via Ignition debug mode. Phar deserialization chain leading to arbitrary command execution.
Pre-auth Remote Code Execution in Metabase via H2 JDBC connection string injection.
Middleware authorization bypass via x-middleware-subrequest header manipulation in Next.js applications.
Remote Code Execution via React Server Components with UTF-16LE WAF bypass technique.
Blog & Writeups
Security research, vulnerability writeups, and technical deep-dives.
Chaining Email Enumeration to Full DB Dump
How I combined email enumeration, credential brute force, and SSRF into a chain that led to a complete database dump of 7,000+ records.
DOM Clobbering + Cross-Origin Exploit Chain
Walkthrough of the Intigriti March 2026 XSS challenge — DOM clobbering with cross-origin window.open for code execution.
Android Pentesting Without Root — FridHunter
Building a rootless Android pentesting framework using Frida Gadget injection on Termux.
Let's Work
Together.
Interested in collaboration, bug bounty programs, or security consulting?