Apple
×3 · web server securityListed by name in Apple's official security acknowledgements — three separate months.
- February 2026
- August 2025
- July 2025
Offensive Security Researcher
A bug in every wave.
Top-1,000 hacker on HackerOne — credited by Apple, Goldman Sachs, SpaceX and GitHub.
Penetration testing · red teaming · application & vulnerability research — remote or relocating · GMT+6
200 m The record
Every figure below was pulled live from the HackerOne API on 15 August 2026 — not from a CV. They're checkable: my profile is public.
1 000 m Every wave · HackerOne
Every mark below is a HackerOne program that accepted at least one of my reports as valid — the public ones. Rendered in a single ink, because down here everything glows the same. My private programs, most of my work, can't be named — that's further down.
And these are only the ones I'm allowed to name — about a sixth of the work. The rest is below.
2 000 m A second current · Bugcrowd
The same work on a second platform. SpaceX, Atlassian, Twilio, the U.S. Department of Veterans Affairs — each took one of my reports into their public hall of fame. Three more are private, and stay that way.
4 000 m Water nobody can see
Twenty-eight of my sixty-seven programs are private — invitation-only, names withheld by HackerOne. They hold 2 896 of my 3 447 reputation. My public profile is the shallow end.
One private program. Ninety-four reports submitted, forty-eight recognised, first place overall. It cannot be named here, and it is the best evidence of what I do.
5 000 m Acknowledged
Listed by name in Apple's official security acknowledgements — three separate months.
Two bounties awarded in May 2026 — my most recent notable wins, one of them co-authored with fellow Bangladeshi hunter refat0g.
Report resolved September 2021, and the GitHub Security Researcher badge that came with it.
Four findings resolved inside six weeks in early 2023 — the densest run on any named program.
5 500 m What I find
Not a skills list. Badges are only issued on a valid report of that class.
5 800 m Instruments
Extracts hosts from Shodan and defeats the platform's hard ceiling of 1 000 results per query by recursively subdividing the search — country, then city, then port — until every bucket fits under the limit. Validates, strips reserved ranges, deduplicates.
A port scanner that never touches the target. Resolves open ports out of Shodan's InternetDB at ~500 requests a second with rotating user agents, so an entire estate can be mapped without a single packet reaching the asset owner.
Continuous external attack-surface mapping, folding Crunchbase, Shodan, Censys, Whoxy and crt.sh into one picture with custom reconnaissance on top.
6 000 m Surface
English — IELTS 8.0 · বাংলা · हिन्दी · اردو