
Mikhail Shcherbakov
@yu5k3
Followers
948
Following
1K
Media
54
Statuses
472
Doing security research. For fun and profit...
Stockholm, Sverige
Joined October 2014
🤓 2025 YTD #BugBounty stats update, May:. 📄 11 issues Reported (4 Crit, 2 High, 5 Medium).💰 9 issues Paid. A new month means 2 more RCEs reported 👌.This time I hit Chromium headless browser for the first time in BBPs.
👌 2025 YTD #BugBounty stats update, April:. 📄 9 issues Reported (2 Crit, 2 High, 5 Medium).💰 8 issues Paid. Switched to monthly updates instead of weekly. Why? I don't drop new vulns every week 😅 My stats from the last months confirm my "capacity": ~2 RCEs per month.
1
0
2
In April, I reported 2 #RCE (consistency 😎), and once again, one of them was classified as Medium. Fine, move on. Many previously reported vulns also got paid this month 💸 . I've been doing BB full-time since late last year, so it's a good moment to sum things up.
1
0
0
👌 2025 YTD #BugBounty stats update, April:. 📄 9 issues Reported (2 Crit, 2 High, 5 Medium).💰 8 issues Paid. Switched to monthly updates instead of weekly. Why? I don't drop new vulns every week 😅 My stats from the last months confirm my "capacity": ~2 RCEs per month.
🫡 2025 YTD #BugBounty stats update, March:. 📄 7 issues Reported (2 Crit, 1 High, 4 Medium).💰 2 issues Paid. Reported 2 RCEs and some "collateral damage" for March. Still investigating new targets and developing my own tools.
2
0
4
Unrestricted File Upload in Elastic Kibana (CVSS 5.4). Part of another chain ending in XSS and showing ATO impact. I shared some details at my last DEF CON, but the deep dive is still in the vault. Looks like I've hoarded enough CVEs for the next talk 😅.
CVE-2024-11390 Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript fil…
1
0
0
Unrestricted File Upload in Elastic Kibana. Part of the most beautiful and non-trivial chain I've built. I'm excited to get a chance to share the full story in a con talk someday 🤞.
CVE-2025-25016 Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-…
1
0
0