تدخّل طارئ
Active Researcher · Bug Bounty Hunter
CYBER755
Independent Security Researcher · Jordan

Independent security researcher specializing in discovering critical vulnerabilities (CVSS 8.0+) and reporting them responsibly to vendors worldwide.

🛡️ Responsible Disclosure 🎯 CVSS 8.0+ Focus 📍 Jordan · Middle East h1 HackerOne: cyber755
150+Vulnerabilities Found
9.8Highest CVSS Recorded
100%Responsible Disclosure
// Core Expertise

Areas of Expertise

💥
Remote Code Execution (RCE)

Specializing in Sandbox Escapes and Code Injection in Node.js environments and server-side applications.

Sandbox EscapeCode InjectionVM2 / Node.js
🌐
Web Server Vulnerabilities

Analysis of HTTP Request Smuggling and CRLF Injection in Apache and Nginx servers.

HTTP SmugglingCRLF InjectionApache / Nginx
🔐
Web Application Security

Discovering Authentication Bypass, Privilege Escalation, and REST API logical flaws.

Auth BypassPrivilege EscalationIDOR / SSRF
🛡️
Network & Infrastructure Security

Firewall Bypass and detection of Zero-Trust Security Framework implementation flaws.

Firewall BypassZero-Trust FlawsNetwork Protocol
// Disclosure History

Notable Findings

CVE-2026-24781CVSS 9.8 Critical
VM2 Sandbox Escape — Remote Code Execution

Critical Sandbox Escape vulnerability in the Node.js vm2 library allowing arbitrary code execution outside the isolated environment. Reported to multiple vendors before any public disclosure.

CVE-2026-33523CVSS 6.5 Medium
Apache HTTP Response Splitting — CRLF Injection

HTTP Response Splitting vulnerability in Apache HTTP Server 2.4.58 enabling HTTP response injection via CRLF sequences. Reported to the Apache Security Team.

Private Repository
150+ Vulnerabilities in Private Repository

A collection of vulnerabilities discovered across various global systems. Some are currently under coordinated responsible disclosure with the affected vendors.

Automation · 2026
Bug Bounty Scout — Automated Matching Pipeline

Built an automated system linking new NVD vulnerabilities to HackerOne Bug Bounty programs with DeepSeek AI analysis for each CVE and estimated bounty ranges.

// Disclosure Philosophy

Ethical Commitment

Responsible Disclosure Advocate. Every vulnerability reported ethically to vendors before any public mention.

I give companies sufficient time to patch before any public disclosure. My goal is to protect users, not to damage systems.

// Bug Bounty Platforms

Invite Me to Your Program

H1
HackerOne — cyber755
hackerone.com/cyber755
● Active

Do You Have a Private Bug Bounty Program?

If your company has a private Bug Bounty program or VDP, I’m interested in joining and contributing to improving the security of your products.

© 2026 Cyber755 · Independent Security Researcher · Jordan · cs755.com