APPLE
Five web server security acknowledgements for responsibly disclosed vulnerabilities.
↗IDENTITY / TRIFFIN AUGUSTINE
Penetration tester. Bug bounty hunter. Security researcher. A curiosity problem that turned into a career path.

CURIOUS / BY DEFAULT
I'm Triffin Augustine, widely known in the security community as TrffnSec. I'm a penetration tester, bug bounty hunter, and security researcher with a strong passion for discovering real-world vulnerabilities and helping organizations strengthen their security posture.
My journey into ethical hacking started from pure curiosity and evolved into a professional pursuit as I began hunting vulnerabilities across public and private bug bounty programs. Over time, I've identified and responsibly disclosed security issues including XSS, Host Header Injection, IDOR, access control flaws, and logic vulnerabilities across well-known platforms, universities, and enterprise applications.
Today, I document findings through detailed write-ups on Medium, sharing attack paths, methodologies, and lessons learned. Alongside hunting, I focus on continuous learning, tool development, and community knowledge-sharing - practical, experience-driven security research is the whole point.
RESPONSIBLE DISCLOSURE / ACKNOWLEDGEMENTS
Selected acknowledgements from responsibly disclosed security research.
Five web server security acknowledgements for responsibly disclosed vulnerabilities.
↗Acknowledged for identifying and responsibly reporting a security issue on a NASA domain.
↗Recognition for responsibly disclosing a security vulnerability.
↗Acknowledged for reporting a valid security issue through responsible disclosure.
↗Official acknowledgement from Dublin City University for identifying multiple security vulnerabilities.
↗Acknowledged for responsibly reporting a security issue affecting the platform.
↗Recognition from the Zain mobile application for discovering and responsibly disclosing a vulnerability.
↗THE OPERATING PRINCIPLES
The first answer explains the feature. The second often explains the vulnerability.
A clean attack path, negative controls, and useful evidence beat a dramatic claim every time.
Good notes compound. Write-ups, tools, and methodology turn one hunt into the next researcher's head start.