← All articles

How one bug bounty researcher chooses what to investigate

Rufus Achterberg · 1 min read

For Cybersecurity Awareness Month we sat down with one of our most prolific external researchers to talk method, patience and the features they never touch.

Most reports we receive are about the newest feature. The best ones rarely are.

Start where the seams are

"I look for places where two systems meet," they told us. "Permissions in one service, rendering in another. Each team is sure the other one checks."

A typical first hour

  • Read the changelog, backwards.

  • Map every place an identifier crosses a boundary.

  • Write down assumptions, then try to break each one.

# enumerate the API surface a feature touches
forge api routes --since 2026-09-01 --format table | grep -i export

The bug is almost never in the code you are reading. It is in the code you assume someone else wrote carefully.

0 comments

  • Be the first to comment.