logo

‘Proficiency takes time’: Xel on his best Bug Bounty finds and the primacy of patience in ethical hacking

ID: c31ec80c-5867-5e3b-b588-c5db7dd0a266

STIX ID: report--c31ec80c-5867-5e3b-b588-c5db7dd0a266

Feed Name: YesWeHack Blog

Date Published: 2024-02-22

Date Updated: 2026-07-04

...
...

This interview with Raphaël “Xel” Arrouas outlines his transition to full-time bug bounty hunting, the challenges of freelance vulnerability research, and advice for aspiring hunters; he also recounts notable finds (an unauthenticated RCE on a firewall orchestrator and a constrained server-side template injection RCE in an e-banking app). The piece is educational/promotional rather than a technical incident or threat report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.