Riyadh, Kingdom of Saudi Arabia

Penetration Tester &
Bug Bounty Hunter

I find and responsibly disclose real-world vulnerabilities in web applications, the CVEs I publish stand on the public record, and my reports are credited by the vendors who ship the fixes.

  • 0CVEs published
  • 0Reports filed
  • 0BugBounty.sa points
  • 0Competition podiums

01, About

Security research with a public paper trail.

I'm Abdulaziz Alasaiqah, a 16-year-old penetration tester and bug bounty hunter based in Riyadh. My work centres on web application security, hunting for the logic flaws, injection points and access-control gaps that survive automated scanning, and reporting them through responsible disclosure.

I'm an active researcher on BugBounty.sa, Saudi Arabia's national platform, where I've filed 132 reports for 1,500 points. Five of my findings are published CVEs, four of them in Firefox and patched by Mozilla, including one in Firefox 150 and ESR 140.10, and I've placed on the podium at seven security competitions and CTFs, including two 1st-place wins at KSU CTF 2026 and Tuwaiq Challenges, and Black Hat MEA 2025.

eCPPT certificate awarded to Abdulaziz Alasaiqah by INE Security, 17 May 2025

eCPPTv3

Issued 17 May 2025, ID 143537278

Verify
eJPT certificate awarded to Abdulaziz Alasaiqah by INE Security, 18 December 2024

eJPTv2

Issued 18 December 2024, ID 126900387

Verify

02, Track Record

Findings, credits and podiums.

Everything below is verifiable, published CVEs, platform credits and competition results.

  1. CVE

    CVE-2026-6765, Firefox Form Autofill

    Reported to Mozilla and patched in Firefox 150 and ESR 140.10. Awarded a 3,750 SAR bounty.

    Mozilla, Patched
  2. CVE

    CVE-2026-39154, Stored XSS in CometChat

    Discovered and responsibly disclosed; officially credited by the platform.

    CometChat, Fixed
  3. 1st

    Tuwaiq Challenges Booth CTF, LEAP 2026 (Day 3)

    First place with 2 First Bloods, PixelVault (hard, web) and Dead Air (medium, pwn).

    Tuwaiq Academy, LEAP 26
  4. 1st

    KSU CTF 2026, National University Championship

    Champions with team Cybranos, 7,600+ team points. Personally claimed 10 of the team's 11 First Bloods and 18 of 25 flags.

    Cyverse × King Saud University
  5. 2nd

    Tuwaiq Challenges CTF, LEAP 2026

    Second place finish.

    Tuwaiq Academy, LEAP 26
  6. 3rd

    Tuwaiq Cyber Challenge

    Third place, plus a First Blood in the reversing category as the first competitor to solve it.

    Tuwaiq Academy × FlagYard
  7. 4th

    CyberXbytes CTF, LEAP 2026

    Fourth place finish.

    T&S × CyberXbytes × Sicura X
  8. 3rd

    Black Hat MEA 2025, Bug Bounty Junior

    Third place at one of the region's largest cybersecurity gatherings.

    Riyadh, 2025
  9. 2nd

    Defenseathon (#GADD), Project Sate'

    Second place in the Defenseathon challenge.

    Challenge
  10. 3rd

    BugBounty Joiner Competition

    Third place finish.

    Competition
  11. SA

    BugBounty.sa, National Platform

    Active researcher, 132 reports filed across 1,500 points.

    1,500 pts

On the podium, click to enlarge.

Abdulaziz Alasaiqah receiving the third-place prize at the Black Hat MEA 2025 Bug Bounty Junior competition
Black Hat MEA 2025 Bug Bounty Junior, 3rd place, SAR 5,000
Abdulaziz Alasaiqah receiving the second-place prize at the Defensethon challenge
Defensethon (#GADD) Project Sate', 2nd place, SAR 15,000
Abdulaziz Alasaiqah holding the first-place award board for KSU CTF 2026, Champions of KSU CTF 2026, hosted by King Saud University
KSU CTF 2026 Champions, 1st place, SAR 5,000
Abdulaziz Alasaiqah receiving the first-place medal at the Tuwaiq Challenges booth during LEAP 2026
Tuwaiq Challenges, LEAP 2026 1st place, Day 3, 2 First Bloods
Abdulaziz Alasaiqah holding a T&S gift voucher board at the CyberXbytes CTF, LEAP 2026
CyberXbytes CTF, LEAP 2026 4th place

03, Expertise

What I actually do.

Offensive Security

Black-box and grey-box testing of web applications, from recon through to a written report a developer can act on.

  • Web App Pentesting
  • Bug Bounty
  • XSS
  • Injection
  • Logic Flaws
  • Access Control
  • Responsible Disclosure

Vulnerability Research

Chasing a finding all the way to a CVE, reproducing it, proving impact, and writing it up so the vendor can ship a fix.

  • CVE Research
  • Responsible Disclosure
  • Proof of Concept
  • Impact Analysis
  • Vendor Reporting

Tooling & Automation

Building the small tools the testing needs, scripting repetitive recon so the time goes into the interesting bugs.

  • Python
  • JavaScript
  • Burp Suite
  • Automation
  • Scripting
  • Recon
National emblem of the Kingdom of Saudi Arabia, two crossed swords and a palm tree

04, The Kingdom

Serving the Kingdom's security.

A proud citizen of the Kingdom of Saudi Arabia, working to strengthen its digital defenses.

05, Contact

Let's talk security.

Open to penetration testing engagements, security research collaborations and full-time positions.

abdulazizalasaiqah@gmail.com