TFSecurity
Malaysian security researchers. We focus on deep security research and offensive security across the world.
[ 01 ]
WHO WE ARE
We are an independent team of Malaysian security researchers. We focus on security research across the world.
TFSec is a dedicated collective of researchers. We test systems, find critical vulnerabilities, report them responsibly, and document our findings. We spend our time hunting on real-world targets and doing deep research into how complex systems actually break.
MY
Based in Malaysia
100%
Open Research
[ 02 ]
OUR WORK
SECURITY RESEARCH
We dig into how web applications and systems work under the hood. When we find something interesting or a new way things can break, we document it properly and share it here.
READ OUR RESEARCH →VULNERABILITY RESEARCH
We actively hunt for vulnerabilities across complex systems worldwide. When we find and report critical security flaws, we document the process and what we learned from it.
HACKERONE ↗[ 03 ]
CVE HIGHLIGHTS
32+ CVEs and security advisories across Adobe, Sonatype, WooCommerce, and more. Here are a few that stand out.
Application DoS — Content Credentials SDK
Application DoS — Adobe Commerce
Payment Bypass via Session Hijack — Stripe for WooCommerce
SSRF / Cloud Credential Theft — Nexus Repository Manager
Arbitrary File System Read — Content Credentials SDK
Arbitrary File System Write — Content Credentials SDK
[ 04 ]
THE TEAM
A collective of security researchers from Malaysia. We focus on deep security research across the world.
[ 05 ]
RECORDS
Our recent standings and achievements on HackerOne leaderboards and private programs.
MALAYSIA LEADERBOARD
+
// Q2 2026 (APR - JUN)
VIEW LEADERBOARD ↗// Q1 2026 (JAN - MAR)
VIEW LEADERBOARD ↗GLOBAL: SOURCE CODE
+
// Q2 2026 (APR - JUN)
VIEW LEADERBOARD ↗// Q1 2026 (JAN - MAR)
VIEW LEADERBOARD ↗ADOBE
+
STRIPE
+
// 2026
VIEW PROGRAM ↗// ALL TIME
WOOCOMMERCE
+
// JULY 2026
VIEW ADVISORY ↗Checkout Session hijack, CVSS 8.1 High, HackerOne #3835686
[ 06 ]
LATEST RESEARCH
SSRF Redirect Bypass in Sonatype Nexus, Stealing Cloud Credentials Through a Proxy Repository (CVE-2026-14646)
Sonatype Nexus Repository Manager had SSRF protection that blocked requests to cloud metadata endpoints. But it only validated the initial URL. A single HTTP redirect bypassed everything. Full technical breakdown of CVE-2026-14646.
Cart Swap Attack on Stripe for WooCommerce, From Session Hijack to Full Payment Bypass
A deep dive into how a missing ownership check on a single WooCommerce AJAX endpoint let attackers rewrite Stripe payment amounts mid checkout. Includes the full attack flow, root cause analysis, and what every developer should learn from it.
31 CVEs in Adobe Content Credentials SDK & Adobe Commerce
We spent months digging into Adobe's Content Credentials SDK and Adobe Commerce. Ended up with 31 CVEs across three security bulletins.
[ 07 ]
FAQ
What is TFSec?
A team of Malaysian security researchers. We do security research, vulnerability analysis, and write about what we find. We are not a company, just a dedicated team.
How did you guys start?
We started as a group of friends interested in web security. Over time, we teamed up to focus on deep security research full-time.
What do you post on the blog?
Security research we have done, CVEs we found, and interesting vulnerabilities we reported. Basically anything we think is worth sharing.
Are you open to new members?
Not actively recruiting right now. But if you are into web security and have something to show, reach out. We keep it small on purpose.


