8K Dollars bounty
Started with recon ended with full impact
→ 2,000 user accounts (ATO)
→ Company SSH access exposed
→ IDOR exploited for unauthorized access
→ Got leaked internal team user information Valid Sendgrid api key using GhostJS (TrinetLayer)
→ 2Fa Bypass