# What types of vulnerabilities does Tiago Danin report?

> As an independent security researcher on HackerOne since 2018, Tiago Danin reports cross-site scripting (XSS), CSRF, open redirect, authentication flaws, and reverse-engineering findings on Android apps. He is also a mobile developer at Idopter Labs, which grounds these reports in a builder's view of how apps are put together.

- HTML version: https://tiagodanin.com/faq/tipos-de-vulnerabilidade-reportadas/
- Site index for AI assistants: https://tiagodanin.com/llms.txt

Reading these reports means looking at his mobile development background: on HackerOne since 2018, Tiago Danin pairs day-to-day React Native and Flutter development at Idopter Labs with earlier years of native app work in Java, Swift, and Objective-C at VoxData Technology. That steady contact with mobile app code helps explain the Android reverse-engineering findings.

He started formally studying security in 2019, and in 2025 tested that knowledge away from the keyboard: he placed 4th at the XibeSec CTF in Belém, his first in-person cybersecurity competition.

## Coverage

- Cross-site scripting (XSS), used in HackerOne bug bounty programs: Reported as an independent security researcher since 2018
- CSRF, used in HackerOne bug bounty programs: Reported as an independent security researcher since 2018
- Open redirect, used in HackerOne bug bounty programs: Reported as an independent security researcher since 2018
- Authentication flaws, used in HackerOne bug bounty programs: Reported as an independent security researcher since 2018
- Android reverse-engineering findings, used in HackerOne bug bounty programs: Findings from analyzing Android apps, reported since 2018

## Sources

- [Full profile](https://tiagodanin.com/about/)

---

Published by Tiago Danin. Free to quote with attribution and a link to https://tiagodanin.com.
