What types of vulnerabilities does Tiago Danin report?
As an independent security researcher on HackerOne since 2018, Tiago Danin reports cross-site scripting (XSS), CSRF, open redirect, authentication flaws, and reverse-engineering findings on Android apps. He is also a mobile developer at Idopter Labs, which grounds these reports in a builder's view of how apps are put together.
Reading these reports means looking at his mobile development background: on HackerOne since 2018, Tiago Danin pairs day-to-day React Native and Flutter development at Idopter Labs with earlier years of native app work in Java, Swift, and Objective-C at VoxData Technology. That steady contact with mobile app code helps explain the Android reverse-engineering findings.
He started formally studying security in 2019, and in 2025 tested that knowledge away from the keyboard: he placed 4th at the XibeSec CTF in Belém, his first in-person cybersecurity competition.
| Technology | Where it was used | Evidence |
|---|---|---|
| Cross-site scripting (XSS) | HackerOne bug bounty programs | Reported as an independent security researcher since 2018 |
| CSRF | HackerOne bug bounty programs | Reported as an independent security researcher since 2018 |
| Open redirect | HackerOne bug bounty programs | Reported as an independent security researcher since 2018 |
| Authentication flaws | HackerOne bug bounty programs | Reported as an independent security researcher since 2018 |
| Android reverse-engineering findings | HackerOne bug bounty programs | Findings from analyzing Android apps, reported since 2018 |