September 21, 2026
The “Hackerman” Joke That Taught Me a Real Security Trick 2026
“No hacker launches into space with their fingers crossed.

By Imran Niaz
3 min read
- 1 The real question is:
- 2 Who is going to review, test, secure, and take responsibility for the code being produced?
- 3 Simple steps which you can follow to get successful
- 4 What are the exact steps to approach and test local businesses for bugs?
- 5 How can I get my applications approved on platforms like HackerOne?
Then, a tired debate started when generative AI began taking over everything; everyone was saying that AI was going to take over the world, programming, and everything. On the other side, I was looking at everything, and I was also worried about what if AI can do anything; where do we all go? I was still thinking that this couldn't happen because if everyone could write code, then who would protect that code? More code is going up than in the previous 10 years of history.
The whole story starts here.
Everyone was writing code and submitting it on the internet, but no one was really wondering:
Is what you're writing safe? Who is responsible for quality assurance? Is your code secure, or are you just trying to get it shipped?
As more and more people started writing and publishing code, security and quality assurance became increasingly important. But now, instead of improving quality, we're seeing more pressure to reduce or even eliminate the people responsible for quality assurance.
The real question is:
Who is going to review, test, secure, and take responsibility for the code being produced?
The shortest answer is: hackers.
Right now, hackers are becoming the real quality assurance and testing layer — not because organizations planned it that way, but because many organizations are trying to reduce costs by cutting back on security and testing.
Whenever I'm on the Internet, I see a website, any internet portal, or something that looks like AI patterns or looks like it is completely AI-based; I totally dick out on that, and I have to be honest, I have found more bugs in those things than a large enterprise that is on Hackerone, Bugcrowd, or any other platform.
If you want to be successful, you have to find those organisations, websites, and other stuff which is that on Hacker 1.
This is one of the major problems I have been doing since long time she is long time; none of my applications got approved on Hacker 1, but individually, my many bug continuously you approved.
Simple steps which you can follow to get successful
This is one of the experience which I was doing. I have made one QuickBooks task.
- Always try to find local businesses that can have to you cover.
- While you are finding local businesses, make sure that they are using a high amount of generative AI-related stuff.
- Break your task into multiple things. And when you complete them, remember that there should be all steps.
- automation script that can collect maximum information.
- assistant that can run 24/7 for you.
- An SMTP server that helps you to track and send emails.
- All the tasks should be in a list, and they should be easy to track. Turn off all notifications; that is not good.
What are the exact steps to approach and test local businesses for bugs?
The best way is to find all the bugs and all the targets for the local businesses. You have to use multiple types of search operators,, multiple types of search engines, and one of the greatest techniques: do you know some spam Bank linking website links to multiple other businesses? You can collect a bunch of them.
How can I get my applications approved on platforms like HackerOne?
HackerOne is becoming one of the toughest Park bounty platforms with multiple regulations and everything, and sometimes they close your report as informative. You have to read multiple-box articles, and one of the best things you need to learn is about quality assurance. Also, buy it; checking the dark web can be huge potential that you can find zero days.
Information Gathering Roadmap
1. Find targets → Local businesses, public websites, and exposed services. 2. Map the attack surface → Domains, subdomains, APIs, endpoints, technologies, and third-party services. 3. Collect intelligence → Search engines, public sources, code repositories, certificates, DNS, and legitimate threat-intelligence sources. 4. Automate recon → Use scripts to continuously organize and monitor discovered assets. 5. Verify → Separate real security issues from false positives. 6. Document everything → Target → evidence → impact → reproduction → report. 7. Keep monitoring → Your 24/7 infrastructure can continuously watch authorized assets for changes.
What automation scripts or assistants do you recommend for beginners?
I script that can test multiple and points finding subtitment checking dark web and other information which can be collected for various purposes.
Can you share more details about your QuickBooks task and what you learned?
I've been working in this field for a long time. I've realized that success may not come today, but with consistency, one day I'll reach where I want to be in bug bounty. I'm also able to earn some income from the market, which helps me keep going. I collect useful research from various sources, including the dark web, and I maintain my own 24/7 server infrastructure, which gives me the freedom to run my work continuously.
At the end of this article,, I just want to tell you one thing: just keep in mind that one day you will be successful,, but not every day is a good day, and not every bad day is a good day. You have to be sure what you have to do.