Rules
Report requirements
- The incident must be real and have valid public evidence.
- Do not submit credentials, personal data, payloads, or exploitation instructions.
- Do not attack systems to create evidence.
- Pending targets are not published before verification.
- Administrators may reject or remove risky reports.