mersa-v6:~$ whoami

mersa-v6

Application Security Researcher & Bug Bounty Hunter

terminal
$ echo $MISSION

"I research and report real-world security vulnerabilities across web and mobile applications, APIs, AI systems, and SaaS platforms."

>

I'm Alaa, known as mersa-v6 — a cybersecurity researcher and bug bounty hunter focused on finding real-world security vulnerabilities in production web and mobile applications, APIs, modern AI systems, and SaaS platforms.

My research covers web and mobile application security, API and GraphQL security, payment and billing logic bypasses, IDORs, broken access control, authentication and authorization flaws, business logic vulnerabilities, vulnerability chaining, and responsible disclosure.

I work across public and private bug bounty programs, focusing on practical impact, clear reporting, and helping organizations secure real-world attack surfaces.

Uber
Epic Games
Capital One
Amazon
MetaMask
CodeRabbit.ai
Sonatype
IBM
JFrog
Consensys
Lyft
Mollie

Research conducted independently under each program's disclosure and bug bounty terms.

mersa-v6:~/contact$ cat links.txt
HackerOnehackerone.com/mersa-v6HackenProofhackenproof.com/hackers/mersa-v6GitHubgithub.com/mersa-v6X@mersa_v6LinkedInin/mersa-v6Emailcontact@mersa.info