If you’ve been following my journey, you’ll know this blog started with one goal: bug bounties.
Three years later, I’ve submitted four reports, earned zero payouts, and learned firsthand just how difficult it is to bridge the gap between learning on platforms and finding real vulnerabilities in live targets.
I’m not giving up on bug bounties. But I do need to be honest with myself—and with everyone reading this.
Right now, that’s not where my energy is.
Over the last few months, without ever intending to, I found myself disappearing down a completely different rabbit hole.
It started with a simple problem. Every morning I was logging into multiple platforms just to understand the health of my infrastructure. There had to be a better way.
So I asked Claude to help me build a dashboard.
That dashboard became a Docker container running on a Linux VM. Then came integrations with Zabbix and Wazuh. Later, I built an AI agent named Hermes that could manage my VMware environment through Telegram commands.
Then one day I shut down a virtual machine simply by chatting with a bot.
That was the moment it clicked.
This wasn’t just another side project anymore. It was changing how I think about managing infrastructure and solving problems.
More importantly, it taught me something bug bounty hadn’t.
I already have a real-world environment where I can build, test, break, fix, automate, and improve things every single day. It’s called production.
Instead of forcing myself toward an area where I was making slow progress, I started investing more heavily in the skills I use daily as a one-person IT department—automation, PowerShell, Linux, Docker, monitoring, documentation, and AI-assisted workflows.
This isn’t a move away from security.
If anything, it’s some of the most security-relevant work I’ve done all year. Hardening systems, improving visibility, documenting infrastructure, reducing human error, and building resilient automation are all part of good security—they just happen from the infrastructure side rather than the bug bounty side.
AI has completely changed the way I learn.
Today I can describe my environment, explain the outcome I want, and have AI generate a script that’s understandable, reviewable, and easy to refine. Instead of spending hours searching through documentation for syntax, I spend that time understanding why the solution works and adapting it to my environment.
Looking back, I don’t think this blog was ever really about bug bounties.
It was always about documenting the uncomfortable space between learning and doing, and being honest about that journey.
That gap hasn’t disappeared—it has simply moved.
Today the question isn’t, “How do I find my first XSS?”
It’s, “How do I transform a fragile, one-person IT department into something automated, documented, resilient, and AI-assisted, so it no longer depends on me remembering everything?”
That’s the journey I’m on now.
And I think it’s going to be an even more interesting one.
