Just based on original statement, you sound like one of those guys who thinks he's some hotshot hacker and won't play nice with everyone else. When you're like that, you have to bring
lots of value. Downside protection like "I stopped us from having broken anti-fraud" is really kind of not that interesting as a story. People want upside story.
At any point of time, almost every company is teetering on some massive exploit. That's just how it is. Finding one isn't this big thing if the risk is mitigated in some other way (maximum exploit size is $10k and we'll wake up the OC eng to turn off writes and rollback). I'm not interested in this binary failure-is-worst-case nonsense.
Listen, people aren't that interested in knowing that they can be fooled because most people apply some default amount of trust to the world. "Spoofed number to bypass contact whitelist". Dude, come on. This is boring stuff. Just knocking on the door isn't enough to be interesting. This isn't a Hollywood hacker movie.
My advice: Work on being productive. No one cares about all this 'exploit hacker' shit you've got going on. It's not interesting. It's not profitable. It's boring. So go finish your degree somewhere. Write some code. Find someone who you can write some code for. For free even. Move up from there.
EDIT: Jesus Christ, reading other comments, want to be promoted for finding some random issues like this in the first two weeks? Yeah, no. Here's a hint: everyone sees these things. It's not some great secret. Other people are also able to do one more thing: multiply by probability of external exploit and amount of loss.