Author

Ayoub

Senior security content developer

Intigriti Bug Bytes #240 - September 2026 πŸš€

Bug Bytes

September 25, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising OpenAI, Slack, Meta, and more via a vulnerable image library Hacking OpenAI employee accounts in under 72 hours Breaking into Google's GFile for $100K Hacking AI CX agents Turbo Intruder 2 surpassing

Continue reading: Intigriti Bug Bytes #240 - September 2026 πŸš€

Hacking AI customer service agents

Web & API Hacking
Injection Attacks

Hacking Tools

September 2, 2026

As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be. At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire, Founding Memb

Continue reading: Hacking AI customer service agents

Intigriti Bug Bytes #239 - August 2026 πŸš€

Bug Bytes

Bug Bytes

August 28, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready

Continue reading: Intigriti Bug Bytes #239 - August 2026 πŸš€

Web fuzzing for hackers

Web & API Hacking

Hacking Tools

August 20, 2026

Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crash

Continue reading: Web fuzzing for hackers

Intigriti Bug Bytes #238 - July 2026 πŸš€

Bug Bytes

Bug Bytes

July 31, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo

Continue reading: Intigriti Bug Bytes #238 - July 2026 πŸš€

How to appeal a bug bounty submission

Bug Bounty Tips & Methodology

Hacking Tools

July 30, 2026

Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are mish

Continue reading: How to appeal a bug bounty submission

Intigriti Bug Bytes #237 - June 2026 πŸš€

Bug Bytes

Bug Bytes

June 26, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at scal

Continue reading: Intigriti Bug Bytes #237 - June 2026 πŸš€

Exploiting web cache poisoning vulnerabilities

Web & API Hacking
Security Misconfigurations

Hacking Tools

June 24, 2026

Web (or HTTP) caching is a highly adopted practice to effectively optimize web page loading times for clients. However, as with most technologies, when incorrectly implemented, it may open up a new exploitable attack surface for us to look into. In this article, we'll cover what web cache poisoning

Continue reading: Exploiting web cache poisoning vulnerabilities

Intigriti Bug Bytes #236 - May 2026 πŸš€

Bug Bytes

Bug Bytes

May 30, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sani

Continue reading: Intigriti Bug Bytes #236 - May 2026 πŸš€

Exploiting SQL injection vulnerabilities

Web & API Hacking

Hacking Tools

April 30, 2026

Most assume that SQL injection is a solved problem in today's application landscape, especially with increased awareness of secure coding practices (such as resorting to prepared statements or parameterized queries) and the widespread adoption of NoSQL databases. However, in practice, SQLi vulnerabi

Continue reading: Exploiting SQL injection vulnerabilities

Intigriti Bug Bytes #235 - April 2026 πŸš€

Bug Bytes

Bug Bytes

April 24, 2026

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising an NPM package with 40M weekly downloads Bypassing Cloudflare WAF for a full ATO 20-part series on exploiting JWT vulnerabilities First Intigriti Bug Bounty Meetup And so much more! Let's dive in! Bug

Continue reading: Intigriti Bug Bytes #235 - April 2026 πŸš€

BugQuest 2026: 31 Days of Broken Access Control

CTF Challenge

Hacking Tools

April 1, 2026

In March 2026, we ran BugQuest, a 31-day campaign covering everything you need to know about finding and exploiting broken access control vulnerabilities. From understanding the basics of authentication and authorization to spotting subtle authorization bypasses in real code, we broke down one of th

Continue reading: BugQuest 2026: 31 Days of Broken Access Control

Intigriti Bug Bytes #234 - March 2026 πŸš€

Bug Bytes

Bug Bytes

March 27, 2026

Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Earning $180K via SSRFs Free Burp Suite Pro licenses for top hackers Bypassing tricky file upload restrictions Injecting malicious code into AI coding assistants And so much more! Let’s dive in! We've teamed up wi

Continue reading: Intigriti Bug Bytes #234 - March 2026 πŸš€

Intigriti 0326 CTF Challenge: Chaining DOM clobbering and CSP bypasses for XSS

CTF Challenge

Hacking Tools

March 25, 2026

At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security researcher community. This month's challenge, brought forward by Kulindu, presented us with a Secure Search Portal that, on the surface, appeared to be well protected. A strict Content Secu

Continue reading: Intigriti 0326 CTF Challenge: Chaining DOM clobbering and CSP bypasses for XSS

Exploiting broken access control vulnerabilities

Web & API Hacking
Authentication & Authorization

Hacking Tools

March 20, 2026

Broken access control vulnerabilities have consistently remained at the top of the OWASP Top 10, and for a good reason. As web applications continue to grow in complexity, with the introduction of role-based access controls, multi-tenant support, and granular permission models, the likelihood of acc

Continue reading: Exploiting broken access control vulnerabilities

Intigriti Bug Bytes #233 - February 2026 πŸš€

Bug Bytes

Bug Bytes

February 20, 2026

Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: How a read-only Kubernetes permission turned into full cluster takeover AI agent autonomously finds a 1-click RCE Race condition in blockchain infrastructure worth billions Finding over 500 high-severity vulnerabi

Continue reading: Intigriti Bug Bytes #233 - February 2026 πŸš€

How to use AI for improved vulnerability report writing

Bug Bounty Tips & Methodology

Hacking Tools

February 17, 2026

Report writing is an integral part of bug bounty or any type of vulnerability assessment. In fact, sometimes, it can become the most important phase. Submitting a confusing report can often lead to misalignment and faulty interpretation of your reported vulnerability. On the contrary, a well-written

Continue reading: How to use AI for improved vulnerability report writing

Exploiting PostMessage vulnerabilities: A complete guide

Web & API Hacking
Client-Side Attacks

Hacking Tools

January 31, 2026

PostMessage vulnerabilities arise when developers fail to properly validate message origins or sanitize content within cross-origin communication handlers. As modern web applications increasingly rely on the postMessage API for cross-origin communication, whether for embedded widgets, OAuth flows, t

Continue reading: Exploiting PostMessage vulnerabilities: A complete guide

Intigriti 0126 CTF Challenge: Exploiting insecure postMessage handlers

CTF Challenge

Hacking Tools

January 28, 2026

At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security researcher community. January's challenge presented participants with CRYPTIGRITI, a cryptocurrency trading platform where users could buy and trade Bitcoin (BTC), Monero (XMR), and a custo

Continue reading: Intigriti 0126 CTF Challenge: Exploiting insecure postMessage handlers

Intigriti Bug Bytes #232 - January 2026 πŸš€

Bug Bytes

Bug Bytes

January 16, 2026

Welcome to the latest edition of Bug Bytes (and the first of 2026)! In this month’s issue, we’ll be featuring: Hijacking official AWS GitHub repositories New anonymous bug bounty forum Finding more IDORs & SSRFs using a unique methodology New JavaScript file scanner to find hidden endpoints And so m

Continue reading: Intigriti Bug Bytes #232 - January 2026 πŸš€