Ayoub
Author
Ayoub
Senior security content developer
Intigriti Bug Bytes #240 - September 2026 π
Bug Bytes
September 25, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising OpenAI, Slack, Meta, and more via a vulnerable image library Hacking OpenAI employee accounts in under 72 hours Breaking into Google's GFile for $100K Hacking AI CX agents Turbo Intruder 2 surpassing
Hacking AI customer service agents
Hacking Tools
September 2, 2026
As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be. At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire, Founding Memb
Intigriti Bug Bytes #239 - August 2026 π
Bug Bytes
August 28, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready
Web fuzzing for hackers
Hacking Tools
August 20, 2026
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crash
Intigriti Bug Bytes #238 - July 2026 π
Bug Bytes
July 31, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo
How to appeal a bug bounty submission
Hacking Tools
July 30, 2026
Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are mish
Intigriti Bug Bytes #237 - June 2026 π
Bug Bytes
June 26, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at scal
Exploiting web cache poisoning vulnerabilities
Hacking Tools
June 24, 2026
Web (or HTTP) caching is a highly adopted practice to effectively optimize web page loading times for clients. However, as with most technologies, when incorrectly implemented, it may open up a new exploitable attack surface for us to look into. In this article, we'll cover what web cache poisoning
Intigriti Bug Bytes #236 - May 2026 π
Bug Bytes
May 30, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sani
Exploiting SQL injection vulnerabilities
Hacking Tools
April 30, 2026
Most assume that SQL injection is a solved problem in today's application landscape, especially with increased awareness of secure coding practices (such as resorting to prepared statements or parameterized queries) and the widespread adoption of NoSQL databases. However, in practice, SQLi vulnerabi
Intigriti Bug Bytes #235 - April 2026 π
Bug Bytes
April 24, 2026
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising an NPM package with 40M weekly downloads Bypassing Cloudflare WAF for a full ATO 20-part series on exploiting JWT vulnerabilities First Intigriti Bug Bounty Meetup And so much more! Let's dive in! Bug
BugQuest 2026: 31 Days of Broken Access Control
Hacking Tools
April 1, 2026
In March 2026, we ran BugQuest, a 31-day campaign covering everything you need to know about finding and exploiting broken access control vulnerabilities. From understanding the basics of authentication and authorization to spotting subtle authorization bypasses in real code, we broke down one of th
Intigriti Bug Bytes #234 - March 2026 π
Bug Bytes
March 27, 2026
Welcome to the latest edition of Bug Bytes! In this monthβs issue, weβll be featuring: Earning $180K via SSRFs Free Burp Suite Pro licenses for top hackers Bypassing tricky file upload restrictions Injecting malicious code into AI coding assistants And so much more! Letβs dive in! We've teamed up wi
Intigriti 0326 CTF Challenge: Chaining DOM clobbering and CSP bypasses for XSS
Hacking Tools
March 25, 2026
At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security researcher community. This month's challenge, brought forward by Kulindu, presented us with a Secure Search Portal that, on the surface, appeared to be well protected. A strict Content Secu
Exploiting broken access control vulnerabilities
Hacking Tools
March 20, 2026
Broken access control vulnerabilities have consistently remained at the top of the OWASP Top 10, and for a good reason. As web applications continue to grow in complexity, with the introduction of role-based access controls, multi-tenant support, and granular permission models, the likelihood of acc
Intigriti Bug Bytes #233 - February 2026 π
Bug Bytes
February 20, 2026
Welcome to the latest edition of Bug Bytes! In this monthβs issue, weβll be featuring: How a read-only Kubernetes permission turned into full cluster takeover AI agent autonomously finds a 1-click RCE Race condition in blockchain infrastructure worth billions Finding over 500 high-severity vulnerabi
How to use AI for improved vulnerability report writing
Hacking Tools
February 17, 2026
Report writing is an integral part of bug bounty or any type of vulnerability assessment. In fact, sometimes, it can become the most important phase. Submitting a confusing report can often lead to misalignment and faulty interpretation of your reported vulnerability. On the contrary, a well-written
Exploiting PostMessage vulnerabilities: A complete guide
Hacking Tools
January 31, 2026
PostMessage vulnerabilities arise when developers fail to properly validate message origins or sanitize content within cross-origin communication handlers. As modern web applications increasingly rely on the postMessage API for cross-origin communication, whether for embedded widgets, OAuth flows, t
Intigriti 0126 CTF Challenge: Exploiting insecure postMessage handlers
Hacking Tools
January 28, 2026
At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security researcher community. January's challenge presented participants with CRYPTIGRITI, a cryptocurrency trading platform where users could buy and trade Bitcoin (BTC), Monero (XMR), and a custo
Intigriti Bug Bytes #232 - January 2026 π
Bug Bytes
January 16, 2026
Welcome to the latest edition of Bug Bytes (and the first of 2026)! In this monthβs issue, weβll be featuring: Hijacking official AWS GitHub repositories New anonymous bug bounty forum Finding more IDORs & SSRFs using a unique methodology New JavaScript file scanner to find hidden endpoints And so m
