Bug Bytes #209 – The only graphQL wordlist you need, ML bug hunting and VDP submissions

By travisintigriti

August 23, 2023

Last updated on August 8, 2026

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by InsiderPhD. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources.

This issue covers the week from August 14th – August 20th

Intigriti News

From my notebook

  1. Episode 32: The Great Write-up Low-down

  2. graphql-wordlist – The only graphql wordlists you’ll ever need.

  3. Episode 388 – Video game vulnerabilities

  4. Google Online Security Blog: AI-Powered Fuzzing: Breaking the Bug Hunting Barrier

  5. Weaponizing ML models for red teams and bounty hunters

Join 125,000+ Security Researchers Getting Monthly Bug Bounty Tips & Insights!

You may also like

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising OpenAI, Slack, Meta, and more via a vulnerable image library Hacking OpenAI employee accounts in under 72 hours Breaking into Google's GFile for $100K Hacking AI CX agents Turbo Intruder 2 surpassing

Read more: Intigriti Bug Bytes #240 - September 2026 🚀

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready

Read more: Intigriti Bug Bytes #239 - August 2026 🚀

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo

Read more: Intigriti Bug Bytes #238 - July 2026 🚀