
Hey there! Man, it’s been an insane year, both in my personal life and in bug bounty. This is my first post since April, and I’ve definitely missed doing this regularly. I appreciate you still being around and opening this email.
So, where have I been? As I mentioned earlier this year, I decided to temporarily deprioritize the newsletter to go heads down on building AI automation and an autonomous bug bounty system. Months later, that decision has really paid off. I’m having by far my best year in bug bounty, and I’ve learned A TON about AI engineering, safety controls, and token optimization along the way. There’s still much more to learn, but I’ve really enjoyed building.
At HackerOne, I’ve also been lucky enough to run Live Hacking Events in Japan, Lisbon, Berlin, and Cork since April. Between my day job, hacking, and organizing the third Bug Bounty Village at DEF CON, I’ve been super tied up these past few months.
Unrelated, I’ve been considering going after the OSAI certification from OffSec. I feel like the more we learn about offensive AI right now, the more relevant we’ll continue to be as the space evolves. Has anybody in the bug bounty community completed it? If so, has it proven to be a worthwhile investment? Let me know. I’m genuinely curious.
Anyway, let’s dive in.
P.S. We’re now publishing full talks from DEF CON on the Bug Bounty Village YouTube channel. More recordings will continue to drop each week, so make sure to check those out!

Nothing to promote; I’m just happy you’re here.

Hacktron AI Details a Chained Intrusion into OpenAI [📓 Blog]
by Hacktron AI (@HacktronAI)
Hacktron AI documents a July 2026 exploit chain starting with a libheif heap buffer overflow reachable via ImageMagick conversions, culminating in RCE on Discourse and downstream identity/SSO abuse. The post covers exploit development constraints (ASLR, jemalloc) and how LLM assistance accelerated iteration, plus affected versions and patch guidance. The main lesson is that image-processing supply chains and IdP flows can compound into org-wide impact.
Unsigned JWTs in Microsoft Analytics API Could Expose Trillions of Records [📓 Blog]
by Faav (@efaav)
Faav describes an auth flaw in an internal Microsoft analytics API that accepted unsigned JWTs, enabling role/identity spoofing via claim manipulation and unlocking arbitrary SQL queries. The write-up walks through endpoint discovery and validation, with careful sampling to avoid PII while estimating scale from metadata counts.
Have something you want to Spotlight? Tell me.

Meta’s Muse AI-Agent Bounty Goes Public (Up to $300K) [📣 Update]
by Meta
Meta’s bug bounty page now advertises a public program for Muse, including payouts up to $300,000 for qualifying security issues and high-impact prompt injection. It’s a notable signal that agentic/LLM products are getting first-class bounty treatment with explicit reward bands.
Anthropic Threat Intelligence Report (September 2026): AI Misuse in the Wild [📣 Update]
by Anthropic
Anthropic’s September 2026 report summarizes observed misuse of Claude models across multiple harm areas, with a heavy focus on AI-augmented cyber operations. It details multi-agent automation of phishing and intrusion workflows, malware rebuilding for evasion, and account-takeover tradecraft, alongside a GTG taxonomy and supporting indicators. For defenders, it’s a useful map of where “uplift” from LLMs is showing up operationally (speed, scale, and depth).
by Intel
Intel has quietly suspended its paid bug bounty, which paid up to $100,000 per vulnerability across hardware, firmware, software and open source. It's been replaced with a vulnerability disclosure program on Intigriti that explicitly accepts reports "without bounties." You can still report to Intel, you just won't get paid for it.
Vercel Consolidates Its Bug Bounty Programs Into One Public HackerOne Program [📣 Update]
by vercel (@vercel)
Vercel announced that its private and OSS bounties are now unified into a single public HackerOne program spanning Vercel products and open-source projects. The post frames the change as partly driven by AI-inflated report volume and describes internal tooling and process changes to keep triage efficient. Scope, bounty bands, and submission rules live on the HackerOne program page.
by Microsoft Security Response Center (MSRC)
MSRC revised its Dynamics 365 and Power Platform bounty on September 14. The headline change is new cross-tenant multipliers, which add +100% or +50% to the award for qualifying scenarios where a bug crosses tenant boundaries. Awards now run up to $60,000 for critical vulnerabilities, with more granular severity and impact categories.
Adobe’s Bug Bounty Program Moves to Intigriti (September 1, 2026) [📣 Update]
by Intigriti
Adobe announced its public bug bounty program is migrating to Intigriti, with the new program going live September 1, 2026. The post covers continuity expectations for submissions during the transition and points researchers to the new Intigriti program page. No technical research here—this is strictly a platform and process change.
Anthropic Releases Claude Opus 5.5 [📣 Update]
by Luke Stephens (@hakluke)
Anthropic announces Claude Opus 5.5 with performance/cost claims and updated safety controls, including prompt-injection hardening and tooling around auditing agent actions. For offensive security teams, it’s most relevant as a capabilities update for what agentic workflows can do (and what safeguards may block).
Intigriti Launches CrowdRecon (Public Beta) [📣 Update]
by Intigriti
Intigriti announced CrowdRecon, a feature aimed at sharing crowd-led recon insights around exposure, scope coverage, and follow-up between reports. The tweet points to a blog post and a public beta sign-up for researchers who want early access.

by YesWeHack
Round two in Buenos Aires: Banco Galicia, Bug Bounty Argentina and YesWeHack are teaming up again for a live hacking event at ekoparty 2026, October 7–9. It's open to all conference attendees, not invite-only, so if you're heading to ekoparty this is a rare chance to hack a live target alongside the event crowd.
NahamCon Announces “Prompt2Pwn” Live Hacking Event for 2026 [𝕏 Tweet]
by Ben Sadeghipour (@NahamSec)
NahamSec teased a new in-person NahamCon format called “Prompt2Pwn,” positioned as a live hacking event. The announcement notes that keynotes and location details will follow.
Did I miss an important update? Tell me.

reburp: Expose Burp’s Montoya API via OpenAPI [𝕏 Tweet]
by forefy (@forefy)
reburp is a Burp extension that exposes the Montoya API as a local OpenAPI-described REST interface. It enables external scripts or agents to drive Burp workflows programmatically (e.g., scanning, fuzzing, sitemap iteration, and WebSocket handling) without writing a full extension.
ars0n-framework-v2 Beta 0.1.0 [🛠️ Tool]
by Harrison Richardson (@rs0n)
ars0n-framework-v2 ships a beta release focused on an MCP-based architecture for orchestrating AI agents and integrating a large set of bug-hunting tools behind a GUI. The release notes call out a completed URL workflow, per-tool configuration support, and client-side performance improvements for large recon datasets.
geminiHunter: Scan for Exposed Google Gemini API Keys (Web + Android) [🛠️ Tool]
by Daniel Púa (@devploit)
geminiHunter scans web assets and Android apps for exposed Gemini API keys, including extraction from bundled JS, source maps, and decompiled APKs. It validates candidates via API checks and can optionally probe “403” responses with bounded variations to identify misconfigurations. Outputs are designed for reporting, with JSON export and reproducible curl evidence.
tturl Released: Operationalizing Timing-Attack Techniques [𝕏 Tweet]
by Shubs (@infosec_au)
Shubs shares the release of tturl alongside timing-attack research presented at BSidesCbr. The project aims to make timing techniques easier to run and measure in practice, bridging the gap between theory and repeatable testing.
Burp + HTTP/3: Turbo Intruder Support and an HTTP/3 Adapter Extension [📓 Blog]
by James Kettle (@albinowax)
PortSwigger adds HTTP/3 support to Turbo Intruder via a new adapter extension, enabling high-rate fuzzing and direct access to HTTP/3-only edge cases. The post includes tuning guidance and demos HTTP/3-specific race techniques (including QPACK blocked-stream behavior) plus downgrade/header-injection testing patterns.
Nuclei Template for CVE-2026-87902 (WordPress Template Path Traversal) [🛠️ Tool]
by ProjectDiscovery
ProjectDiscovery published a nuclei template targeting CVE-2026-87902, a WordPress core path traversal that can force inclusion of readable PHP files outside the active theme via get_page_template(). The template automates page-ID discovery and attempts multiple traversal vectors, then confirms behavior via footer/OPML markers.
Nuclei Template for CVE-2026-85706 (GitLab Unauthenticated File Read) [🛠️ Tool]
by ynsmroztas/GitLabSniper
This nuclei template probes for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE caused by percent-decoding inconsistencies between Workhorse and Puma/Grape. It sends a crafted POST request and matches on response traits consistent with the vulnerable code path.
Have a favorite tool? Tell me.

Out of Bounds, Out of Sandbox: RCE in the Goja JavaScript Engine [📓 Blog]
by Searchlight Cyber (@SLCyberSec)
Searchlight Cyber details an out-of-bounds heap write in Goja (TypedArray.prototype.with/toReversed) that can be turned into arbitrary read/write and full RCE. The write-up walks through heap shaping, ArrayBuffer length corruption, pointer recovery, and hijacking execution by overwriting a Go function pointer. It includes PoC snippets and remediation guidance for products embedding Goja.
Breaking into Google’s GFile for $100K [📓 Blog]
by Arvin Shivram (@Arvin Shivram)
Arvin Shivram explains how mining discovery docs at scale led to an internal Google RPC surface where undocumented methods were still reachable via generic /$rpc/<service>/<method> routing. The write-up covers reconstructing protobuf request schemas with reverse-engineering tools and LLM-assisted analysis to build valid calls and reach impact.
Valid, But Never Issued: Session Spoofing and SSRF in Grafana MCP [📓 Blog]
by Ariel Fogel (@Pillar_sec)
Pillar Security reports two issues in Grafana MCP: session IDs were accepted without authenticating callers (enabling tool execution with server-side privileges), and grafana_api_request allowed method-capable SSRF (CVE-2026-19516). The post shows how these primitives enable credential exposure and IMDS-style flows, then maps fixes introduced in mcp-grafana v1.1.0.
8x8 Automation Builder RCE (Twice): Jint Escape and Newtonsoft TypeNameHandling Bypass [📓 Blog]
by kyotozx
kyotozx details an RCE in 8x8 Automation Builder that started with a Jint template escape exposing CLR objects, then escalated via .NET reflection and unsafe deserialization paths. After an initial patch, a second bypass abused overload selection and serializer coercion to re-enable attacker-controlled TypeNameHandling and trigger Process execution.
test2shells: When a “Valid” URL Turns Into Command Injection [📓 Blog]
by Manuel Valdez (@saur1n)
Manuel Valdez describes two command injection bugs in a cloud provisioning platform caused by passing an attacker-controlled “SSH host” value into a shell-invoked curl command. The write-up shows how initial SSRF-style probing failed, but the observed curl User-Agent hinted at the real primitive: shell argument injection leading to root-level execution in one case.
GeoNetwork Pre-auth RCE Chain via Unauthenticated Formatter Upload + Unsafe XSLT [📓 Blog]
by André Baptista (@0xacb)
This write-up details an unauthenticated RCE chain in GeoNetwork, centered on a formatter upload endpoint missing authorization and unsafe Saxon XSLT processing that can reach java.lang.Runtime. It also documents additional issues (SSRF and reflected XSS) and shows how chaining increases impact.
Write-up: Jailbreaking Claude Code Opus 5 Auto Mode [𝕏 Tweet]
by Gareth Heyes (@garethheyes)
Gareth Heyes links to a full write-up demonstrating a jailbreak of Claude Code Opus 5 Auto Mode. The material focuses on the specific prompt/interaction pattern used to bypass protections and produce an actionable PoC.
Did I miss something? Tell me.

AI Customer Service Agents: Attack Surface and Exploitation Paths [𝕏 Tweet]
by Intigriti
Intigriti shares an article (based on a DEF CON talk) mapping common failure modes in AI customer service agents, including spoofed identity via email workflows and unauthorized tool execution. The focus is on real-world exploitation paths that don’t require traditional scanners, but instead abuse business logic and validation gaps around agent “actions.”
Using Codex for Bug Bounty Research and Validation [📓 Blog]
by YesWeHack
YesWeHack outlines a Codex-based workflow for bug bounty research, including model selection, evidence-driven validation, and integrations via MCP (e.g., Burp and Playwright). The post emphasizes multi-agent orchestration with hypothesis tracking and “critic” loops to reduce false positives, backed by case studies and lab testing.
Build Reproducible One-Command PoCs with Built-In Tests [𝕏 Tweet]
by Critical Thinking Podcast
CTBB shares practical guidance for writing PoCs that double as tests: single-command execution, minimal dependencies, and clear pass/fail output that’s easy for triage teams to rerun. It also recommends tagging traffic (e.g., X-POC-Actor) and baking environment setup into automation to support reliable retesting.
How to Hack APIs in 2026 [📓 Blog]
by Luke Stephens (@hakluke)
This Detectify Labs guide updates a practical API testing methodology: discovery/mapping (JS and mobile analysis, OpenAPI/GraphQL), tooling suggestions, and a prioritized vulnerability checklist. It focuses on the highest-ROI classes—authorization failures (BOLA/IDOR), auth token/OAuth/OIDC pitfalls, mass assignment, and async/rate/race issues—alongside SSRF and data exposure.
Silent Patches and the Attacker–Defender Gap (CVE-2023-54391 Case Study) [📓 Blog]
by YesWeHack
YesWeHack examines CVE-2023-54391 (a Proxmox VE auth bypass fixed quietly in 2023 and exploited later) as a case study in “silent patches.” It shows how AI-assisted commit mining reduces the effort to turn unannounced fixes into weaponizable diffs, widening the asymmetry between attackers and CVE-driven defenders.
Cache Key Injection: Smuggling Poison Through the Door [📓 Blog]
by YesWeHack
YesWeHack introduces “cache key injection,” where ambiguous concatenation of cache-key fragments creates attacker-controlled collisions that enable cache poisoning. The post includes Nginx configuration examples, black-box detection strategies, and scenarios involving layered caches (e.g., poisoning an origin cache behind a CDN).
Did I miss something? Tell me.

Exfil Everything: A Year of Stealing Data from AI Agents [🎥 Video]
by Antisyphon Training (@Antisy_Training)
This talk surveys real-world exfiltration bugs in AI agents and frames them as trust-boundary failures reminiscent of early XSS. It walks through multiple exploit chains (unfurling/markdown tricks, URL/image proxy issues, Unicode bypasses, malicious MCP servers, and DNS-based leaks) and discusses how common mitigations fail in practice.
“Easiest RCE Payload Ever” (DEF CON 34, Bug Bounty Village) [🎥 Video]
by Bug Bounty Village
Tobias Diehl shows how sftp:// links can expose weak URL scheme validation and, via OS protocol handlers and desktop app handoffs (Electron/WebView2), escalate to RCE. The talk includes hunting patterns and case studies across popular products, emphasizing web-to-desktop escalation and the value of retesting “fixed” issues.
Cache Poisoning: The Cache You Can’t Purge [🎥 Video]
by Amr Elsagaei (@amrelsagaei)
Amr Elsagaei demos a Next.js cache poisoning class where an internal response cache keys on pathname and trusts x-now-route-matches, letting attackers flip cacheability and persist responses on disk. The talk reproduces a zero-click stored XSS chain and critiques the upstream “header scrubbing” fix as a narrow door-closing patch. It also covers fingerprinting strategies and how to communicate cache impact clearly in reports.
Browser Logic Errors and XS-Leaks (with Jorian Woltjer) [🎥 Video]
by Critical Thinking Podcast
This episode digs into browser logic bugs and XS-Leaks, including practical techniques for status-code leaks via history/:visited and timing side channels. The discussion connects bounty-relevant wins to browser mechanics like cookie scoping, rendering behavior, and performance measurement. It’s useful for anyone building a modern client-side exfiltration playbook beyond “classic” XSS.
How to Build an AI Hacking Agent with Custom Skills [🎥 Video]
by zack0x01
zack0x01 demonstrates building an autonomous hacking agent using the Hermes framework, including model configuration, a Telegram bot, and custom skill modules. The video focuses on wiring tooling into an orchestrated recon/monitoring loop and shows a live demo against test targets.
Password Reset Bypass Leaked 2,480 Employee Records (Report Breakdown) [🎥 Video]
by Logan-sec (Logan-sec)
This video breaks down a HackerOne report where weaknesses in account recovery enabled bypassing verification steps and exposing employee data. It focuses on how cross-feature interactions in auth flows can create non-obvious attack paths beyond single-endpoint testing.
What 12 Years of Bug Bounty Reports Look Like Through Claude [🎥 Video]
by Ben Sadeghipour (@NahamSec)
NahamSec feeds a large personal archive of bug bounty reports into Claude to extract patterns in vulnerability types, impact framing, and what made submissions land. The video is primarily about using LLMs for retrospectives and workflow improvement—categorization, report quality, and prioritization—rather than live exploitation.
Did I miss something? Tell me.

SCIM Auth Bypass via Path Normalization (%55) [𝕏 Tweet]
by 𝐤𝐣𝐮𝐥𝐢𝐮𝐬 (@ethical_h4ck3r_)
A tweet highlights a SCIM path normalization edge case where encoding “U” as %55 in /scim/v2/{org}/%55sers/{user_id} returned a user object without auth. The unencoded path reportedly produced a 401, suggesting inconsistent routing/auth middleware across normalized and raw paths.
Array-Wrapped IDs Can Turn Equality Checks into IN() (Node ORM IDOR) [𝕏 Tweet]
by André Baptista (@0xacb)
André Baptista notes a common pitfall where supplying an array instead of a scalar ID can cause ORMs like Sequelize/Mongoose to emit WHERE id IN (...). In apps that treat the request field as a single-user identifier, this can become a multi-object IDOR with a trivial payload shape change.
User-Controlled Identity Claim Enabled Impersonation [𝕏 Tweet]
by Marius du Preez (@mdp_sec)
Marius du Preez describes a case where a low-privileged user could edit a custom identity claim that the backend treated as authoritative. Swapping it to another user’s key resulted in the victim’s session being served, illustrating how authz collapses if the identity primitive itself is user-controlled.
Chatbot URL Prompt Injection, Cache Side-Channels, and CDN Constraints [𝕏 Tweet]
by Critical Thinking Podcast
CTBB shares hunting notes on chatbot prompts sourced from URL parameters, enabling prompt injection on link click without additional interaction. It also discusses exfil constraints imposed by “images only from CDN” policies and how per-user cached asset paths can become a cache-hit side channel for incremental leakage.
Email Spoofing PoC Leaks User Data via AI Support Agent Workflows [𝕏 Tweet]
by Intigriti
A tweet describes a PoC where spoofing the From header on a GDPR request and CC’ing an attacker address caused an AI support workflow to send victim data to both recipients. The core issue is weak identity verification in email-based support flows, amplified by automated agent behavior across many organizations.
Black-Box Benchmark Tests Bug-Bounty Agents on 100 Real Labs [𝕏 Tweet]
by Marius du Preez (@mdp_sec)
Marius du Preez shares results from a black-box benchmark built from 100 real bug bounty vulnerabilities converted into isolated web/API labs. The thread compares nine agents on solve rate, partial progress, token usage, and normalized cost, highlighting that “best model” depends heavily on task shape and retry behavior.
Plugin4Shell: Agent Plugin Updates Can Bypass SHA Pinning [𝕏 Tweet]
by VIEH Group
VIEH Group describes a zero-click RCE class where coding agents pin plugins to a commit SHA but fail to verify the checked-out HEAD after fetch/checkout. An attacker controlling a branch can cause agents to pull unintended code during background updates, despite “pinned” references. The fix is post-checkout integrity verification, not just pinning.
Did I miss something? Tell me.
Because Disclosure Matters: This newsletter was produced with the assistance of AI. While I strive for accuracy and quality, not all content has been independently vetted or fact-checked. Please allow for a reasonable margin of error. The views expressed are my own and do not reflect those of my employer.










