Excited to share that Intigriti has been named the new provider for Adobe's Bug Bounty Program, effective September 1, 2026! 🪲 www.intigriti.com/blog/news/in...
Intigriti
@intigriti.com
Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍 linktr.ee/hackwithintigriti
Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Intigriti turns 10! ✅ RCE in GitHub and GitHub Enterprise Server ✅ Burp Suite going agentic with Burp AT ✅ Hacking Gemini Enterprise for $15,000 ✅ 3,708 live credentials found by scanning GitHub Archive
Intigriti turns 10! 🚀 For a decade, we’ve brought ethical hackers and organizations together to make the digital world safer.
Last week, we wrapped up #BugQuest! 🤠 In 31 days, we dived deep into broken access control vulnerabilities, and it's now available as one comprehensive guide! 🧐
That's a wrap on #BugQuest! 🏁 Over the past 31 days, you've learned the fundamentals of finding and exploiting broken access control vulnerabilities. We've covered everything from authentication vs authorization basics to spotting subtle bypasses in code reviews.
Day 31 of #BugQuest! 😎 Yesterday, we covered Firefox Multi-Account Containers for manual testing across multiple user sessions. Today, we're wrapping up with Autorize, an open-source Burp Suite extension.
Today marks day 29 of #BugQuest! 🤠 For those who’ve been following us along since the first day, we’re almost there! Just 2 more days left before you can go there and hack the planet (with BAC vulnerabilities)!
Day 28 of #BugQuest! 🤠 Yesterday, we featured another code snippet, this time vulnerable to an algorithm confusion attack that allowed a malicious user to bypass signature validation entirely in insecure JWT implementations.
Today marks day 27 of #BugQuest! 🤠 We’re almost wrapping up this series, so if you’ve reached this far, you should be proud of your consistent efforts! 💪
Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Earning $180K via SSRFs ✅ Free Burp Suite Pro licenses for top hackers ✅ Bypassing tricky file upload restrictions ✅ Injecting malicious code into AI coding assistants + company news & much more! 😎
Day 26 of #BugQuest! 🤠 Yesterday's challenge featured a method-specific authorization check where GET requests were protected, but POST/PUT or any other requests bypassed the authorization entirely, allowing attackers to modify any user's profile data.
Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.
As Intigriti 0326 wraps up, we're releasing the official write-up for March’s CTF challenge! 🤠 KulinduKodi presented us with a secure search portal that required chaining a tricky DOM clobbering with a CSP bypass to achieve client-side code execution on the challenge page on behalf of the admin! 😎
🚀 I’m now an @intigriti.com Hacker Ambassador for Germany 🇩🇪 Kicking things off with my first event: 🔥 Bug Bounty Meetup Stuttgart 📅 April 19, 2026 📍 Shackspace (Ulmer Str. 300, Stuttgart) 🕒 14:00 – Open End All levels welcome 🤝 👉 forms.gle/w1oLU61U8DQx...
Day 24 of #BugQuest! 🤠 Yesterday’s challenge involved spotting a common missing authorization check in an endpoint that allowed any bad user to view other people’s order data. Today's challenge is trickier! This vulnerability pattern was covered on Day 19, where we learned about REDACTED. 😎
Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.
Day 23 of #BugQuest! 🤠 Today also marks the start of the practice section of this series! Over the next week, we'll be featuring several vulnerable code snippets to help you spot more broken access controls. Let’s start easy! Can you spot the vulnerability in the following code snippet? 🐛
Day 22 of #BugQuest! 🤠 Today marks the final day for exploitation! Next up, we’ll analyze vulnerable code snippets to further sharpen your BAC exploitation skills. 😎
Broken access controls can be quite complex to find... 😓 but sometimes surprisingly easy to exploit! 🤠 However, you must have the right methodology. 🧐 In our latest article, we break down what authorization flaws are, a 3-step methodology, and 7 proven broken access exploitation techniques! 🤠
Today marks day 21 of #BugQuest! 🤠 And we're covering one of the trickiest BAC vulnerability types that’s harder to spot. We all know that broken access controls do not always stem from a single endpoint that lacks authorization controls.
Day 20 of #BugQuest! 🤠 Today, we're exploring one of the most critical authorization (and authentication) bypass techniques: JWT token manipulation. JWTs (JSON Web Tokens) are commonly implemented to manage authentication within web applications.
Can you hack an AI bot? 🤠 If you want to find out if you've got what it takes to hack AI, come see our team at RSAC Booth S-1161! 🧐 🔥 Three difficulty levels 🏆 Three top-tier prizes 🧠 One question... Can you think like a hacker? 😎
Day 19 of #BugQuest! 🤠 In today’s post, we're covering a technique that's deceptively simple but incredibly effective: swapping static keywords with actual identifiers.
Today marks day 18 of #BugQuest! 🤠 And we're exploring two interesting techniques that can help us exploit BAC flaws in applications that fail to handle user input delivered in an unexpected manner.
Day 17 of #BugQuest! 🔄 Yesterday, we covered the core BAC testing methodology. Today, we're diving into a specific exploitation technique. Developers often implement authorization checks for each HTTP method and app route, but often overlook others.
Today marks day 16 of #BugQuest and the start of the exploitation section! 🎯 We've spent two weeks building the foundation and discovering endpoints. Now comes the fun part, actually breaking authorization checks and exploiting BAC vulnerabilities.
My writeup for @intigriti.com's "InkDrop" challenge 🖋 cryptocat.me/blog/ctf/mon...
Stored XSS + JSONP Callback Injection to Cookie Exfiltration | Intigriti 02-26: InkDrop | CryptoCat's Blog
Intigriti 02-26 writeup: unsafe markdown rendering leads to stored XSS, which is executed via a client-side script reinjection gadget loading /api JSONP, allowing CSP bypass and bot flag cookie exfilt...
cryptocat.me