0xBugLetter

Curated archive · Bug bounty

The reading that’s worth it, without the noise.

A timeline of bug bounty writeups and research. Every entry is verified against its source and classified by bug type — so you can filter instead of scroll.

writeups
35
bug types
11
live sources
7

Latest

Recently added

see all →
HighInfo Disclosure

CSS: the bomb inside your inbox

CSS sanitizado en clientes de webmail resulta suficiente para exfiltrar tokens con attribute selectors, spoofear UI y montar un keylogger sin una línea de JavaScript. Afecta a Gmail, Outlook, Fastmail y ProtonMail.

Gareth HeyesPortSwigger Researchportswigger.net
InfoMethodology

Intigriti named new provider for Adobe's Bug Bounty Program

Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of

IntigritiIntigritiintigriti.com

How it works

The content lives in the repository

Everything is YAML

Each writeup is a file in data/writeups/. No database, no admin panel. The change history is the git history.

Contributed by PR

Add a file, open a pull request, and CI validates the schema. If it passes, it lands in the archive with your name on the commit.

The bot notifies

A GitHub Action checks the feeds daily and posts what's new to Discord. The site is the archive; the bot is the notification.