0xBugLetter

Archive

Writeups

Every entry was verified against its original source. Bounty amounts appear only when they are public — never estimated.

35 of 35 writeups

Aug 2026

7
HighInfo Disclosure

CSS: the bomb inside your inbox

CSS sanitizado en clientes de webmail resulta suficiente para exfiltrar tokens con attribute selectors, spoofear UI y montar un keylogger sin una línea de JavaScript. Afecta a Gmail, Outlook, Fastmail y ProtonMail.

Gareth HeyesPortSwigger Researchportswigger.net
InfoMethodology

Intigriti named new provider for Adobe's Bug Bounty Program

Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of

IntigritiIntigritiintigriti.com

Jul 2026

10
InfoMethodology

How to appeal a bug bounty submission

Qué hacer cuando un reporte válido se cierra como N/A o duplicado. Proceso concreto, no consejos genéricos.

Ayoub SafaIntigritiintigriti.com
InfoLLM / AI

RAG and ruin: why your existing controls may miss AI poisoning attacks

Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe recommendations. In agentic systems with tools and permissions, it can become data leakage, un

IntigritiIntigritiintigriti.com
InfoMethodology

AI’s convenience cost. The impact of the lethal trifecta on organizations today

The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails. This blog takes a look at the lethal

IntigritiIntigritiintigriti.com
HighLLM / AI

Oh My Rogue Agent

ProjectDiscoveryProjectDiscoveryprojectdiscovery.io
InfoMethodology

Introducing Internal Network Scanning: see your network the way an attacker inside it would

Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Internal scanning was supposed to catch exactly that but most scanners match a host's banner and version against a CVE list and flag everything potentially affected, so the few reachable exposures sit lost

ProjectDiscoveryProjectDiscoveryprojectdiscovery.io
InfoMethodology

The between-reports problem: why security teams miss what attackers see

What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What we believe security teams will need next: earlier signals that support action before the next repor

IntigritiIntigritiintigriti.com
InfoMethodology

Community Spotlight: Rishi (@rxerium)

“Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Rishi (@rxerium) If you’ve spent any time in the Nuclei Templates repository, you’ve almost certainly run something Rishi engineered. With over 500 templates merged, picked up by the likes of the UK’s National Cyber Security Center (NCSC), California Cybersecurity Integration Cente

ProjectDiscoveryProjectDiscoveryprojectdiscovery.io

Jun 2026

3
InfoMethodology

Reconnaissance for exposure management: why context matters in the AI era

Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!), and the human layer triage (The AI Impact), judgment, and prioritization has become more important, not less (CEO Insights). But there’s a deeper implication hiding underneath all of that: most security teams still only learn from

IntigritiIntigritiintigriti.com

May 2026

1

Feb 2026

1
InfoMethodology

Top 10 web hacking techniques of 2025

El ranking anual de la comunidad. Punto de partida obligado para entender qué técnicas movieron la aguja el año pasado.

PortSwigger ResearchPortSwigger Researchportswigger.net

Dec 2025

1

Nov 2025

1

Sep 2025

2

Aug 2025

3

Jul 2025

1

Apr 2025

2

Feb 2025

1

Jan 2025

1

May 2020

1