Sign in

Intigriti

@intigriti.com
384 followers 8 following 405 posts

Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍 linktr.ee/hackwithintigriti

PostsRepliesMedia
Intigriti @intigriti.com · 03/09/2026
Most support chatbots have evolved into fully autonomous agents that can help you with almost anything... And that comes with additional risk ☝️ www.intigriti.com/researchers/...
100
Intigriti @intigriti.com · 20/08/2026
When fuzzing is no longer treated as merely bruteforcing, you start to unlock meaningful results 🤠 From discovering hidden assets to turning unusual behavior into exploitable vulnerabilities! 😎
120
Intigriti @intigriti.com · 13/08/2026
Disagree with how your report was handled? 😓 It can happen ☝️ At Intigriti, we have a mediation process in place to help researchers work toward a fair resolution. In our latest article, we walk you through how it works, how you can appeal a bug bounty submission on Intigriti...
100
Intigriti @intigriti.com · 12/08/2026
We will be at Hack Glasgow! 🤠 Come find us at the Citizens Theatre in Glasgow on Saturday, August 15th. Meet the Intigriti team, learn about bug bounty, and grab some cool swag! 😎 See you there!
020
Intigriti @intigriti.com · 10/08/2026
Something exciting is coming. 👀 At DEF CON 34, our Senior Product Manager Radu, stepped into the Bug Bounty Village to give the first look at CrowdRecon, a project the Intigriti team has been building for months.
110
Intigriti @intigriti.com · 08/08/2026
Vulnerability Vibes was a blast! 🤠 The vibes were unmatched, the conversations were solid, and the poster got signed by some of the best in the community. Nothing tops meeting the people behind the handles in person. Big shoutout to the organizers, sponsors and anyone else for making this happen!🙌
010
Intigriti @intigriti.com · 06/08/2026
Learn to craft your bug bounty methodology! 👇
110
Intigriti @intigriti.com · 04/08/2026
Excited to share that Intigriti has been named the new provider for Adobe's Bug Bounty Program, effective September 1, 2026! 🪲 www.intigriti.com/blog/news/in...
100
Intigriti @intigriti.com · 31/07/2026
Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Intigriti turns 10! ✅ RCE in GitHub and GitHub Enterprise Server ✅ Burp Suite going agentic with Burp AT ✅ Hacking Gemini Enterprise for $15,000 ✅ 3,708 live credentials found by scanning GitHub Archive
110
Intigriti @intigriti.com · 29/07/2026
Intigriti turns 10! 🚀 For a decade, we’ve brought ethical hackers and organizations together to make the digital world safer.
120
Intigriti @intigriti.com · 07/04/2026
Last week, we wrapped up #BugQuest! 🤠 In 31 days, we dived deep into broken access control vulnerabilities, and it's now available as one comprehensive guide! 🧐
120
Intigriti @intigriti.com · 01/04/2026
That's a wrap on #BugQuest! 🏁 Over the past 31 days, you've learned the fundamentals of finding and exploiting broken access control vulnerabilities. We've covered everything from authentication vs authorization basics to spotting subtle bypasses in code reviews.
100
Intigriti @intigriti.com · 31/03/2026
Day 31 of #BugQuest! 😎 Yesterday, we covered Firefox Multi-Account Containers for manual testing across multiple user sessions. Today, we're wrapping up with Autorize, an open-source Burp Suite extension.
100
Intigriti @intigriti.com · 30/03/2026
Day 30 of #BugQuest! 🦊 We've reached the final day of practice challenges!
100
Intigriti @intigriti.com · 29/03/2026
Today marks day 29 of #BugQuest! 🤠 For those who’ve been following us along since the first day, we’re almost there! Just 2 more days left before you can go there and hack the planet (with BAC vulnerabilities)!
100
Intigriti @intigriti.com · 28/03/2026
Day 28 of #BugQuest! 🤠 Yesterday, we featured another code snippet, this time vulnerable to an algorithm confusion attack that allowed a malicious user to bypass signature validation entirely in insecure JWT implementations.
100
Intigriti @intigriti.com · 28/03/2026
Exploiting BAC vulnerabilities! 🤠
100
Intigriti @intigriti.com · 27/03/2026
Today marks day 27 of #BugQuest! 🤠 We’re almost wrapping up this series, so if you’ve reached this far, you should be proud of your consistent efforts! 💪
100
Intigriti @intigriti.com · 27/03/2026
Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Earning $180K via SSRFs ✅ Free Burp Suite Pro licenses for top hackers ✅ Bypassing tricky file upload restrictions ✅ Injecting malicious code into AI coding assistants + company news & much more! 😎
110
Intigriti @intigriti.com · 26/03/2026
Day 26 of #BugQuest! 🤠 Yesterday's challenge featured a method-specific authorization check where GET requests were protected, but POST/PUT or any other requests bypassed the authorization entirely, allowing attackers to modify any user's profile data.
100
Intigriti @intigriti.com · 25/03/2026
Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.
100
Intigriti @intigriti.com · 25/03/2026
As Intigriti 0326 wraps up, we're releasing the official write-up for March’s CTF challenge! 🤠 KulinduKodi presented us with a secure search portal that required chaining a tricky DOM clobbering with a CSP bypass to achieve client-side code execution on the challenge page on behalf of the admin! 😎
101
Reposted by Intigriti
Oli (C..1..P.H.Y) @munz4u.de · 25/03/2026
🚀 I’m now an @intigriti.com Hacker Ambassador for Germany 🇩🇪 Kicking things off with my first event: 🔥 Bug Bounty Meetup Stuttgart 📅 April 19, 2026 📍 Shackspace (Ulmer Str. 300, Stuttgart) 🕒 14:00 – Open End All levels welcome 🤝 👉 forms.gle/w1oLU61U8DQx...
111
Intigriti @intigriti.com · 24/03/2026
Day 24 of #BugQuest! 🤠 Yesterday’s challenge involved spotting a common missing authorization check in an endpoint that allowed any bad user to view other people’s order data. Today's challenge is trickier! This vulnerability pattern was covered on Day 19, where we learned about REDACTED. 😎
100
Intigriti @intigriti.com · 24/03/2026
Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.
100
Intigriti @intigriti.com · 23/03/2026
Day 23 of #BugQuest! 🤠 Today also marks the start of the practice section of this series! Over the next week, we'll be featuring several vulnerable code snippets to help you spot more broken access controls. Let’s start easy! Can you spot the vulnerability in the following code snippet? 🐛
100
Intigriti @intigriti.com · 22/03/2026
Day 22 of #BugQuest! 🤠 Today marks the final day for exploitation! Next up, we’ll analyze vulnerable code snippets to further sharpen your BAC exploitation skills. 😎
100
Intigriti @intigriti.com · 21/03/2026
Broken access controls can be quite complex to find... 😓 but sometimes surprisingly easy to exploit! 🤠 However, you must have the right methodology. 🧐 In our latest article, we break down what authorization flaws are, a 3-step methodology, and 7 proven broken access exploitation techniques! 🤠
100
Intigriti @intigriti.com · 21/03/2026
Today marks day 21 of #BugQuest! 🤠 And we're covering one of the trickiest BAC vulnerability types that’s harder to spot. We all know that broken access controls do not always stem from a single endpoint that lacks authorization controls.
100
Intigriti @intigriti.com · 20/03/2026
Day 20 of #BugQuest! 🤠 Today, we're exploring one of the most critical authorization (and authentication) bypass techniques: JWT token manipulation. JWTs (JSON Web Tokens) are commonly implemented to manage authentication within web applications.
100
Intigriti @intigriti.com · 20/03/2026
Can you hack an AI bot? 🤠 If you want to find out if you've got what it takes to hack AI, come see our team at RSAC Booth S-1161! 🧐 🔥 Three difficulty levels 🏆 Three top-tier prizes 🧠 One question... Can you think like a hacker? 😎
101
Intigriti @intigriti.com · 19/03/2026
Day 19 of #BugQuest! 🤠 In today’s post, we're covering a technique that's deceptively simple but incredibly effective: swapping static keywords with actual identifiers.
100
Intigriti @intigriti.com · 19/03/2026
Testing for broken access control flaws! 👇
000
Intigriti @intigriti.com · 18/03/2026
Today marks day 18 of #BugQuest! 🤠 And we're exploring two interesting techniques that can help us exploit BAC flaws in applications that fail to handle user input delivered in an unexpected manner.
100
Intigriti @intigriti.com · 17/03/2026
Day 17 of #BugQuest! 🔄 Yesterday, we covered the core BAC testing methodology. Today, we're diving into a specific exploitation technique. Developers often implement authorization checks for each HTTP method and app route, but often overlook others.
100
Intigriti @intigriti.com · 16/03/2026
Today marks day 16 of #BugQuest and the start of the exploitation section! 🎯 We've spent two weeks building the foundation and discovering endpoints. Now comes the fun part, actually breaking authorization checks and exploiting BAC vulnerabilities.
100
Reposted by Intigriti
CryptoCat @cryptocat.me · 25/02/2026
My writeup for @intigriti.com's "InkDrop" challenge 🖋 cryptocat.me/blog/ctf/mon...
cryptocat.me
Stored XSS + JSONP Callback Injection to Cookie Exfiltration | Intigriti 02-26: InkDrop | CryptoCat's Blog
Intigriti 02-26 writeup: unsafe markdown rendering leads to stored XSS, which is executed via a client-side script reinjection gadget loading /api JSONP, allowing CSP bypass and bot flag cookie exfilt...
011
Reposted by Intigriti
jorenverheyen.bsky.social @jorenverheyen.bsky.social · 25/02/2026
My solution to this month @intigriti.com CTF challenge. CSP bypass allowing to setup a Blind XSS attack and an unexpected IDOR. jorenverheyen.github.io/intigriti-fe...
jorenverheyen.github.io
Intigriti's February 2026 CTF Challenge
021
Intigriti @intigriti.com · 15/03/2026
Day 15 of #BugQuest! 🤠 You've almost made it! Discovery week ends today! And we're exploring mobile app analysis, one of the most underrated methods for endpoint discovery. Mobile apps often communicate with completely different APIs than their web variants.
100
Intigriti @intigriti.com · 14/03/2026
Day 14 of #BugQuest! 🤠 We're almost wrapping up the discovery section with GraphQL APIs, one of the most powerful methods for discovering unreferenced endpoints (in GraphQL, it’s more about discovering queries and mutations).
100
Intigriti @intigriti.com · 13/03/2026
Today marks day 13 of BugQuest! We're almost 2 full weeks into #BugQuest! 🤠 We've covered discovering endpoints through active sources. Today, we're going to explore a passive method to enumerate more app routes and API endpoints.
100
Intigriti @intigriti.com · 12/03/2026
Day 12 of #BugQuest! 🤠 Today's topic is one of the easiest ways to find endpoints, and it's via public documentation. Developers create docs to help integrate with their APIs, but they often accidentally expose more than intended.
100
Intigriti @intigriti.com · 11/03/2026
Day 11 of #BugQuest! 🤠 Today we're diving into one of the most effective discovery methods: JavaScript file analysis. Modern web applications are packed with JavaScript code that reference API endpoints, application routes, and input parameters.
100
Intigriti @intigriti.com · 10/03/2026
Day 10 of #BugQuest! 🤠 We've covered content discovery through commonly exposed configuration files. Now it's time to scale up with automated content discovery and endpoint fuzzing. Tools like Ffuf, Feroxbuster, and Dirsearch can help you enumerate thousands of potential endpoints.
100
Intigriti @intigriti.com · 09/03/2026
Day 9 of #BugQuest! 🤠 Yesterday, we listed an overview of the primary ways to discover endpoints. Today, we're diving deep into one of the easiest and most overlooked methods: common configuration files.
110
Intigriti @intigriti.com · 08/03/2026
Day 8 of #BugQuest! 🤠 This week is all about finding the endpoints and resources you need to test for BAC vulnerabilities. Today, we're covering where to start your reconnaissance. BAC bugs can appear anywhere in an application, so thorough endpoint discovery is crucial.
100
Intigriti @intigriti.com · 07/03/2026
Day 7 of #BugQuest! 🤠 Theory part is almost over (we promise!)! We've covered what BAC is, how authentication and authorization work, and what counts as a valid finding. Today, we’re covering where you can spot BAC vulnerabilities. BACs can appear almost everywhere within an application or API.
110
Intigriti @intigriti.com · 06/03/2026
Day 6 of #BugQuest! 🤠 We're almost wrapping up theory week with a crucial topic: What actually counts as a valid BAC vulnerability in bug bounty? Not every authorization issue is impactful. Programs may reject findings that don't demonstrate real risk.
100
Intigriti @intigriti.com · 05/03/2026
Day 5 of #BugQuest! 🤠 We're almost wrapping up the theory section with one more crucial topic: authorization models. 😅 Applications use different models to decide who can access what. Understanding RBAC, ABAC, DAC, and MAC helps you identify which type of authorization check is missing or broken.
100
Intigriti @intigriti.com · 05/03/2026
Big news for our hacker community! 🤠 We're excited to launch the official Intigriti Hacker Ambassador Program, designed to support community leaders who are already making a difference through meetups, content creation, mentoring, and bringing hackers together! 😎
100