This week, Disclosed.
#BugBounty
DEF CON 33 Badge Pre-Orders, Bug Bounty Village Agenda, HackAICon Announcement, NullCon Scholarships, Caido Acquires Shift, and more
Highlights below 👇
Full issue →
getdisclosed.com
@BugBountyDEFCON opened pre-orders for a limited edition Bug Bounty Village badge in a green variant. Pre-order online and pick up in person at the con.
@CaidoIO acquired the Shift plugin, now free for users with payload crafting and HTTPQL support.
@BugBountyDEFCON released the full agenda for Bug Bounty Village at DEF CON 33.
@0xacb announced HackAICon 2025 (Sept 25, Lisbon), featuring AI, hacking challenges, talks, and networking.
@nullcon is offering Bug Bounty Hunter Scholarships for their Berlin event (Sep 4–5). Apply by July 28.
@hackenproof announced a new bug bounty program for No Ones App with rewards up to $5k per bug.
@xss0r shared 6 new
@Microsoft domains now eligible for the Identity Bug Bounty program.
@yeswehack posted highlights from the live hacking event at leHACK 2025 in a recap video.
@Hacker0x01 updates their in-platform color scheme to align better with their updated marketing site.
PwnFox (via
@BApp_Store) adds multi-session, color-coded testing in Burp Suite.
@garethheyes announces Custom Actions to automate request rewriting and payload generation in Burp Suite.
@fneves97 updated JXScout Pro for improved JavaScript asset navigation in VSCode.
@adce626 launched the Bug Bounty Recon Toolkit, which generates commands for 50 tools based on target.
@KN0X55 introduced XSS Gym to train on real XSS payloads and scenarios.
@alicanact60 published a Chrome extension that restores the classic HackerOne UI.
From .git disclosure to RCE. The author details a full bug bounty chain from initial .git leak to remote code execution, with techniques and tools.
Leaking PII in Microsoft Guest Check-In. The author (Faav) shows how exposed PII and Burp Suite let them break into Microsoft buildings.
HackerOne report by
@MrMax4o4 documents how a banned user retained API access to a deleted account, exposing weak access controls.
@deadoverflow_ explains a race condition in Reddit’s coin API inflating coins via parallel requests.
@medusa_0xf highlights business logic vulnerabilities that led to real payouts.
@NahamSec shows JWT mistakes that enabled account takeover and big bounties.
@amrelsagaei interviews
@NahamSec on mindset, overcoming plateaus, and building a personal brand.
BePractical demonstrates exploiting zip slip on file uploads to overwrite paths.
@Magn4_ shares the story of earning his first bounty with a $100 open redirect.
@ctbbpodcast Ep.131 features live SSRF and IDOR hacks, leaked secrets, Google’s defense strategy, and community insights.
@cyb3r_dan shares an SQLi detection guide covering manual and automated techniques with practice labs.
@Bugcrowd explains how to find bugs on hardened targets by chaining smaller flaws.
@coffinxp7 publishes an advanced bug bounty recon checklist.
@intigriti introduces GitHub dorking with search patterns to uncover vulnerabilities.
@clintgibler highlights Check Point’s discovery of malware using prompt injection.
@40sp3l reminds hunters not to skip targets just because they have many reports — good bugs still remain.
@0xacb points out that Chrome’s upcoming features could open up new bypass techniques.
@njcve_ shares success at SteelCon where an authentication bypass bug was found.
@intigriti explains 3 exploitable and highly rewarded vulnerabilities in detail.
@Bugcrowd offers 5 actionable tips for beginners breaking into cybersecurity.
Full links, tools, write-ups & more →
getdisclosed.com
The bug bounty world, curated.