This week, Disclosed.
#BugBounty
Full issue →
getDisclosed.com
Highlights below 👇
@samm0uda goes crazy and releases EIGHT write-ups on Meta attack chains, each exploiting different trust boundaries across Facebook and Instagram's authentication, messaging, and analytics infrastructure.
Vote on
@portswigger’s Top 10 Web Hacking Techniques of 2025 poll before Jan 22.
@caidoio Year in Review 2025, ten releases from v0.45.0 to v0.54.0; 29 plugins; notable focus on Scanner and GraphQL workflows.
OpenProject public bug bounty launched on
@yeswehack, max payout €5,000, a large open-source surface area with auth, permissions, and data exposure failure modes.
@BugbopApp First Year in Review, platform metrics; triage lessons; planned changes around pre-report filtering and report disposition.
@Bugcrowd on adversarial AI usage, phishing and impersonation ops; recon automation; malware development; plus prompt-injection-style abuse in real product surfaces.
@Six2dez1 on Burp Suite MCP Server plus Codex CLI integration, an agent workflow over intercepted HTTP traffic with MCP proxy extraction and local reasoning loops.
@_nikitastupin’s clairvoyance, GraphQL schema recovery even when introspection is disabled; probing heuristics; wordlists; error-driven enumeration for recon pipelines.
@0x0SojalSec released a 1.7B public domains dataset, sorted multi-TLD input for OSINT, large-scale recon, enrichment, and threat intel pipelines.
@xnl_h4ck3r shipped waymore v7.5, IntelX support via Free Academia tier, IntelX data pulled into recon runs without separate tooling glue.
@aacle_ on DNS rebinding bypassing Slack SSRF filters, including a reported $1,000 payout and implementation details around resolution and validation drift.
@ryotkak shared an article on Pwning Claude Code in 8 Different Ways, eight paths to command execution via permission gaps and argument parsing edge cases across Git; sed; Bash expansion; wrapper interpretation.
@_lauritz_ on turning RFC2369 List-Unsubscribe into an SSRF/XSS gadget, stored XSS and blind SSRF primitives in webmail and mail clients via header-driven behaviors.
@0xasm0d3us on an ElysiaJS cookie signature validation bypass, secret handling and rotation pitfalls; PoC and affected code paths with patch guidance.
@yeswehack Dojo #47 APICrash solution, a GraphQL mutation batching race with aliases; concurrent TinyDB-backed file writes corrupt state via thread spawning.
@BourAbdelhadi on Supabase anon JWT exposure found with rep , validation steps against Supabase APIs
@sijan2003 on modifying Netflix OTP messages via an unauthenticated endpoint, reversing and instrumenting the Android client to map the OTP trigger flow and messaging risk.
@Hacker0x01 talk with
@rez0__ on AI red teaming beyond jailbreak framing, application-level failure modes like prompt injection in product surfaces and evaluation that resembles real usage.
@zack0x01 video on open redirect exploitation, bypass techniques against weak allowlists; normalization and encoding tricks; redirect weaponization.
That's not all. Full links, writeups & more →
getDisclosed.com
The bug bounty world, curated.