HxBugLetter

Curated archive · Bug bounty

The reading that’s worth it, without the noise.

A timeline of bug bounty writeups and research. Every entry is verified against its source and classified by bug type — so you can filter instead of scroll.

writeups
41
bug types
13
live sources
7

Latest

Recently added

see all →
InfoMethodology

When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS)

Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo

IntigritiIntigritiintigriti.com
InfoMethodology

When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS)

Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo

IntigritiIntigritiintigriti.com
InfoMethodology

Web fuzzing for hackers

Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crashing the UNIX utilities he was running. Web fuzzing is no different. Despite the rise of automated sc

IntigritiIntigritiintigriti.com
InfoSupply Chain

Supply Chain Security Analysis of a 9.5M-Install VS Code Extension

Your code editor extensions auto-update and run with your privileges on the machine that holds your source code, your SSH keys, and your publishing credentials, but they rarely show up in a software bill of materials. Using Neo we audited one of the most popular ones, Markdown Preview Enhanced has roughly 9.5 million installs. The neo found five CVEs across two attack surfaces. A WaveDrom render

ProjectDiscoveryProjectDiscoveryprojectdiscovery.io
InfoMethodology

CrowdRecon is coming: turning hacker reconnaissance into security intelligence

At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started with a question we kept running into: what happens to all the reconnaissance work hackers do before a v

IntigritiIntigritiintigriti.com

How it works

The content lives in the repository

Everything is YAML

Each writeup is a file in data/writeups/. No database, no admin panel. The change history is the git history.

Contributed by PR

Add a file, open a pull request, and CI validates the schema. If it passes, it lands in the archive with your name on the commit.

The bot notifies

A GitHub Action checks the feeds daily and posts what's new to Discord. The site is the archive; the bot is the notification.