Offensive Security & Exposure Management Platform 🎯 yeswehack.com/programs 👾 dojo-yeswehack.com 💡 yeswehack.com/blog

World
Can Gemini CLI actually help with Bug Bounty? We put it through blind vulnerability labs to find out. It won’t actively exploit targets, but give it captured traffic or source code to analyse and things get interesting 👀 Full test 👇 yeswehack.com/learn-bug-boun…
2
8
52
3,205
How much automation do you need to reach the top of a #BugBounty leaderboard? 🤖 Less than you might think 👀 In our latest interview, our all-time #1 hunter @Issam_Rabhi shares his methodology, best finds, favourite vulns & tips for hackers 👇 yeswehack.com/community/auto…
2
7
107
4,131
Got your @ekoparty 2026 ticket? You’re in 👀 From 7-9 Oct, @BancoGalicia, @BugBountyArg and @YesWeHack are bringing live bug hunting back to Buenos Aires - open to all attendees. Bring your laptop, bring your best game, and join the hunt! ⚡
1
3
10
1,395
Can a private Flutter dependency exposed in an APK become an entry point into your build environment? ⚠️ At @ekoparty's Bug Bounty Village (@BugBountyArg), @pwnwithlove will present ‘DevPUBdency Confusion: Weaponizing the Flutter Supply Chain’. 🕔 7 Oct, 4:55PM 📍 Auditorium E
3
11
38
1,970
Think you know how a whitelist-based SSRF filter behaves? 👀 In the latest Talkie Pwnii, @pwnwithlove takes on a @PortSwigger @WebSecAcademy lab using URL parsing, hostname validation and double encoding. Watch the full breakdown 👇 piped.video/watch?v=0GGYTksa…
2
10
40
2,655
Let's take on a retro game-style CTF challenge! 🎮 This month's Dojo challenge is still waiting for you to hack it and capture the flag! 🚩 Let's play 👉 dojo-yeswehack.com/challenge…
1
1
22
1,746
Before you hit submit, let Claude Kit review your report like a triager 👀 Claude Kit checks for missing evidence, overclaimed impact and vulnerability-specific gotchas, then tells you whether your report is actually ready to go. Give it a try 👇 yeswehack.com/learn-bug-boun…
2
8
46
3,104
Cache poisoning isn’t always about unkeyed input🔑 At @BugBountyDEFCON, @brumens2 showed how cache key injection can lead to unauthenticated cache deception, CPDoS and stored XSS via scheme fragments 🧪 This research is now live on our blog 👇 yeswehack.com/lab/research-c…
1
32
122
9,225
Massive congrats @kyle_wu 🔥
Just got a reward for a critical vulnerability submitted on @yeswehack -- Insecure Direct Object Reference (IDOR) (CWE-639). #YesWeRHackers
3
195
7,244
When choosing Bug Bounty Programs, hunters often weigh up the scope, rewards and how promptly bounties are paid 🎯 For @Krevetk0Valeriy, another factor usually comes first: the societal value of the organisation’s services 🌍 Read the interview 👇 yeswehack.com/community/targ…
1
1
31
2,326
Notre expérimentation de Codex appliqué au Bug Bounty est à l’honneur dans @Clubic 👀 L’IA gagne en autonomie dans l’investigation, mais le chercheur reste essentiel pour transformer les résultats en rapports exploitables. Article de @AlexBoeroOff 👇 clubic.com/actualite-628231-…
1
2
18
2,309
Still haven't beaten the high score? 👀🎮 Our latest CTF challenge is live, and this retro game definitely isn't meant to be played by the rules. Find the weakness, hack your way through and capture the flag 🚩 Go hack it 👉 dojo-yeswehack.com/challenge…
4
1,503
What happens when a vulnerability is fixed… but nobody is told it was a vulnerability? 👀 CVE-2023-54391 shows how silent patches can widen the attacker-defender info gap – especially as AI makes old fixes easier to excavate 🤖⛏️ A must-read 👇 yeswehack.com/lab/cve-2023-5…
1
2
10
1,767
Buenos Aires, round two is coming 👀 @BancoGalicia, @BugBountyArg and @yeswehack are teaming up again at @ekoparty 2026 for another Live Hacking Event! 🔥 📅 7-9 October 🎟️ Open to all attendees Ready for the rematch? 👊
1
8
37
3,336
¡Sumate a @BancoGalicia Super Live Hacking Event! 🔥 En colaboración con Banco Galicia y @yeswehack organizamos un exclusivo evento de hacking en vivo durante la EKO Buenos Aires 2026. 🚀 🚩 ¿El objetivo? Banco Galicia. Los participantes van a tener la oportunidad de poner a prueba su seguridad, buscar vulnerabilidades y demostrar sus habilidades de bug hunting sobre un scope especialmente preparado para el evento. Durante el evento, no solo te vas a sumergir en el hacking, sino que también vas a poder colaborar con otros bug hunters, e interactuar con expertos en seguridad de Banco Galicia y YesWeHack. Y, por supuesto, habrá jugosos bounties y mucho swag para quienes encuentren bugs. 🤓💪 👀 La competencia estará abierta a los asistentes presenciales durante el miércoles y jueves de la EKO, pero todavía no podemos contarte todo. En los próximos días vamos a revelar las fechas, horarios, dinámica y todos los detalles para que puedas sumarte.
7
21
1,507
YesWeHack ⠵ retweeted
Our Bug Bounty Bulletin – featuring a research roundup, new hacking opportunities, technical advice & hunter Q&As – is now available on X! Inside: high-calibre research from @albinowax @t0xodile @garethheyes @olivier_boschko @citizenlab & more 👇
Article

Bug Bounty Bulletin #21 – and the first on X!

Insights, inspiration and hunting opportunities for ethical hackers Welcome to YesWeHack’s Bug Bounty Bulletin – featuring new hunting opportunities 🐞 CTF challenges 🏁 a research roundup 🔬 plus

1
5
54
4,734