“I could’ve rickrolled the entire FIFA World Cup,” according to BobDaHacker’s latest, rather topical research. The exploit, which arose from the simplest of oversights on the Fifa Agent Platform – implementing client-side authorisation without server-side enforcement – could have allowed an attacker to replace FIFA World Cup broadcasts worldwide with any video of their choosing. The only prerequisite for exploitation was getting approved as a licensed FIFA agent – a rather simple process, it transpired. BobDaHacker said FIFA fixed the vulnerability but never responded to her disclosure. “But they did leave me on the FDP email distribution list,” she noted. “I’m still receiving official FIFA World Cup 2026 match documents: Start Lists, Tactical Lineups, Full Time Match Reports. All sent from no_reply@fdp.fifa.org. In four languages.” Tech Crunch’s coverage indicated that FIFA did not respond to its requests for comment either. ⚽
Ammar Askar’s discovery one-click vulnerability in github.dev, VS Code’s browser-based editor, made an impact not just because of its admittedly impressive technical bona fides. The exploit itself arose from malicious JavaScript in a Jupyter notebook being able to mimic genuine keyboard input, install an attacker-controlled extension and steal a victim’s GitHub OAuth token, potentially exposing private repositories. However, the disclosure also renewed criticism of Microsoft’s handling and recognition of security researchers, while prompting a debate on r/netsec about Askar’s decision to bypass its official reporting process. 🔑
Harder, Better, Faster, Stronger: How to hack with LLMs
AI use in Bug Bounty has been ticking up for some time, but excitement, anxiety and, no doubt, adoption have gone into overdrive since Anthropic delayed the release of Claude Mythos Preview in April. Mindful of growing anxiety among hunters about the relevance of their skills and the durability of the crowdsourced security model, popular Bug Bounty podcast Critical Thinking has helpfully explained ‘how to stay motivated and keep the vibes strong during this trying time for Bug Bounty’. While aimed more at organisations than hunters, our assertion that although some have claimed that AI would kill Bug Bounty, the data says otherwise offers more reassurance about the future of our industry. By the way, you can find more Critical Thinking episodes on YouTube. 🐛
One of the podcast’s co-hosts, Rhynorater, recently spoke to YesWeHack about his own LLM use, including how he combines Claude Code, custom AI agents and LLM workflows to find vulnerabilities faster. This is part of a series of interviews about hunters’ use of LLMs, which also featured Aituglo, who explained how he leverages AI, his best LLM-assisted find so far, and the impact of AI on his own performance and that of his peers. 🤖
There’s little doubt that Claude Code is by far the most popular AI hunting tool at present. We put Anthropic’s coding assistant through two blind Bug Bounty labs – DOM XSS and HTTP request smuggling – to see if it can find and validate real vulnerabilities. The result is a guide to leveraging Claude Code for Bug Bounty hunting, covering installation, connecting it to Burp Suite over MCP, testing it against real labs, and understanding and mitigating its limitations. We’ve also published a guide to harnessing LLMs, agentic CLIs and MCP servers to boost Bug Bounty workflows while keeping manual validation at the core of vulnerability research. But it’s not all about AI: we recently published the latest in our ‘Vulnerability Vectors’ series, this time focusing on finding and exploiting SSRF vulnerabilities. 💡
What happens when you unleash an AI across all of Google's infrastructure? So begins a blog post from Arvin Shivram, aka Brutecat. Well, what happens is the mapping of around 1,500 Google APIs and collected 3,600 Google-owned API keys by analysing mobile apps and traffic across thousands of domains. He turned Google’s API documentation into MCP tools for Claude, then used them to test for IDORs and other access-control flaws. The findings included Google Voice account takeover and AdExchange administrative access. The writeup shows how AI can make an otherwise unmanageable attack surface testable, while still relying on human expertise to design the methodology, guide the process and validate the results. Nice work. 🗺️
Live hacking with PUMA
Highlights from our leHACK live Bug Bounty with iconic sportswear brand PUMA dropped last week. The event showed the value of in-person collaboration, as well as both AI-assisted testing – the impact of which was noted by our triage team – and manual testing, with the overall winners actually eschewing automation on this occasion. Humans are still holding their own! Read the full recap and hear from the winners. As you can see, points accrued on the PUMA leaderboard have propelled several participants to a promising position on the overall YesWeHack leaderboard for Q3 so far. 👏
Unleashing Lab
We recently launched a new channel dedicated to novel research – with the unbeatably concise name of Lab – to showcase work from our increasingly prolific roster of security researchers. Our vulnerability intelligence team’s latest work, ‘Don’t eat the ChocoPoCs!’ (a nostalgic reference for French readers of a certain age 😉) tells the story of how our researchers were repeatedly targeted by trojanised exploits. The research made a splash, with Bleeping Computer’s Bill Toulas noting that “ChocoPoC stands out for not embedding the malware directly in the exploit file but for adding malicious Python packages to the PoC’s dependency list”. This marks a step change from the vuln intel team’s previous research, which centred on vulnerabilities identified while testing and validating emerging exploits to create Checkpoints for our Autonomous Pentest solution. Since the last edition of this newsletter, that work has included a pre-auth RCE in Joomla JCE and PostgreSQL SQL Injection in Drupal. 🔬
Despite AI’s increasing centrality to Bug Bounty workflows, in our latest video interview Sn0rky reaffirms the importance of human ingenuity: “Your main tool should be your own knowledge & curiosity,” he says. In case you missed them when they first appeared on YouTube, we’ve re-published a couple of other recent hunter interviews on our blog: with yassine_eal, who recalls a CSRF that enabled him to deploy code through an enterprise’s App Store account, and SpawnZii, who talks about balancing Bug Bounty with a full-time pentesting role. 💡
Research roundup
Rachid Allam returned with a characteristically impressive writeup, this time chaining subtle behaviours in a fully updated Next.js application to achieve zero-click stored XSS. By manipulating reflected headers, they changed a React Server Component response to text/html, injected JavaScript through an unescaped URL parameter and poisoned the CDN cache. A second cache-poisoning step redirected users to the malicious response automatically. The researcher earned a five-figure bounty for his efforts. Bravo! 👏
Before we conclude YesWeHack-related content, here’s a roundup of other interested research we’ve noticed since the last edition:
🔬 Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE – by N Maccary, Lexfo
🔬 Stealing Passwords via HTML Injection Under a Strict CSP – Rafał Wójcicki, Afine
🔬 SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon – Dolev Taler, Varonis
🔬 Chaining Razor SSTI into RCE via Reflection and Runtime Strings – Philip Sinnott
🔬 MeshCentral: From XSS to RCE – Kev Breen, TechAnarchy
🔬 More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry 🔬 Pre-Auth OS Command Injection CVE-2026-10520) – Sonny, watchTowr Labs
🔬 Squidbleed (CVE-2026-47729) – Khanh, Calif
🔬 AI Agents May Always Fall for Prompt Injections – Sahar Abdelnabi, Eugene Bagdasarian
🔬 A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack – Argus Systems
🔬 Pwnd Blaster: Hacking your PC using your speaker without ever touching it – Rasmus Moorats
Leaderboards and CTF challenges
Three weeks into the third quarter of 2026 and, for now at least, perennial leader rabhi is not leading the pack. It’s been a great month for Vozec, whose triumph at leHACK has helped him to set the pace at the summit, with YoyoDavelion edging out rabhi in second place. Rabhi still tops the overall 2026 rankings but the gap to YoyoDavelion in second is only 107 points at the time of writing. 🏆
Our latest monthly CTF challenge is Hacker Club, with swag up for grabs for the best solutions submitted by 20 August. “Hackers are being invited to a new secret club, but only those with the right access can claim a limited invitation,” reads the description. “Are you one of the hackers who will get access?” The best solutions are out for the previous two challenges, Deadbolt and StreamCore.
🤘 Meet the YesWeHack Team 🤘
More than halfway through the year and we’ve already attended countless hacker cons and infosec events around the world… And there’s more to come, with the biggest of them all hoving into view: DEF CON. 🤩
YesWeHack is again sponsoring the DEF CON Bug Bounty Village. Like last year, Brumens will present some innovative technical research, YesWeHack experts will participate on a panel discussion - this time on handling AI-assisted submissions to Bug Bounty - and we’ll invite attendees to tackle a hacking challenge, called Payload Plz Reloaded.
Here's the latest schedule, with more to announce soon:
📍FutureCon | California, US | 23 July
📍DEF CON 34 | Las Vegas, US | 6-9 August
📍CESIN 2026 | Louveciennes, France | 28 August
And that’s a wrap until our next edition in September – happy hunting in the meantime! 👊
Read this monthly roundup of content aimed at ethical hackers even sooner by subscribing to Bug Bounty Bulletin.
Are you a CISO, other security professional or security-conscious dev? Check out our CISO-focused sister newsletter, CrowdSecWisdom – bringing you news, insights and inspiration around offensive security topics like Bug Bounty, vulnerability disclosure and management, pentest management and attack surface protection.



