cd /news/ai-agents/intigriti-bug-bytes-240-september-20… Β· home β€Ί topics β€Ί ai-agents β€Ί article
[ARTICLE Β· art-139761] src=intigriti.com β†— pub= topic=ai-agents verified=true sentiment=Β· neutral

Intigriti Bug Bytes #240 - September 2026 πŸš€

Intigriti published Bug Bytes #240 on September 25, 2026, highlighting research on compromising OpenAI, Slack, and Meta through a vulnerable image library and on hacking OpenAI employee accounts in under 72 hours, alongside a $100K Google GFile breach and techniques for attacking AI customer service agents. The newsletter also announced the public beta of CrowdRecon, a crowd-led reconnaissance product, and reported that 79 hackers solved August's Bad Reception CTF with 21 write-ups submitted, while the 0926 Critter Gallery challenge runs until Monday, September 28 for €400 in swag prizes.

by read10 min views1 publishedSep 25, 2026
Intigriti Bug Bytes #240 - September 2026 πŸš€
Image: Intigriti (auto-discovered)

By Ayoub

September 25, 2026

Hi hackers, #

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring:

  • Compromising OpenAI, Slack, Meta, and more via a vulnerable image library
  • Hacking OpenAI employee accounts in under 72 hours
  • Breaking into Google's GFile for $100K
  • Hacking AI CX agents
  • Turbo Intruder 2 surpassing 100K requests per second over HTTP/3

And so much more! Let's dive in!

Reconnaissance unleashed: meet CrowdRecon #

CrowdRecon is officially here! CrowdRecon brings crowd-led context to the moments before and between vulnerability reports. It helps customers quickly identify where attention is needed across exposure, scope, coverage, investigation, and follow-up. For researchers, it introduces new ways to collaborate, contribute, and earn recognition for the valuable recon work that usually disappears.

The public beta is open! Register today and be among the first to try it.

Reconnaissance unleashed: meet CrowdRecon

How AI changed my day as a QA Engineer #

In our latest post, Senior QA Engineer Martin Klimovski shares how he is leveraging AI for repetitive tasks to free up time for deep exploratory work and security testing. The piece covers how he removes friction while keeping judgment, and his views on AI security and safety.

From sceptic to supercharged. How AI changed my day as a QA Engineer

How AI has changed the way I think, build, and work #

Senior Software Engineer Koen Van Hauwe shares an honest look at a day in his life and his shift from writing code to steering AI. The post covers the Orchestrator shift and the critical role of human oversight, the risks of speed and subtle mistakes that build up over time, and how AI introduces new attack surfaces alongside opportunities for defenders.

How AI has changed the way I think, build, and work. A day in the life of an Intigriti Engineer

Intigriti's 0926 Challenge, Critter Gallery by @khanhdlq, is still ongoing. Capture the flag before Monday the 28th of September for a chance to win €400 in swag prizes.

Intigriti Challenge 0926

Intigriti 0826 Bad Reception CTF results are in #

August's CTF challenge, Bad Reception, featured a broken TV that revealed the flag once fixed. This challenge definitely sent lots of participants down rabbit holes and dead ends, which made it more engaging than ever.

Quick recap:

  • 79 hackers found the correct solution
- 21 hackers wrote a cool write-up

If you want to put your hacking skills to the test, be sure to give [Bad Reception 0826](https://challenge-0826.challenges.intigriti.io/) a go before heading over to [Bugology](https://bugology.intigriti.io/intigriti-monthly-challenges/0826), where you can find all the researchers' submitted solutions.

Intigriti Challenge 0826

Blogs & videos #

Hacking AI customer service agents

Hacking AI customer service agents Cover Image

Most support chatbots have evolved into fully autonomous agents that can help with almost anything, and that comes with additional risk. Our latest article, based on @intidc's talk at Bug Bounty Village during DEF CON 34, breaks down the full attack surface in AI customer service agents: from tricking them into leaking sensitive data via email spoofing to invoking unauthorized tool calls on behalf of the victim. All without ever touching an automated scanner or proxy interceptor.

  • Looking for a complete guide on file upload vulnerabilities? Our full guide onexploiting insecure file uploads covers everything from basic bypass techniques to advanced exploitation scenarios.
  • Reports sometimes get closed incorrectly, downgraded in severity, or left pending for longer than expected. When that happens, knowing how to respond through the right channels matters. Our comprehensive guide walks you throughIntigriti's mediation process , the most common scenarios researchers face, and the mistakes to avoid during the process, such as unauthorized public disclosure, which can work against you rather than help your case.
  • Going from zero to your first valid bug report? In case you missed it, we recently launched theBug Bounty Starter Kit , a free guide covering everything from recon and tooling to the exploitation of SQLi, XSS, and BAC vulnerabilities, to finally how to learn to write a compelling vulnerability report that gets triaged faster.Get your copy now.

Tools & resources #

Tools

GeminiHunter

GeminiHunter

Did you know that some exposed Google Maps API keys also have access to Gemini models? GeminiHunter by @devploit finds and validates exposed Google Gemini API keys across web assets, source maps, Wayback snapshots, and Android APKs. It deduplicates findings, checks if keys are actually valid, and attempts bypass variations on restricted ones. If you are hunting Google API key exposures, this adds a new dimension to check.

  • Prompt injection is the top risk in the OWASP LLM Top 10.Awesome Prompt Injection is a curated collection of resources covering everything from research papers and real-world attack chains to hands-on CTFs and detection tools for testing LLM and agentic applications.
  • Want your AI agent to interact directly with Chrome?Chrome DevTools MCP lets AI agents use Chrome's debugging protocol to inspect network requests, DOM elements, execute JavaScript in the console, and capture screenshots, all programmatically.

Resources

HEIF Heist

HEIF Heist research

@rootxharsh and team published HEIF Heist, a months-long investigation into libheif that compromised OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick, and more. The attack surface was a single obscure image parsing library sitting beneath a huge number of applications. Some of the RCE and information leak attempts only landed after thousands of image uploads, and only one organization caught the exploitation in progress.

Company news #

Wild West Hackin' Fest

Intigriti is a Gold Sponsor of Wild West Hackin Fest in Deadwood, South Dakota. If you are attending, be sure to come say hi!

Wild West Hackin' Fest

Feedback & suggestions #

Before you click away: Do you have feedback, or would you like your technical content to get featured in the next Bug Bytes issue? We want to hear from you. Feel free to send us an email at community@intigriti.com or DM us on X/Twitter, and we'll take it from there.

Did you like this Bug Bytes issue? Consider sharing it with your friends and tagging us along on X/Twitter, Instagram, or LinkedIn.

Wishing you a bountiful month ahead,

Keep on rocking!

Author

Ayoub

Senior security content developer

You may also like #

August 28, 2026

Intigriti Bug Bytes #239 - August 2026 πŸš€

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready

Read more: Intigriti Bug Bytes #239 - August 2026 πŸš€ July 31, 2026

Intigriti Bug Bytes #238 - July 2026 πŸš€

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo

Read more: Intigriti Bug Bytes #238 - July 2026 πŸš€ June 26, 2026

Intigriti Bug Bytes #237 - June 2026 πŸš€

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at scal

Read more: Intigriti Bug Bytes #237 - June 2026 πŸš€

── more in #ai-agents 4 stories Β· sorted by recency
── more on @intigriti 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain β€” perfect for shipping the agent you just read about.

$git push zahid main
β†’ Live at https://your-agent.zahid.host βœ“
Get free account β†’ Pricing
from €0/mo Β· no card required
LIVE [news/intigriti-bug-bytes-…] indexed:0 read:10min 2026-09-25 Β· β€”