Bug Bytes #208 – Burp gets an update, Sharefile gets a CVE and JavaScript files get analysed

By travisintigriti

July 19, 2023

Last updated on August 8, 2026

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by InsiderPhD. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources.

This issue covers the week from July 10th – July 16th

CLICK HERE TO SUBSCRIBE

Intigriti News

From my notebook

  1. Improve your API Security Testing with Burp BCheck Scripts

  2. Introducing jswzl: In-depth JavaScript analysis for web security testers

  3. Exploiting XSS in hidden inputs and meta tags

  4. Using MiTMProxy as a scriptable pre-proxy for BurpSuite

  5. Encrypted Doesn’t Mean Authenticated: ShareFile RCE (CVE-2023-24489)

You may also like

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready

Read more

Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo

Read more

Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at scal

Read more