This tweet shares a new technique discovered to bypass Web Application Firewalls (WAFs) from Akamai and Cloudflare. The bypass specifically targets vulnerabilities related to Cross-Site Scripting (XSS). While the tweet does not provide the exact payload used for the bypass, it highlights that a fresh method is effective in defeating protections of these two popular WAF vendors. Akamai and Cloudflare are widely used services aiming to protect web applications from attacks including XSS, making this discovery important for security researchers and bug bounty hunters. Since no specific payload is provided, we can understand this bypass involves innovative or less known approaches allowing malicious scripts to run past these WAFs. Such findings help improve web security by informing service providers and the community, encouraging updates to filtering and detection techniques to counter emerging threats like this new WAF bypass targeting XSS vulnerabilities.
Bug Bounty tips ?
New WAF Bypass Discovered – Akamai & Cloudflare ?A fresh technique has been spotted that successfully bypasses WAFs like Akamai and Cloudflare.#Exploit #WAFBypass #XSS #Cloudflare #Akamai #WebSecurity #BugBounty #bugbountytips pic.twitter.com/6C96zv7vhI
— VIEH Group (@viehgroup) August 21, 2025