Daily Writeups
3.48K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Emergency Doxing: Scammers Impersonate Police to Steal Data from Apple, Charter, and Amazon
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:53:58 +0000
════════════════════════
Tags: #Cybercriminals #Amazon #Apple #Charter #cybercrime #data leak #Doxing #Emergency Data Request #Law Enforcement #Police Impersonation #Social Engineering
Title: Kali Linux 2025.4 Final Release: GNOME is Now Wayland Exclusive, New Pentesting Tools Added
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:51:58 +0000
════════════════════════
Tags: #Linux #cybersecurity tools #ethical hacking #GNOME 49 #Kali 2025.4 #kali linux #KDE Plasma 6.5 #NetHunter #Pentesting #Wayland
Title: UK Sanctions 2 Chinese Firms: i-Soon & Integrity Tech Targeted for Cyberattacks on Allies
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:51:19 +0000
════════════════════════
Tags: #Cyber Security #China #Cyber Espionage #cyberattack #i_Soon #Integrity Tech #National Security #NCSC #State_Sponsored Hacking #UK Sanctions
Title: React2Shell Saga Continues: New DoS Flaw & Source Code Leak Discovered in React Server Components
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:47:41 +0000
════════════════════════
Tags: #Vulnerability #CVE_2025_55184 #Denial of Service #DoS #Next.js #React Server Components #React2Shell #Source Code Leak #Vercel #Web Vulnerability
Title: Windows RasMan Zero-Day: New DoS Flaw Crashes Service, Unofficial Fix Available
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:45:25 +0000
════════════════════════
Tags: #Vulnerability #Windows #0patch #ACROS Security #CVE_2025_59230 #Denial of Service #DoS #Micropatch #privilege escalation #RasMan #windows #zero_day
Title: NANOREMOTE Trojan Uses Google Drive as Covert C2 for Chinese Espionage Campaigns
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:44:18 +0000
════════════════════════
Tags: #Malware #C2 #Chinese Espionage #cloud security #FINALDRAFT #Google Drive API #NANOREMOTE #REF7707 #Windows Trojan #WMLOADER
Title: Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:42:21 +0000
════════════════════════
Tags: #Malware #Accessibility Services #Android malware #Device Admin #Droidlock #mobile security #phishing #ransomware #Screen Capture #Zimperium
Title: ConsentFix Attack: New Phishing Bypasses MFA to Hijack Microsoft Accounts via OAuth Code
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:34:59 +0000
════════════════════════
Tags: #Cybercriminals #Azure CLI #ClickFix #cloud security #ConsentFix #MFA Bypass #Microsoft Account Takeover #OAuth 2.0 #phishing #Social Engineering
Title: The End of d_genocide(): Linux Kernel Removes Controversial Function Name in 6.19 Refactor
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:32:03 +0000
════════════════════════
Tags: #Linux #Al Viro #d_genocide #dcache #Inclusive Language #Linux 6.19 #Linux Kernel #open source #Terminology
Title: The HTTPS Lockdown: Chrome & CAs Retire 11 Legacy Domain Validation Methods by 2028
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:27:51 +0000
════════════════════════
Tags: #Technology #ACME #CA/Browser Forum #Certificate Authority #Chrome Root Program #DCV #Domain Validation #HTTPS #Security Standard #TLS
Title: PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
Title: Notepad++ Fixes WinGUp Vulnerability Exploited to Deliver Reconnaissance Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:25:21 +0000
════════════════════════
Tags: #Vulnerability #AutoUpdater.exe #Code Execution #cybersecurity #Notepad++ #reconnaissance #software update #supply chain attack #WinGUp
Title: MITRE ATT&CK Evaluation 2025, Scattered Spider Mustang Panda
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:21:03 +0000
════════════════════════
Tags: #Cybercriminals #APT #cloud security #Cybersecurity Evaluation #EDR #MITRE ATT&CK #Mustang Panda #ransomware #Scattered Spider #SoC #Threat Hunting
Title: Unmasking Mythic: Kaspersky Reveals How to Detect the Stealthy Open-Source Post-Exploitation Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:18:31 +0000
════════════════════════
Tags: #Cybercriminals #APT #C2 framework #Cobalt Strike #kaspersky #Mythic #Network Detection #open source #post_exploitation #Suricata #UUID
Title: ARTEMIS AI Places 2nd in Live Pentest, Outperforming 9 of 10 Human Security Experts
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 15 Dec 2025 07:16:21 +0000
════════════════════════
Tags: #Information Security #AI Agent #ARTEMIS #Autonomous Hacking #Cost_Effectiveness #cybersecurity #Pentesting #RCE #Stanford #Vulnerability Triage
Title: Advanced Search Techniques for Exposed Information — By Reju Kole
════════════════════════
𐀪 Author: Reju Kole
════════════════════════
Time: Mon, 15 Dec 2025 08:42:46 GMT
════════════════════════
Tags: #bug_bounty #ethical_hacking #google #google_dorking #cybersecurity
Title: How I Check for Subdomain Takeovers Part 1
════════════════════════
𐀪 Author: Red
════════════════════════
Time: Mon, 15 Dec 2025 08:41:12 GMT
════════════════════════
Tags: #linux #security #website #cybersecurity #bug_bounty
Title: When AI Gossips: How I Eavesdropped on a Federated Learning System
════════════════════════
𐀪 Author: Iski
════════════════════════
Time: Mon, 15 Dec 2025 08:40:54 GMT
════════════════════════
Tags: #bug_bounty #money #bug_bounty_tips #cybersecurity #hacking
Title: Reflected XSS in OAuth Callback Endpoint
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
Time: Mon, 15 Dec 2025 08:34:56 GMT
════════════════════════
Tags: #infosec #xss_attack #reflected_xss #bug_bounty #javascript
Title: How I Turned a 403 Error into a $200 API Key Leak Bounty
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
Time: Mon, 15 Dec 2025 08:34:18 GMT
════════════════════════
Tags: #bugbounty_writeup #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Title: Top 3 tools for Bug Bounty/Pentesting (2025)
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
Time: Mon, 15 Dec 2025 08:32:45 GMT
════════════════════════
Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked