Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: HackTheBox — File Uploads-Whitelist Filters
════════════════════════
𐀪 Author: 415141
════════════════════════
Time: Wed, 17 Dec 2025 22:27:18 GMT
════════════════════════
Tags: #ethical_hacking #cybersecurity #web_security #file_upload #hackthebox
Title: “Script” Engellemek Yetmez: Reflected XSS Gerçeği
════════════════════════
𐀪 Author: Melih Yılmaz
════════════════════════
Time: Wed, 17 Dec 2025 22:09:33 GMT
════════════════════════
Tags: #xss_attack #web_security #cybersecurity #web_application_security #ethical_hacking
Title: Vulnhub Deathnote: 1 Walkthrough
════════════════════════
𐀪 Author: Luke Gearty
════════════════════════
Time: Wed, 17 Dec 2025 22:06:07 GMT
════════════════════════
Tags: #cybersecurity #vulnerable_machine #ethical_hacking #hack_to_learn #vulnhub_walkthrough
Title: The Invisible Glue of the Internet: What Is API Security and Why It Matters to You
════════════════════════
𐀪 Author: Ngobirifalyne
════════════════════════
Time: Wed, 17 Dec 2025 22:51:32 GMT
════════════════════════
Tags: #api_introduction #api_security #api #getting_started_with_api #api_usage
Title: Solving OIDC Integration Challenges with Kong API Gateway and Angular UI
════════════════════════
𐀪 Author: Amanuel Eshete
════════════════════════
Time: Wed, 17 Dec 2025 22:48:41 GMT
════════════════════════
Tags: #kong_api_gateway #api_security #openid_connect #microservices #angular
Title: France Arrests 22 Year Old After Hack of Interior Ministry Systems
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Thu, 18 Dec 2025 00:26:27 +0000
════════════════════════
Tags: #Cyber Crime #BreachForums #Cyber Attack #Cybersecurity #data breach #France #hacking #ShinyHunters
Title: $5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution
════════════════════════
𐀪 Author: janet zech
════════════════════════
Time: Thu, 18 Dec 2025 00:05:51 GMT
════════════════════════
Tags: #technology #ai #security #llm #bug_bounty
Title: SSRF Vulnerability Tryhackme Walkthrough
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
Time: Thu, 18 Dec 2025 00:42:44 GMT
════════════════════════
Tags: #ssrf_walkthrough #tryhackme_walkthrough #cybersecurity #web_hacking #hacking
Title: CTF Flow| HackingClub
════════════════════════
𐀪 Author: Henrique
════════════════════════
Time: Thu, 18 Dec 2025 00:09:06 GMT
════════════════════════
Tags: #ctf_writeup #hacking #offensive_security #pentesting
Title: Testability vs. Automatability: Why Most Automation Efforts Fail Before They Begin
════════════════════════
𐀪 Author: tanvi mittal
════════════════════════
Time: Thu, 18 Dec 2025 01:02:38 GMT
════════════════════════
Tags: #testing #penetration_testing #software_testing #software_development #test_automation
Title: GPO Stealth: Turn Active Directory Into Your C2 With the New GroupPolicyBackdoor Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:59:56 +0000
════════════════════════
Tags: #Open Source Tool #Active Directory #DEF CON 33 #GPO Abuse #GroupPolicyBackdoor #LDAP #privilege escalation #python #red teaming #SMB #Stealth Exploitation #Synacktiv
Title: The Plagiarism Trap: How ForumTroll APT is Holding Academic Careers Hostage to Deploy Spyware
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:55:26 +0000
════════════════════════
Tags: #Cyber Security #Academic Espionage #COM Hijacking #Dante Spyware #ForumTroll #Kaspersky Lab #LeetAgent #phishing #Russian Universities #threat intelligence #Tuoni Framework
Title: The Invisible Roommate: How the GhostPairing Scam Steals Your WhatsApp Without a Password
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:53:30 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #Cybersecurity 2025 #Device Pairing #Gen Digital #GhostPairing #phishing #privacy #QR Code Scam #Social Engineering #WhatsApp
Title: The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
Title: SYSTEM via WAC: How a Permissions Oversight in Windows Admin Center Leads to Full Host Compromise
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:50:07 +0000
════════════════════════
Tags: #Vulnerability #CVE_2025_64669 #cybersecurity #Cymulate #DLL hijacking #Microsoft #PowerShell #privilege escalation #TOCTOU #Windows Admin Center #Windows Server
Title: The Silent Listener: New DRBControl Backdoor Variant Uses Network Sniffing to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:48:07 +0000
════════════════════════
Tags: #Malware #APT27 #APT41 #Cyber Espionage #DLL Sideloading #DRBControl #IIJ #malware analysis #Mofu Loader #Promiscuous Mode #ShadowPad #Type 1 Backdoor
Title: The Trojan Book: How a Malicious E-book Can Hijack Your Entire Amazon Account
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:37:25 +0000
════════════════════════
Tags: #Cybercriminals #Amazon Kindle #bug bounty #cybersecurity #E_book Malware #IoT Security #Kindle Patch #Session Cookie Theft #sideloading #Thales #Valentino Ricotta
Title: Hidden in Plain Sight: How the GhostPoster Campaign Injected Malware Into 50,000 Firefox Users
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:36:09 +0000
════════════════════════
Tags: #Malware #Ad Fraud #browser security #cybersecurity #Firefox Extensions #GhostPoster #JavaScript Loader #Koi Security #Malware_as_a_Service #Mozilla #Steganography
Title: The Five-Year Sleeper: Malicious NuGet Package Poses as Tracer.Fody to Drain Crypto Wallets
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:35:24 +0000
════════════════════════
Tags: #Malware #.NET #cybersecurity #Homoglyph Attack #Info_stealer #NuGet #Socket Threat Research #Stratis Wallet #supply chain attack #Tracer.Fody #Typosquatting
Title: Kill the Cipher: Microsoft to Disable RC4 Authentication by Mid-2026—Are You Ready?
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:32:48 +0000
════════════════════════
Tags: #Microsoft #Active Directory #AES_SHA1 #Audit 4768 #cybersecurity #Domain Controller #Encryption #Kerberos #PowerShell #RC4 #Windows Server
Title: Internet Rewired: Cloudflare 2025 Report Reveals a 19% Traffic Surge and the Rise of AI Bot Wars
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 18 Dec 2025 03:31:43 +0000
════════════════════════
Tags: #Information Security #2025 Year in Review #AI Crawlers #bot traffic #Cloudflare Radar #DDoS attacks #Googlebot #internet security #Post_Quantum Cryptography #Starlink #Tech trends