Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Router Risk: New FreeBSD Flaw Exploits IPv6 to Grant Remote Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 01:58:06 +0000
════════════════════════
Tags: #Vulnerability #CVE_2025_14558 #FreeBSD #IPv6 #network security #OS Command Injection #Patch Alert #RCE #resolvconf #Router Advertisement #rtsold
Title: The Two-Day Tax: How Much of Your Life Is Being Stolen by Online Ads?
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 01:56:25 +0000
════════════════════════
Tags: #Cybercriminals #2025 Report #ad blocker #AdGuard #Cyber Security #data privacy #Data Savings #FBI Recommendations #Google Trackers #Page Load Speed #web performance
Title: Ghost in the Machine: The $6B “Doublespeed” Leak Exposes the AI Warehouse Hijacking TikTok
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 01:55:49 +0000
════════════════════════
Tags: #Data Leak #a16z #AI Influencers #Algorithmic Manipulation #Andreessen Horowitz #Doublespeed #Generative AI #Kira Hacker #Smartphone Farm #Social Media Fraud #TikTok
Title: n8n Under Fire: Critical CVSS 10.0 RCE Vulnerability Grants Total Server Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:55:12 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_68613 #Cyber Security #DevOps #Expression Injection #infosec #n8n #Patch Update #rce #Remote Code Execution #Workflow Automation
Title: Hackers Abuse “Device Codes” to Bypass Security and Seize Microsoft 365 Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
Title: The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
Title: Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
Title: “ClickFix” Trap: Fake Human Verification Leads to Qilin Ransomware Infection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
Title: TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
Title: The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
Title: Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Title: North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
Title: “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Title: AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
Title: Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
════════════════════════
𐀪 Author: Val Vask
════════════════════════
Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
Tags: #penetration_testing #cyber_kill_chain #red_team
Title: Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
Title: TryHackMe | Tempest | Challenge Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
Title: Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
════════════════════════
𐀪 Author: Negro Med
════════════════════════
Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
Tags: #data_science #ethical_hacking #cybersecurity #programming #python
Title: The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack