Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Hackers Abuse “Device Codes” to Bypass Security and Seize Microsoft 365 Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
Title: The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
Title: Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
Title: “ClickFix” Trap: Fake Human Verification Leads to Qilin Ransomware Infection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
Title: TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
Title: The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
Title: Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Title: North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
Title: “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Title: AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
Title: Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
════════════════════════
𐀪 Author: Val Vask
════════════════════════
Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
Tags: #penetration_testing #cyber_kill_chain #red_team
Title: Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
Title: TryHackMe | Tempest | Challenge Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
Title: Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
════════════════════════
𐀪 Author: Negro Med
════════════════════════
Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
Tags: #data_science #ethical_hacking #cybersecurity #programming #python
Title: The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack
Title: 21,000 SIMs Discovered: CBI Dismantles Massive “Phishing Factory” in Operation Chakra-V
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:29:39 +0000
════════════════════════
Tags: #Cybercriminals #CBI #Cyber Security India #Digital Arrest #Financial Scams #KYC Violation #Lord Mahavira Services #NCR #Operation Chakra_V #phishing #SIM Box #SMS Fraud
Title: Operation Magic Cat: Google Sues to Dismantle the Chinese “Darcula” Phishing Empire
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:28:56 +0000
════════════════════════
Tags: #Cybercriminals #Google #Credit Card Fraud #Cyber Lawsuit #Darcula #google #Google Messages #Magic Cat #Phishing Toolkit #Phishing_as_a_Service #Smishing #Yucheng Chang
Title: Hacking “Analytical Amnesia”: How the ATHF Framework Gives AI a Memory for Threat Hunting
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:26:08 +0000
════════════════════════
Tags: #Open Source Tool #AI Agents #ATHF #Cybersecurity 2026 #Infosec Memory #LOCK Template #MITRE ATT&CK #open source #python #Threat Hunting #threat intelligence
Title: The Intimacy Breach: TikTok Sued for Unlawfully Tracking Users on Grindr
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 22 Dec 2025 03:21:32 +0000
════════════════════════
Tags: #Data Leak #AppsFlyer #Article 9 #Austrian DPA #Data Access Request #data privacy #GDPR #Grindr #Max Schrems #noyb #Off_App Tracking #Sensitive Data #TikTok