Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Instagram’s “17 Million User Data Leak” Was Just Scraped Records from 2022
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Sun, 11 Jan 2026 22:24:14 +0000
════════════════════════
Tags: #Leaks #Security #BreachForums #Cybersecurity #data breach #Instagram #LeakBase #LEAKS #Malwarebytes #Meta #Privacy
1
Title: Beyond IDOR: Discovering a Stored XSS in a Vulnerable Web Platform
════════════════════════
𐀪 Author: mv999exe
════════════════════════
Time: Sun, 11 Jan 2026 22:11:49 GMT
════════════════════════
Tags: #penetration_testing #bug_bounty_writeup #bug_bounty #pentesting
Title: 30 Days of Red Team: Day 15 — Credential Harvesting
════════════════════════
𐀪 Author: Maxwell Cross
════════════════════════
Time: Sun, 11 Jan 2026 22:43:18 GMT
════════════════════════
Tags: #ethical_hacking #infosec #red_teaming #cybersecurity #penetration_testing
Title: Professional Ethical Hacking & Digital Investigation Services.
════════════════════════
𐀪 Author: Private-hackers.com
════════════════════════
Time: Sun, 11 Jan 2026 22:55:15 GMT
════════════════════════
Tags: #digital_investigation #hireprofessionalhacker #ethical_hacking #account_recovery #cybersecurity
Title: The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 01:46:54 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Struts 2 #CVE_2025_68493 #Denial of Service #Java security #ssrf #XWork #XXE Injection #ZAST.AI
Title: CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:32:41 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Spark #Apache Uniffle #Big Data Security #CVE_2025_68637 #Hadoop MapReduce #mitm attack #network_security #SSL Verification
Title: “Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:28:23 +0000
════════════════════════
Tags: #Cybercriminals #Acronis #Astaroth #Banking Trojan #Boto Cor_de_Rosa #Malware Analysis #Python Worm #social engineering #WhatsApp Security
Title: Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:22:56 +0000
════════════════════════
Tags: #Cybercriminals #Crypto Scams #Cybercrime Economy #Fraud Intelligence #Infoblox #PBaaS #Penguin (Threat Actor) #Pig Butchering #UWORK
Title: CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:22:14 +0000
════════════════════════
Tags: #Vulnerability Report #buffer overflow #CVE_2026_22184 #Data Compression #Open Source Security #Remote Code Execution #untgz #vulnerability management #zlib
Title: RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:17:36 +0000
════════════════════════
Tags: #Cyber Security #Malware #APT (Advanced Persistent Threat) #CloudSEK #Malware Analysis #Middle East Cyberattacks #MuddyWater #Rust malware #RustyWater #Spearphishing
Title: Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:12:46 +0000
════════════════════════
Tags: #Vulnerability Report #CERT Polska #CVE_2025_66049 #End of Life (EOL) #IoT Vulnerability #IP Camera Security #RTSP #Surveillance Privacy #Vivotek
Title: China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:07:39 +0000
════════════════════════
Tags: #Cyber Security #APT #Bulbature #Cisco Talos #Critical Infrastructure #cyber_espionage #ORB (Operational Relay Box) #Telecommunications Security #UAT_7290
Title: Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 00:02:09 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_14338 #CVE_2025_66005 #D_Bus Security #InputPlumber #Linux Gaming #privilege escalation #SteamOS #SUSE
Title: VulnBank — FahemSec Web Challenge
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
Time: Mon, 12 Jan 2026 00:17:39 GMT
════════════════════════
Tags: #penetration_testing #cybersecurity #bug_bounty #ctf #hacking
Title: Threat Modeling Guide: STRIDE, Data Flow Diagrams, Risk Ranking & Mitigations
════════════════════════
𐀪 Author: QuarkAndCode
════════════════════════
Time: Mon, 12 Jan 2026 00:38:37 GMT
════════════════════════
Tags: #strideframework #application_security #data_flow_diagram #devsecops #threat_modeling
Title: Defense-in-Depth for AI Agents: Why Input Security Isn’t Enough
════════════════════════
𐀪 Author: David Anderson
════════════════════════
Time: Sun, 11 Jan 2026 23:47:30 GMT
════════════════════════
Tags: #llm #artificial_intelligence #cybersecurity #application_security #ai
Title: Master CISSP Domain 4: 40 Coffee Shot Questions (Part 2 of 2)
════════════════════════
𐀪 Author: Pushpak Sharma
════════════════════════
Time: Mon, 12 Jan 2026 01:30:14 GMT
════════════════════════
Tags: #cissp #cybersecurity #infosec #arp_layer #isc2
Title: The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 03:47:57 +0000
════════════════════════
Tags: #Data Leak #2FA #Account Hijacking #API Leak #Cybersecurity 2026 #dark web #Data Breach #Instagram #Malwarebytes #Meta #phishing #Solonik
Title: WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 03:16:33 +0000
════════════════════════
Tags: #Vulnerability #Coraza #Cross_Site Scripting (XSS) #modsecurity #OWASP CRS #Rule 922110 #WAF Bypass #web application security
Title: Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
Title: The Soviet Ghost: How Carding Markets Survive on Legacy Domains
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 12 Jan 2026 02:04:47 +0000
════════════════════════
Tags: #Cybercriminals #.su Domain #bulletproof hosting #carding #Credit Card Fraud #Cybercrime Economy #Dark Web Markets #Team Cymru #threat intelligence