Daily Writeups
3.53K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: The Persistence of WinRAR: Google Warns of Widespread CVE-2025-8088 Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:15:22 +0000
════════════════════════
Tags: #Cybercriminals #Vulnerability #Ads #CVE_2025_8088 #Google Threat Intelligence #InfoSec 2026 #path traversal #phishing #RomCom #Sandworm #Startup Persistence #Winrar
Title: Defending the Start-Up Nation: Israel Unveils First Permanent Cyber Law
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:14:01 +0000
════════════════════════
Tags: #Cyber Security #Critical Infrastructure #Cyber Security 2026 #data privacy #INCD #Infosec #Israel #Knesset #National Cyber Defense Bill #National Resilience #Yossi Karadi
Title: Memory Under Siege: OpenSSL Releases Urgent Patches for Critical Buffer Overflows
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:12:17 +0000
════════════════════════
Tags: #Vulnerability #AES_GCM #Buffer Overflow #cryptography #CVE_2025_15467 #InfoSec 2026 #openssl #PKCS#12 #Security Patch #Sysadmin #TLS 1.3
Title: Shadow Bankers of the Blockchain: The $16B Rise of Chinese Crypto-Laundering
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:09:39 +0000
════════════════════════
Tags: #Cybercriminals #Black U #Blockchain Forensics #Chainalysis #cryptocurrency #cybercrime #Huione #InfoSec 2026 #Money Laundering #Shadow Banking #USDT #Xinbi
Title: The Heart of Downing Street: China’s Salt Typhoon Infiltrates UK PMs’ Phones
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:08:22 +0000
════════════════════════
Tags: #Cyber Security #Boris Johnson #Chinese Hackers #Cyber Espionage #Downing Street #Five Eyes #GCHQ #InfoSec 2026 #MI5 #Rishi Sunak #Salt Typhoon
Title: The Botnet Merger: Kimwolf Hijacks 10 Million Badbox 2.0 Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:05:49 +0000
════════════════════════
Tags: #Malware #ADB Exploit #Android TV #BadBox 2.0 #BOTNET #Brian Krebs #DDoS #InfoSec 2026 #IoT Security #Kimwolf #Residential Proxies
Title: WhatsApp’s Great Migration: New Lockdown Mode and Rust-Powered Media Security
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 29 Jan 2026 04:02:36 +0000
════════════════════════
Tags: #Technology #C++ #InfoSec 2026 #Lockdown Mode #Media Security #Memory Safety #Meta #Rust #Spyware Protection #Strict Account Settings #WhatsApp
Title: Red Teaming at Scale: GHARF Automates the Attack Lifecycle via CI/CD
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 08:08:16 +0000
════════════════════════
Tags: #Open Source Tool #Automation #CAI/CAD #CI/CD Security #DevSecOps #GHARF #GitHub Actions #InfoSec 2026 #Offensive Security #Pentesting #red teaming
Title: The Browser Puppeteer: New Vishing Kits Hijack Sessions in Real-Time
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 08:03:56 +0000
════════════════════════
Tags: #Cybercriminals #FIDO2 #InfoSec 2026 #MFA Bypass #Okta #Okta FastPass #Phishing_as_a_Service #Session Orchestration #ShinyHunters #Social Engineering #Vishing
Title: The Industrialized Scam: How Sinch and Microsoft Teams Power the Global Fraud Trade
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 08:01:55 +0000
════════════════════════
Tags: #Cybercriminals #Callback Scheme #Demurrage Report #InfoSec 2026 #Inteliquent #KYC #Microsoft Teams #Sinch #Telecom Security #Tom Walker #VoIP Fraud
Title: The ERP Breach: North Korea’s Andariel Group Strikes Europe with New Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 08:00:03 +0000
════════════════════════
Tags: #Malware #Andariel #BYOVD #ERP Hack #GopherRAT #InfoSec 2026 #JelusRAT #North Korea #StarshellRAT #supply chain attack #TigerRAT #WithSecure
Title: MFA Under Siege: Microsoft Unveils Stealthy AiTM Attacks Striking the Energy Sector
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 07:58:44 +0000
════════════════════════
Tags: #Cybercriminals #AiTM #BEC #Energy Sector #InfoSec 2026 #MFA Bypass #Microsoft #Microsoft Defender #phishing #Session Hijacking #SharePoint
Title: The Developer’s Trap: EmEditor Supply Chain Attack Drains Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 07:57:05 +0000
════════════════════════
Tags: #Malware #Developer Security #EmEditor #Emurasoft #Google Drive Caching #InfoSec 2026 #Infostealer #PowerShell #supply chain attack #Trend Micro #Watering Hole
Title: The Year the Web Faltered: Cloudflare’s 2025 Report Unveils a Fragile Digital World
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 07:52:42 +0000
════════════════════════
Tags: #Technology #Cloudflare Radar #Digital Blackout #InfoSec 2026 #Infrastructure Security #Internet Outage #Network Resilience #Submarine Cables #Tanzania Election #WACS
Title: Office Under Siege: Microsoft Rushes Emergency Fix for Active Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 28 Jan 2026 07:51:07 +0000
════════════════════════
Tags: #Vulnerability #CISA #CVE_2026_21509 #Cyber Security #InfoSec 2026 #Microsoft 365 #Microsoft Office #OLE Bypass #Patch Management #Social Engineering #zero_day
Title: VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 31 Jan 2026 00:32:16 +0000
════════════════════════
Tags: #Cybercriminals #Android security #botnet #Galleon VPN #Google Threat Intelligence #IPIDEA #Malicious SDK #Proxy Hijacking #Radish VPN #residential proxy #Windows malware
Title: From User to SYSTEM: PoC Released for Zabbix Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 30 Jan 2026 02:52:48 +0000
════════════════════════
Tags: #Vulnerability #Patch Alert #PoC #privilege escalation #SYSTEM privileges #Windows Security #Zabbix #Zabbix Agent
Title: “Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 30 Jan 2026 02:15:55 +0000
════════════════════════
Tags: #Malware #Antivirus Compromise #cyber attack #eScan #infosec #malware #Manual Patch #MicroWorld Technologies #Morphisec #Reload.exe #supply chain attack
Title: Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 30 Jan 2026 01:59:19 +0000
════════════════════════
Tags: #Vulnerability Report #building automation #CISA #Critical Vulnerability #CVE_2025_26385 #ICS security #Johnson Controls #Metasys #Smart Building #sql injection #TCP 1433
Title: Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 30 Jan 2026 01:52:21 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #exploited in the wild #Ivanti EPMM #MDM #mobile security #MobileIron Core #rce #Remote Code Execution #unauthenticated RCE #zero_day
Title: Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 30 Jan 2026 00:27:09 +0000
════════════════════════
Tags: #Vulnerability Report #Admission Controller #cloud_native #CVE_2026_22039 #CVE_2026_23881 #DevSecOps #dos #K8s #Kubernetes Security #Kyverno #privilege escalation