Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: “Fiber” Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:48:59 +0000
════════════════════════
Tags: #Vulnerability Report #Backend Development #CSRF #CVE_2025_66630 #Fiber Framework #go #Golang #Patch Alert #Session Hijacking #UUID #Web Security
Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Title: Unmasking the Proxy: Silent Push “Traffic Origin” Exposes True Actor Locations
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:42:34 +0000
════════════════════════
Tags: #Cybercriminals #cyber_espionage #geolocation #Insider Threats #IP Analysis #North Korean IT workers #residential proxies #Silent Push #threat intelligence #Traffic Origin #VPN Detection
Title: Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
Title: Fake CEO, Real Hack: North Korea Uses AI Deepfakes to Steal Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:32:29 +0000
════════════════════════
Tags: #Cyber Security #Malware #AI Threat #CHROMEPUSH #Cryptocurrency Theft #DEEPBREATH #Deepfake Attack #macOS Malware #Mandiant #SILENCELIFT #social engineering #UNC1069
Title: Factory Flaw: Critical WAGO Switch Vulnerabilities (CVSS 9.8) Allow Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:27:08 +0000
════════════════════════
Tags: #Vulnerability Report #buffer overflow #CERT@VDE #CVE_2026_22904 #CVE_2026_22906 #Hardcoded Encryption Key #ICS security #Industrial Managed Switch #OT Security #SCADA #WAGO 852 Series
Title: Hiding in the Cloud: GuLoader Malware Evolves to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:22:09 +0000
════════════════════════
Tags: #Malware #CloudEye #cybersecurity #Downloader #Google Drive Malware #GuLoader #infosec #Malware Analysis #Obfuscation #Polymorphic Code #Zscaler ThreatLabz
Title: CVE-2026-23906: Authentication Bypass Flaw Hits Apache Druid Analytics Clusters
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:17:59 +0000
════════════════════════
Tags: #Vulnerability Report #Anonymous Bind #Apache Druid #Authentication Bypass #big data #CVE_2026_23906 #database security #LDAP Authentication #Patch Alert #Real_Time Analytics
Title: 5 Benefits of Using Automation to Stay in Touch With Customers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:13:21 +0000
════════════════════════
Tags: #Technology
Title: Signed” Sealed, Delivered: Cybercriminals Abuse PayPal and Apple to Bypass Email Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:11:33 +0000
════════════════════════
Tags: #Cybercriminals #business email compromise #DKIM replay #DMARC #Email Security #INKY #Invoice Fraud #Kaseya #PayPal Scam #phishing #social engineering
Title: Handshake Halt: GnuTLS 3.8.12 Fixes TLS 1.3 Crash & CPU Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:06:40 +0000
════════════════════════
Tags: #Vulnerability Report #Certificate Verification #CVE_2025_14831 #CVE_2026_1584 #Denial of Service #GnuTLS #network_security #Patch Alert #PSK Binder #SSL/TLS #TLS 1.3
Title: CVE-2026-24343: Apache HertzBeat Flaw Opens Door to Resource Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:00:20 +0000
════════════════════════
Tags: #Vulnerability Report #Apache HertzBeat #CVE_2026_24343 #Denial of Service #DevOps #Monitoring Tools #Observability #Patch Alert #Resource Exhaustion #Xpath injection
Title: Firewall and IDS/IPS: Hard Lab — HackTheBox
════════════════════════
𐀪 Author: William Shively
════════════════════════
Time: Wed, 11 Feb 2026 01:25:17 GMT
════════════════════════
Tags: #hackthebox #nmap #hacking #penetration_testing
Title: NOTICE: Date/Time Normalization Maintenance of Historical CVE Records to Occur February 16–25, 2026
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
Time: Tue, 10 Feb 2026 23:53:27 GMT
════════════════════════
Tags: #infosec #vulnerability #cybersecurity #information_security #technology
Title: PicoCTF.org CTF Challenge Write Up
Category: Web Exploitation

════════════════════════
𐀪 Author: Damian Robert Moore
════════════════════════
Time: Wed, 11 Feb 2026 03:51:40 GMT
════════════════════════
Tags: #capture_the_flag #no_ai_here #web_exploitation #bug_bounty #picoctf
Title: Blind OS Command Injection with Out-of-Band DNS Interaction
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Wed, 11 Feb 2026 03:17:23 GMT
════════════════════════
Tags: #command_injection #blind_os_injection #os_command_injection #bug_bounty #dns_data_exfiltration
Title: Logic Poisoning: How One Bad Review Broke Ratings
════════════════════════
𐀪 Author: Parth Narula
════════════════════════
Time: Wed, 11 Feb 2026 02:52:13 GMT
════════════════════════
Tags: #bug_bounty #bug_bounty_tips #web_application_security #bug_bounty_writeup #vulnerability
Title: How To Hack Part 3
════════════════════════
𐀪 Author: Red
════════════════════════
Time: Wed, 11 Feb 2026 02:11:00 GMT
════════════════════════
Tags: #education #cybersecurity #infosec #linux #hacking
Title: CSRF Vulnerability Analysis in DVWA (Low to Impossible)
════════════════════════
𐀪 Author: Narathama Firmansyah Putra
════════════════════════
Time: Wed, 11 Feb 2026 03:05:11 GMT
════════════════════════
Tags: #csrf_attack #web_penetration_testing #penetration_testing #dvwa #cybersecurity
Title: Sideloading Sidestepped: The UK’s “Light-Touch” Gamble on the Apple-Google Duopoly
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 04:56:03 +0000
════════════════════════
Tags: #Technology #App Store #Apple #CMA #digital regulation #DMA vs UK policy #google #mobile duopoly #Sideloading #Strategic Market Status #tech monopoly #Tech News 2026
Title: Beyond the Screen: Samsung’s Galaxy S26 Ultra Debuts “Magic Flex” Privacy and Agentic AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 04:51:56 +0000
════════════════════════
Tags: #Android #Technology #60W charging #Agentic AI #Galaxy S26 Ultra #Galaxy Unpacked 2026 #Magic Flex Pixel #One UI 8.5 #privacy display #samsung #Snapdragon 8 Elite Gen 5 #Tech News 2026