Daily Writeups
3.78K subscribers
4 photos
133K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Splunk Patches High-Severity Bugs Granting DoS and Internal Log Leaks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 22 May 2026 01:20:03 +0000
════════════════════════
Tags: #Vulnerability Report #access control bypass #CVE_2026_20238 #CVE_2026_20239 #CVE_2026_20240 #Cyber Security #Denial of Service #infosec #Log Leak #Session Cookie Exposure #Splunk AI Toolkit #Splunk Enterprise
Title: A Simple Session Management Bug Every Beginner Bug Hunter Should Test.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Sat, 23 May 2026 08:18:09 GMT
════════════════════════
Tags: #simple_bugs #bug_bounty #session_management #p4_bugs
Title: VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 29 May 2026 09:41:23 +0000
════════════════════════
Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
Title: Cryptographic Paradigm Shift: Google Officially Launches Device Bound Session Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
Title: Weaponizing Management Consoles: The FortiClient EMS Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 01 Jun 2026 03:25:22 +0000
════════════════════════
Tags: #Vulnerability #Arctic Wolf Labs report #CVE_2026_35616 vulnerability #EKZ Infostealer analysis #endpoint security bypass #FortiClient EMS exploit #session cookie hijacking
Title: phpBB Authentication Bypass Fixed in Version 3.3.17
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 16 Jun 2026 03:35:00 +0000
════════════════════════
Tags: #Vulnerability #Aikido Security #authentication bypass #Forum Security #phpBB #Session Hijacking #Web Vulnerability
Title: Payroll Pirate Hijacks Sessions to Steal Paychecks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 17 Jun 2026 07:25:30 +0000
════════════════════════
Tags: #Cybercriminals #AiTM Phishing #Business Email Compromise #MFA Bypass #Payroll Fraud #Payroll Pirate #Session Hijacking
Title: $900 Session Flaw: Deprovisioned Users Retain Access After Permission Removal
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
Time: Fri, 19 Jun 2026 01:31:01 GMT
════════════════════════
Tags: #information_security #session_flaw #bug_bounty #programming #cybersecurity
Title: Session Fixation
════════════════════════
𐀪 Author: Ahemd ashraf
════════════════════════
Time: Tue, 07 Jul 2026 21:06:39 GMT
════════════════════════
Tags: #session_fixation #bugbounty_writeup #bug_bounty_tips
Title: pretix Patches Two Critical Session Takeover and SSRF Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Wed, 08 Jul 2026 13:14:14 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Leak #CVE_2026_13602 #CVE_2026_13603 #Payment Plugins #pretix #Session Takeover #ssrf