Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 09 Dec 2025 00:32:24 +0000
════════════════════════
Tags: #Malware #AES_CFB #backdoor #data exfiltration #dpaste #Go Package #Go Typosquatting #security #Supply Chain
Title: The Ghost in the Machine: Master Stealth with the Orsted C2 Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 26 Dec 2025 02:44:26 +0000
════════════════════════
Tags: #Open Source Tool #AMSI Evasion #Command and Control #cybersecurity #Go_lang #Ligolo_ng #Orsted C2 #Penetration Testing #post_exploitation #red teaming #Sandbox Deception
Title: The “Go Client” Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 03 Feb 2026 04:03:24 +0000
════════════════════════
Tags: #Malware #2FA #botnet attack #cybersecurity alert 2026 #Go Client #IT security tips #Remote Access Malware #remote desktop security #RustDesk #self_hosting RustDesk #social engineering
Title: “Fiber” Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:48:59 +0000
════════════════════════
Tags: #Vulnerability Report #Backend Development #CSRF #CVE_2025_66630 #Fiber Framework #go #Golang #Patch Alert #Session Hijacking #UUID #Web Security
Title: Mapping the Blast Radius: Visualize Attack Paths in AWS EKS with This New Go-Based Scanner
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 12 Feb 2026 03:43:18 +0000
════════════════════════
Tags: #Open Source Tool #attack path visualization #AWS EKS #cloud_native security #DevSecOps #eks_security_scanner #Go #IAM security #Kubernetes security #RBAC audit #Tech News 2026 #Threat Modeling
Title: The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 02 Mar 2026 00:43:46 +0000
════════════════════════
Tags: #Malware #APT31 #cryptography #CVE_2026 #go #Golang #infosec #Linux Security #malware #Open Source Security #Rekoobe #supply chain attack
Title: The Rise of the AI Mercenary: Team Cymru Unmasks “CyberStrikeAI” and its Ties to State-Sponsored Operations
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 05 Mar 2026 07:35:31 +0000
════════════════════════
Tags: #Cybercriminals #AI_native hacking #CyberStrikeAI #Ed1s0nZ #Fortinet FortiGate #Go programming language #Knownsec 404 #NetFlow analysis #Offensive Security #privilege escalation #Team Cymru #Tech News 2026
Title: Path Traversal Vulnerability in Go: From Source Code Review to Exploitation
════════════════════════
𐀪 Author: Sanaullah Aman Korai
════════════════════════
Time: Sat, 04 Apr 2026 18:47:27 GMT
════════════════════════
Tags: #penetration_testing #web_security #ethical_hacking #cybersecurity #go_programming
Title: Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 07 Apr 2026 09:15:50 +0000
════════════════════════
Tags: #Malware #CrystalX RAT #Cyber Trolling #Go malware #infosec #kaspersky #MaaS #Malware Analysis #Prankware #Remote Access Trojan #spyware #Telegram #Webcrystal RAT
Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Title: Team Cymru Mapped the Yurei Ransomware Toolkit Before It Could Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 08 Apr 2026 09:20:15 +0000
════════════════════════
Tags: #Malware #Double Extortion #go programming #infosec #open_source malware #Prince ransomware #Ransomware Tool Matrix #SatanLockv2 #Team Cymru #threat intelligence #Yurei ransomware
Title: The High-Stakes Return of 0xFFF: ‘notnullOSX’ Stealer Targets macOS Crypto Whales
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 14 Apr 2026 02:30:33 +0000
════════════════════════
Tags: #Malware #0xFFF #alh1mik #ClickFix #Crypto Stealer #cyber_espionage #DeFi Security #Go malware #Hardware Wallet #macOS Malware #Moonlock Lab #notnullOSX
Title: CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 16 Apr 2026 12:06:01 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_40884 #CVSS 9.8 #cybersecurity #Go Security #goshs #infosec #pentesting tools #SFTP #SimpleHTTPServer
Title: Unpatch Ollama Flaw: Malicious Model Uploads Can Leak Server Heap Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 13:05:24 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #CVE_2026_5757 #GGUF #Go Security #Heap Leak #Information Disclosure #infosec #LLM Security #Ollama #Quantization Engine #zero_day
Title: Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 12:03:00 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Thrift #C++ #CVE_2026_41603 #cybersecurity #go #infosec #java #memory corruption #mitm #Node.js #RPC Security #swift
Title: Minirat’s Stealth Supply Chain Attack Targets macOS Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 01 May 2026 01:59:57 +0000
════════════════════════
Tags: #Malware #@velora_dex/sdk #2026 #cybersecurity #developer security #go #infosec #macOS #Malware Analysis #Minirat #npm #Remote Access Trojan #supply chain attack
Title: Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack