Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Protect Your Rails API with Rack-Attack Rate Limiting (Step-by-Step)️
════════════════════════
𐀪 Author: Ahmet Kaptan
════════════════════════
Time: Wed, 12 Nov 2025 09:32:21 GMT
════════════════════════
Tags: #rest_api #api_security #ruby_on_rails #software_development #backend_development
Title: Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
Title: Ruby 4.0 Unwrapped: Meet ZJIT and the Game-Changing Ruby Box
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 26 Dec 2025 02:26:41 +0000
════════════════════════
Tags: #Technology #Backend #JIT Compiler #Memory Safety #performance #Programming 2026 #Ractor #Ruby 4.0 #Ruby Box #Web Development #ZJIT
Title: How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
════════════════════════
𐀪 Author: Ahmed Tarek
════════════════════════
Time: Sat, 17 Jan 2026 19:06:39 GMT
════════════════════════
Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby
Title: Secure Query Practices in Ruby on Rails
════════════════════════
𐀪 Author: Muhammad Bin Hussain
════════════════════════
Time: Fri, 20 Feb 2026 20:30:29 GMT
════════════════════════
Tags: #ruby_on_rails #web_security #secure_coding_practice #sql_injection #backend_development
Title: The Unsafe Send: How an HTTP Client Library Led to Remote Code Execution
════════════════════════
𐀪 Author: Alperen
════════════════════════
Time: Sat, 21 Feb 2026 02:44:52 GMT
════════════════════════
Tags: #hackerone #source_code_security #source_code #ruby #bugbounty_writeup
Title: Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
Title: Rate Limiting Your Rails API with Rack::Attack gem
════════════════════════
𐀪 Author: Talha Khalid
════════════════════════
Time: Mon, 02 Mar 2026 00:52:59 GMT
════════════════════════
Tags: #api_rate_limiting #api_security #ruby_on_rails #web_development #rubygems
Title: Bridging the Gap: North Korean APT37 Deploys ‘Ruby Jumper’ to Infiltrate Isolated Air-Gapped Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 03 Mar 2026 00:05:18 +0000
════════════════════════
Tags: #Malware #Air_gap attack #APT37 #Cloud C2 #infosec #North Korean APT #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB malware #VIRUSTASK
Title: Jumping the Gap: APT37’s “Ruby Jumper” Campaign Weaponizes Cloud Storage and USBs to Breach Isolated Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 04 Mar 2026 07:01:03 +0000
════════════════════════
Tags: #Cybercriminals #air_gapped network #APT37 #Cybersecurity 2026 #RESTLEAF #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB Malware #Velvet Chollima #VIRUSTASK #Zoho WorkDrive #Zscaler ThreatLabz
Title: Rocket — CVE-2021–22911 NoSQL Injection + Ruby cap_setuid to Root | TryHackMe
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
Time: Tue, 14 Apr 2026 14:46:42 GMT
════════════════════════
Tags: #penetration_testing #cybersecurity #ethical_hacking #sql #ruby
Title: GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 13 May 2026 04:21:32 +0000
════════════════════════
Tags: #Malware #Cyber Security #data exfiltration #GemStuffer #infosec #Malware Analysis #ModernGov #Ruby Security #RubyGems #Socket #supply chain attack #UK Council Security
Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Title: Before You Deploy, Ask One Question: Are Your Gems Secure?
════════════════════════
𐀪 Author: J3
════════════════════════
Time: Mon, 15 Jun 2026 20:04:58 GMT
════════════════════════
Tags: #devsecops #ruby_on_rails #cybersecurity #application_security #bundleraudit
Title: Stop Ignoring Brakeman Warnings: The Hidden Meaning Behind CWE Codes
════════════════════════
𐀪 Author: J3
════════════════════════
Time: Sat, 20 Jun 2026 15:50:42 GMT
════════════════════════
Tags: #cwecodes #ruby_on_rails #application_security #brakeman #secure_coding
Title: Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 22 Jun 2026 01:11:11 +0000
════════════════════════
Tags: #Vulnerability Report #admin panel #Authorization Bypass #Avo #CVE_2026_55518 #Missing Authorization #privilege escalation #Rails Security #ruby on rails
Title: Rails Active Storage Flaw CVE-2026-66066 Enables Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 30 Jul 2026 03:01:13 +0000
════════════════════════
Tags: #Vulnerability Report #Active Storage #Arbitrary File Read #CVE_2026_66066 #libvips #Remote Code Execution #ruby on rails
Title: Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Fri, 31 Jul 2026 07:30:22 +0000
════════════════════════
Tags: #Vulnerability Report #depthfirst #gitlab #GitLab RCE #ipynbdiff #memory corruption #Oj #proof_of_concept #Remote Code Execution #Ruby
Title: CVE-2026-66066: Rails Active Storage RCE Exploit Code Now Public
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Sat, 01 Aug 2026 10:17:36 +0000
════════════════════════
Tags: #Vulnerability Report #Active Storage #Arbitrary File Read #CVE_2026_66066 #KindaRails2Shell #libvips #metasploit #Remote Code Execution #ruby on rails
Title: KindaRails2Shell: Ruby on Rails CVE-2026-66066 RCE Flaw
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
Time: Tue, 04 Aug 2026 07:28:06 +0000
════════════════════════
Tags: #Vulnerability #Active Storage #CVE_2026_66066 #cybersecurity #KindaRails2Shell #Ruby on Rails