Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Mortgage Market Crisis: SitusAMC Breach Exposes Data for Customers of JPMorgan, Citi
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 25 Nov 2025 03:27:51 +0000
════════════════════════
Tags: #Data Leak #Citi #cybersecurity #data breach #Financial Services #JPMorgan Chase #Mortgage Market #SitusAMC #third_party risk
Title: The Third-Party Breach Epidemic: When vendors become the largest vulnerability
════════════════════════
𐀪 Author: Nikitha Srinivasan
════════════════════════
Time: Fri, 28 Nov 2025 21:32:34 GMT
════════════════════════
Tags: #cloud_security #identity_management #zero_trust_security #cybersecurity #third_party
Title: OpenAI Users Warned of Phishing Risk After Mixpanel Analytics Provider Breach
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sat, 29 Nov 2025 03:08:27 +0000
════════════════════════
Tags: #Data Leak #Analytics Leak #API Users #data breach #Mixpanel #OpenAI #Phishing Risk #security incident #Third_Party Vendor
Title: The new era of third-party security: The perimeter you don’t control but that defines you
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
Time: Tue, 02 Dec 2025 14:43:19 GMT
════════════════════════
Tags: #infosec #cybersecurity #risk #third_party #grc
Title: One Search, Three Angles: See Employee, Customer And Vendor Leaks At Once With LeakRadar
════════════════════════
𐀪 Author: Alexandre Vandamme
════════════════════════
Time: Sat, 06 Dec 2025 09:02:12 GMT
════════════════════════
Tags: #infosec #threat_intelligence #third_party_risk #cybersecurity #data_breach
Title: macOS LPE Flaw Resurfaces: .localized Directory Exploited to Hijack Installers and Gain Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 16 Dec 2025 00:40:04 +0000
════════════════════════
Tags: #Vulnerability Report #.localized #CVE_2025_24099 #Installer Hijack #Local Privilege Escalation #LPE #macOS #root access #Third_Party Software
Title: EU Compliance: iOS 26.3 Adds Notification Forwarding to Third-Party Wearables, Bypassing Apple Watch
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 16 Dec 2025 02:24:35 +0000
════════════════════════
Tags: #Technology #Apple Watch #compliance #Digital Markets Act #EU DMA #iOS 26.3 #Notification Forwarding #privacy #Third_Party Wearables
Title: The Brazil Breakout: Apple Forced to Unlock iOS for Third-Party App Stores
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 26 Dec 2025 00:04:24 +0000
════════════════════════
Tags: #Technology #Antitrust #App Store #Apple #Brazil #CADE #Core Technology Fee #Digital Markets Act #iOS 26.4 #iPhone security #MercadoLibre #Sideloading #Third_Party App Stores
Title: Lens on Liability: Flickr Warns 35 Million Users of Data Exposure via Third-Party Email Leak
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 10 Feb 2026 09:27:55 +0000
════════════════════════
Tags: #Data Leak #account security #cybersecurity news 2026 #data breach #data privacy #email service provider #flickr #GDPR #phishing alert #PII exposure #SmugMug #third_party risk
Title: Beyond Checkboxes: How Quince Reinvented Vendor Security Assessments
════════════════════════
𐀪 Author: Avinash Jain (@logicbomb)
════════════════════════
Time: Fri, 13 Feb 2026 10:56:44 GMT
════════════════════════
Tags: #vendor_security #infosec #information_security #quince #third_party_risk
Title: Cultural Crisis: How the Vivaticket Ransomware Attack Paralyzed the Louvre and 3,500 European Landmarks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 07 Apr 2026 07:43:03 +0000
════════════════════════
Tags: #Malware #ANSSI #Cybersecurity 2026 #data breach #Eiffel Tower #France #Irec SAS #Louvre #Museum Security #RansomHouse #ransomware #third_party risk #Vivaticket
Title: The Illusion of the Perimeter: Why Your Biggest Risk Lives in Your Supply Chain
════════════════════════
𐀪 Author: Stephen Adanson Roque
════════════════════════
Time: Sun, 12 Apr 2026 11:21:01 GMT
════════════════════════
Tags: #grc #risk_management #cybersecurity #infosec #third_party_risk
Title: Vimeo Data Exposed in Anodot Supply Chain Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 29 Apr 2026 01:29:54 +0000
════════════════════════
Tags: #Data Leak #Anodot #cybersecurity #Data Breach #Google Threat Intelligence #infosec #Metadata Leak #supply chain attack #third_party risk #Vendor Management #Vimeo
Title: Vimeo Revokes Access Following Security Breach at Third-Party Partner Anodot
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 30 Apr 2026 07:21:31 +0000
════════════════════════
Tags: #Data Leak #Analytics Security #Anodot #Cyber Security 2026 #data breach #data privacy #Infosec #Metadata Exposure #supply chain attack #third_party risk #Vimeo
Title: New “TencShell” Malware Weaponizes Open-Source Rshell via Third-Party Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 18 May 2026 12:28:23 +0000
════════════════════════
Tags: #Malware #C2 Framework #Cato CTRL #Cyber Security #Donut Shellcode #infosec #Malware Analysis #Rshell #supply chain attack #TencShell #third_party risk #threat intelligence
Title: China-Linked Hackers Deploy “TencShell” Backdoor via Faux Web Font Files
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 20 May 2026 07:45:33 +0000
════════════════════════
Tags: #Malware #Cato CTRL Threat Research #Donut Shellcode In_Memory Execution #Fileless Position_Independent Code #Rshell Framework Customization #State_Sponsored Cyber Espionage #Tencent API Impersonation #TencShell Backdoor Malware #Third_Party Identity Compromise #Web Font Masquerading #Windows Registry Persistence
Title: Beyond AirPlay: Apple May Finally Allow Google Cast as System-Default in iOS 27
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 25 May 2026 08:54:23 +0000
════════════════════════
Tags: #Apple #Apple AirPlay #Digital Markets Act #DMA interoperability #EU technology regulation #Google Cast #iOS 27 #iPhone streaming #smart home integration #third_party protocol support
Title: Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
Title: Sovereign Intervention: EU Mandates Unhindered Third-Party AI Access to WhatsApp API
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 11 Jun 2026 06:50:51 +0000
════════════════════════
Tags: #Technology #market monopoly rules #Meta European Commission order #Tech News #third party AI integration #WhatsApp antitrust API probe #WhatsApp Business gateway tool
Title: When Trusted Advertising Infrastructure Becomes a Malware Delivery Channel
════════════════════════
𐀪 Author: Jas
════════════════════════
Time: Sat, 01 Aug 2026 18:22:25 GMT
════════════════════════
Tags: #supply_chain_security #application_security #web_security #cybersecurity #third_party_risk