Daily Writeups
3.49K subscribers
2 photos
128K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Securing Cloud APIs in Azure: Detecting and Preventing Token Replay Using Identity and Context with…
════════════════════════
𐀪 Author: Prasoon Mathur
════════════════════════
Time: Wed, 22 Apr 2026 23:50:18 GMT
════════════════════════
Tags: #api_security #cloud_security #cybersecurity #azure #zero_trust
Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Title: TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Title: PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
Title: Microsoft Defender Zero-Day “BlueHammer” Hits KEV Catalog Following Researcher’s Protest
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 01:53:17 +0000
════════════════════════
Tags: #Vulnerability Report #BlueHammer #CISA KEV #CVE_2026_33825 #Huntress Labs #infosec #Local Privilege Escalation #LPE #Microsoft Defender #Microsoft Security #RedSun #SAM Database #TOCTOU #UnDefend
Title: ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 01:11:34 +0000
════════════════════════
Tags: #Malware #AppleScript #ClickFix #Crypto theft #cybersecurity #Infostealer #macOS #macOS Tahoe #malware #Netskope #phishing #Session Hijacking #social engineering
Title: Fuzzing 101: How Security Researchers Find Bugs Before Hackers Do
════════════════════════
𐀪 Author: Parth Patel
════════════════════════
Time: Thu, 23 Apr 2026 02:31:01 GMT
════════════════════════
Tags: #software_engineering #hacking #vulnerability_research #cybersecurity #programming
Title: Agent T Challenge — Fixed Python code| TryHackMe
════════════════════════
𐀪 Author: Tengku M Zulfadli
════════════════════════
Time: Thu, 23 Apr 2026 02:49:50 GMT
════════════════════════
Tags: #tryhackme #nmap #python_programming #gobuster
Title: OWASP API Security Top 10–1 | MayankNingania | TryHackMe
════════════════════════
𐀪 Author: Mayank Ningania
════════════════════════
Time: Thu, 23 Apr 2026 02:25:28 GMT
════════════════════════
Tags: #mayankningania #owasp_api_security_top_10 #tryhackme_walkthrough #tryhackme_writeup #tryhackme
Title: CSP bypass and Dangling Markup Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
Time: Thu, 23 Apr 2026 00:58:15 GMT
════════════════════════
Tags: #xss_attack #css #xs #content_security_policy #cross_site_scripting
Title: DOM Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
Time: Thu, 23 Apr 2026 00:57:54 GMT
════════════════════════
Tags: #xs #jquery #css #xss_attack #dom_xss
Title: Blind SQL injection with time delays and information retrieval
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
Time: Thu, 23 Apr 2026 01:47:09 GMT
════════════════════════
Tags: #conditional_time_delay #sql_injection #blind_sql_injection
Title: Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 04:15:52 +0000
════════════════════════
Tags: #Linux #Vulnerability Report #CVE_2026_41651 #Debian #Fedora #infosec #Linux Security #Pack2TheRoot #PackageKit #Patch Alert #privilege escalation #race condition #Root Exploit #Ubuntu
Title: Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 03:08:07 +0000
════════════════════════
Tags: #Vulnerability Report #Arbitrary File Upload #Breeze #Cloudways #CVE_2026_3844 #CVSS 9.8 #PHP Web Shell #Plugin Vulnerability #rce #Wordfence #WordPress Exploit #wordpress security
Title: Session Management Bugs — The Hidden Goldmine in Bug Bounty
════════════════════════
𐀪 Author: Pradeeptadi
════════════════════════
Time: Thu, 23 Apr 2026 03:16:52 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty
Title: Cisco notes Network Basics — Module 16:Application Service Layer
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
Time: Thu, 23 Apr 2026 04:46:23 GMT
════════════════════════
Tags: #web_development #cybersecurity #networking #infosec #ethical_hacking
Title: Cisco notes Network Basics — Module 15:TCP and UDP
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
Time: Thu, 23 Apr 2026 04:45:10 GMT
════════════════════════
Tags: #ethical_hacking #information_security #web_development #infosec #cybersecurity
Title: OWASP APTS
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
Time: Thu, 23 Apr 2026 03:59:24 GMT
════════════════════════
Tags: #ai #ai_pentesting #penetration_testing #owasp
Title: Blind SQL injection with out-of-band data exfiltration
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
Time: Thu, 23 Apr 2026 04:02:30 GMT
════════════════════════
Tags: #out_of_band_interaction #dns_lookup #blind_sql_injection #sql_injection