Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Title: cPanel Issues Emergency Patch for All Supported Versions
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 29 Apr 2026 01:16:31 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Vulnerability #CPanel #cybersecurity #infosec #Patch Alert #security update #Server Management #Server Security #SysAdmin #Web Hosting #WHM
Title: 44,000 IPs Hijacked: cPanel’s 9.8 CVSS Authentication Bypass Triggers Global Ransomware Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 02:04:53 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #CISA KEV #CPanel #CVE_2026_41940 #CVSS 9.8 #cybersecurity #infosec #Mirai botnet #ransomware #Server Security #WebPros #WHM
Title: The File Timestamp That Didn’t Make Sense — And Why I Didn’t Ignore It
════════════════════════
𐀪 Author: Faruk Ahmed
════════════════════════
Time: Tue, 05 May 2026 15:32:14 GMT
════════════════════════
Tags: #linux #sysadmin #infosec #server_security #cybersecurity
Title: GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 02:02:36 +0000
════════════════════════
Tags: #Vulnerability Report #Argo CD #cloud_native #CVE_2026_42880 #cybersecurity #data leak #GitOps #infosec #Kubernetes #Kubernetes Secrets #Patch Alert #Server_Side Diff
Title: Emergency Patch: Critical RCE Vulnerability in Apache HTTP Server 2.4.67 Threatens Millions of Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 06 May 2026 07:31:31 +0000
════════════════════════
Tags: #Vulnerability #Apache HTTP Server #CVE_2026_23918 #CVE_2026_24072 #Cybersecurity 2026 #HTTP/2 #mod_rewrite #Patch Management #privilege escalation #RCE #remote code execution #Server Security
Title: Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 12:38:06 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_41901 #cybersecurity #infosec #Java security #Patch Alert #rce #Sandbox Bypass #Server Side Template Injection #ssti #Thymeleaf #web development
Title: cPanel & WHM Patch 5 High-Severity Flaws, Including 8.6 Severity File Read and SQLi
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 15 May 2026 02:22:43 +0000
════════════════════════
Tags: #Vulnerability Report #Arbitrary File Read #CPanel #CVE_2026_29205 #CVE_2026_29206 #Cyber Security #infosec #Patch Alert #Server Security #sql injection #WHM #WP Squared
Title: Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 18 May 2026 06:56:21 +0000
════════════════════════
Tags: #Vulnerability #Cloud Metadata Exploit #CVE_2026_44578 #CWE_918 #Next.js #Security Patch 2026 #Self_Hosted Node.js #Server_Side Request Forgery #SSRF #Vercel #WebSocket Upgrade
Title: What Are the Types of Attacks Against Web Servers?
════════════════════════
𐀪 Author: Vpshosting
════════════════════════
Time: Mon, 18 May 2026 05:49:42 GMT
════════════════════════
Tags: #types_of_attacks #web_server_attacks #hacking #server_attack
Title: Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
Title: The Underminr Paradigm: Subverting DNS Filters via CDN Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 27 May 2026 04:46:33 +0000
════════════════════════
Tags: #Information Security #ADAMnetworks threat intelligence #cloud command and control traffic #cross tenant CDN routing exploit #Encrypted Client Hello ECH security #legacy domain fronting comparison #outminr network monitoring tool #Protective DNS bypass #Server Name Indication SNI spoofing #shared infrastructure website blacklisting #Underminr DNS evasion technique
Title: Comet Backup Server Flaw Exposes Remote Customer Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sun, 31 May 2026 09:56:41 +0000
════════════════════════
Tags: #Vulnerability Report #Comet Backup #CVE_2026_32999 #RCE vulnerability #Server Security #Software Patch
Title: Severe Plesk Privilege Escalation Flaw Patched in Linux Versions
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 01 Jun 2026 04:49:52 +0000
════════════════════════
Tags: #Vulnerability Report #Linux Security #Plesk #privilege escalation #Server Security #Xpath injection
Title: Critical Security Flaw Exposes Apache LDAP API Connections
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 02 Jun 2026 04:09:06 +0000
════════════════════════
Tags: #Vulnerability #Apache Directory #CVE_2026_35563 #LDAP API #Security Advisory #Server Identity
Title: Apache Fesod SSRF Vulnerability Exposes Internal Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 02 Jun 2026 03:55:30 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Fesod #CVE_2026_49328 #Java Library #Server Security #SSRF vulnerability
Title: Automated Remediation: Microsoft Resolves Cumulative Update Rollback Failures
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 11 Jun 2026 12:24:13 +0000
════════════════════════
Tags: #Windows #component store corruption #DISM manual fix tool #installation loops error #server side rollback #update installation fault #Windows 11 update anomaly