Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
Title: Hardware-Locked: How Chrome’s New DBSC Makes Stolen Cookies Worthless
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 14 Apr 2026 07:18:14 +0000
════════════════════════
Tags: #Technology #Chrome 146 #cybersecurity #DBSC #Device Bound Credentials #google chrome #infosec #InfoStealer malware #Secure Enclave #Session Hijacking #TPM #Web Security
Title: Hackers Hijack Microsoft 365 Accounts via Legitimate Device Code Flows
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 08 May 2026 09:07:51 +0000
════════════════════════
Tags: #Cybercriminals #Cyber Espionage #Device Code Flow #Graphish #M365 Hardening #Microsoft 365 #OAuth #Passwordless Security #phishing 2026 #Proofpoint #QR Code Phishing #SquarePhish2 #TA2723
Title: BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 15 May 2026 02:49:46 +0000
════════════════════════
Tags: #Open Source Tool #Azure AD #BAADTokenBroker #cloud security #Device_Bound Keys #Kerberos #Microsoft Entra ID #NT Hash #post_exploitation #PRT Cookie #red teaming #TGT
Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Title: Microsoft Explains the New “SecureBoot” Folder in Windows 11 KB5089549 Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
Title: Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 19 May 2026 07:11:10 +0000
════════════════════════
Tags: #Cybercriminals #Cloud Security #Cyber Security #Device Authorization Grant #eSentire TRU #infosec #MFA Bypass #Microsoft 365 #Multi_Factor Authentication #OAuth 2.0 #PhaaS #Phishing_as_a_Service #Tycoon 2FA
Title: Intel Architects High-Velocity Point-to-Point Interconnect Paradigm for Linux
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 27 May 2026 06:37:39 +0000
════════════════════════
Tags: #Linux #/dev/tbstreamX character device #cable based host to host streaming #ConfigFS USB4 tunnel configuration #device to device file sharing #hardware peripheral virtualization #Intel thunderbolt_stream kernel patch #Linux USB4STREAM driver protocol #low dependency disaster recovery backup #Mika Westerberg Linux 7.2 merge #raw packet transfer over Thunderbolt
Title: Telemetry Interception: The Unauthorized Routing of Motorola’s Amazon Gateway
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 28 May 2026 03:32:30 +0000
════════════════════════
Tags: #Technology #Allison Yi product management statement #Amazon affiliate code injection #Android launcher app hijacking #Device Native mobile ad monetization #disable Motorola Smart Feed #kira_abboud.com tracking domain #mobile bloatware browser detour #Motorola Razr 60 Ultra app drawer bug #Motorola Smart Feed redirect
Title: Cryptographic Paradigm Shift: Google Officially Launches Device Bound Session Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
Title: Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
Title: Device Code Phishing Using Graph Runner
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
Title: Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Title: Default Security Becomes a Backdoor: Assessing the Smart Wi-Fi Camera
════════════════════════
𐀪 Author: Veereshgadige
════════════════════════
Time: Wed, 15 Jul 2026 12:35:31 GMT
════════════════════════
Tags: #device_security #iot_security #penetration_testing
Title: Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
Title: Misconfigured Server Exposes Three AiTM Phishing Operators
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
Title: LG Monitors Auto-Install Adware Through Windows Device Metadata
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 21 Jul 2026 02:03:32 +0000
════════════════════════
Tags: #Malware #adware #Device Metadata #Group Policy #LG #Microsoft Store #windows
Title: Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
Title: Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing