Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: API Security: Minimum Things Every Team Should Implement Before Going Live
════════════════════════
𐀪 Author: Umashankara Kalaiah
════════════════════════
Time: Mon, 20 Apr 2026 03:21:57 GMT
════════════════════════
Tags: #cybersecurity #owasp_top_10 #authentication #authorization #api_security
Title: 7 Critical Vulnerabilities Threaten Spring Security 7.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 22 Apr 2026 01:54:49 +0000
════════════════════════
Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_22752 #infosec #Java security #JWT Security #Patch Alert #Spring Security #Spring Security 7.0 #ssrf #TOCTOU #X.509 Impersonation
Title: Critical 9.0 CVSS Flaw in ArcadeDB Allows Total Cross-Database Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 02:17:05 +0000
════════════════════════
Tags: #Vulnerability Report #ArcadeDB #Authorization Bypass #CVE_2026_44221 #cybersecurity #Data Isolation #database security #infosec #Multi_Model DBMS #Multi_tenancy #Patch Alert
Title: Critical 9.4 CVSS pgAdmin 4 Flaws Enable Full OS Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 15 May 2026 01:20:16 +0000
════════════════════════
Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_7813 #Cyber Security #database security #infosec #Patch Alert #pgAdmin 4 #pgAdmin 9.15 #PostgreSQL #rce #sql injection
Title: What is BOLA? API Broken Object Level Authorization Explained for Beginners
════════════════════════
𐀪 Author: Abrar Bin Habib
════════════════════════
Time: Fri, 15 May 2026 17:36:40 GMT
════════════════════════
Tags: #owasp_api_top_10 #api_vulnerabilities #authorization #bola #api_security
Title: Login Sistemində Təhlükəsizlik: Auth Modulunda Görülən AppSec Tədbirlərinin bir hissəsi
════════════════════════
𐀪 Author: Kanan Kazimov
════════════════════════
Time: Sat, 16 May 2026 08:10:02 GMT
════════════════════════
Tags: #application_security #authorization #web_security #authentication #cybersecurity
Title: Preventing Reserved Scope Name Misuse in API Platforms
════════════════════════
𐀪 Author: Wishula Jayathunga
════════════════════════
Time: Mon, 18 May 2026 02:57:43 GMT
════════════════════════
Tags: #api_security #backend_governance #scope_validation #enterprise_api_management #authorization_design
Title: Keys to the Kingdom: Critical 9.9 CVSS Budibase Flaw Allows Total Tenant Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 20 May 2026 01:40:37 +0000
════════════════════════
Tags: #Vulnerability Report #Account Takeover #Authorization Bypass #Budibase #CVE_2026_46425 #Cyber Security #DevSecOps #Identity Management #infosec #Patch Alert #privilege escalation #SCIM
Title: New Apache Camel K Flaw (CVE-2026-45760) Enables Cross-Namespace Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 22 May 2026 03:12:15 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Camel K #Authorization Bypass #Build Deputy Attack #Cloud Native Security #CVE_2026_45760 #Cyber Security #infosec #Kubernetes Namespace Bypass #Multi_Tenancy Defect #Patch Alert #Pod Generation Hijack
Title: HTTP 401 vs 403 vs 404 vs 405 — And Advanced Techniques to Bypass Unauthorized Pages
════════════════════════
𐀪 Author: Gehad Reda
════════════════════════
Time: Mon, 01 Jun 2026 11:44:43 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty #penetration_testing #authorization #bypass
Title: AI Agents Calling Your APIs? Here’s How to Secure Them
════════════════════════
𐀪 Author: Curity
════════════════════════
Time: Thu, 11 Jun 2026 10:24:20 GMT
════════════════════════
Tags: #ai_agent #authorization #oauth #api_security #ai_agent_security
Title: How to Build a Role-Based Access Control (RBAC) System
════════════════════════
𐀪 Author: Ushani Saubhagya
════════════════════════
Time: Sat, 13 Jun 2026 11:53:32 GMT
════════════════════════
Tags: #authentication #authorization #role_based_access_control #software_security #application_security
Title: Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 22 Jun 2026 01:11:11 +0000
════════════════════════
Tags: #Vulnerability Report #admin panel #Authorization Bypass #Avo #CVE_2026_55518 #Missing Authorization #privilege escalation #Rails Security #ruby on rails
Title: 5 Authorization Mistakes I Keep Finding During Manual Application Security Testing
════════════════════════
𐀪 Author: Mohammed Khaleel ul hasan
════════════════════════
Time: Tue, 30 Jun 2026 09:18:23 GMT
════════════════════════
Tags: #security #web_application_security #application_security #authorization #pentesting
Title: API Authorization Testing: Insecure Object-Level Access Leading to Unauthorized User Management
════════════════════════
𐀪 Author: Ethical Hacker
════════════════════════
Time: Mon, 06 Jul 2026 14:55:37 GMT
════════════════════════
Tags: #api_security #rbac_access_control #authorization #cyber_security_solutions #bug_bounty
Title: Authorization at Scale:
Policy, Resource, and Tenant Boundaries in ASP.NET Core (.NET 9 Guide P3)

════════════════════════
𐀪 Author: Oleksii Sokol
════════════════════════
Time: Fri, 10 Jul 2026 11:01:25 GMT
════════════════════════
Tags: #authorization #api_security #dotnet #software_architecture #aspnetcore
Title: Authorization Bypass via Privilege Persistence After Role Downgrade in Hasura PromptQL
════════════════════════
𐀪 Author: Ahmed Embaby
════════════════════════
Time: Sat, 18 Jul 2026 15:12:35 GMT
════════════════════════
Tags: #web_security #authorization #bug_bounty #cybersecurity #graphql
1
Title: The Bug Bounty Playbook: IDOR
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
Time: Mon, 20 Jul 2026 22:27:44 GMT
════════════════════════
Tags: #bug_bounty #web_security #idor #authorization #hackerone
Title: Unpatched Plane Authorization Bypass CVE-2026-15342 Exposes Other Workspaces
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 27 Jul 2026 13:03:32 +0000
════════════════════════
Tags: #Vulnerability Report #Authorization Bypass #broken access control #CERT/CC #CVE_2026_15342 #Multi_Tenant #open_source #Plane #Project Management #unpatched #VU#762226
Title: Apache ActiveMQ Patches Authorization Bypass and DoS Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 28 Jul 2026 02:05:15 +0000
════════════════════════
Tags: #Vulnerability Report #ActiveMQ vulnerability #Apache ActiveMQ #Authorization Bypass #CVE_2026_59878 #CVE_2026_61487 #Denial of Service #Message Broker Security