Daily Writeups
3.57K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
Title: Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
Title: Budibase Patches Critical RCE and SSRF Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
Title: The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
Title: The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
Title: Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
Title: Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Title: Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
Title: How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
Title: From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for…
════════════════════════
𐀪 Author: eL Njas!
════════════════════════
Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
Tags: #vulnhunter #open_source #infosec #open_source_security #finance
Title: Amazon Links North Korean Hackers to NPM Supply Chain Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 04 Aug 2026 08:01:39 +0000
════════════════════════
Tags: #Cybercriminals #Amazon Threat Intelligence #DPRK #North Korea #npm #Open Source Security #Sapphire Sleet #supply chain attack