⤷ Title: QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
Daily CyberSecurity
QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
QNAP has patched a critical improper authentication flaw (CVE-2025-52856) in its QVR firmware with a CVSS score of 9.3, allowing remote attackers to bypass security.
⤷ Title: API9:2023 — Improper Inventory Management
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 07:38:11 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #apifort #owasp_api_security_top_10 #improper_inventory
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 07:38:11 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #apifort #owasp_api_security_top_10 #improper_inventory
Medium
🔍 API9:2023 — Improper Inventory Management
API Güvenliğinde Envanter Yönetiminin Kritik Rolü
⤷ Title: GitLab Patches High Runner Hijacking Flaw (CVE-2025-11702) and Multiple DoS Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 09:20:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2025_11702 #dos #gitlab #Improper Access Control #Runner Hijacking #security patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 09:20:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2025_11702 #dos #gitlab #Improper Access Control #Runner Hijacking #security patch
Daily CyberSecurity
GitLab Patches High Runner Hijacking Flaw (CVE-2025-11702) and Multiple DoS Vulnerabilities
GitLab patched a critical runner hijacking flaw (CVE-2025-11702) allowing authenticated users to compromise CI/CD pipelines, plus three unauthenticated DoS vulnerabilities.
⤷ Title: Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
Daily CyberSecurity
Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
Elastic patched a Critical EoP flaw (CVE-2025-37736) in ECE (v3.8.3/4.0.3) where the readonly user can create admin users and inject new API keys by bypassing authorization checks.
⤷ Title: Critical Dell Data Lakehouse Vulnerability (CVE-2025-46608) Allows Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:47:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_46608 #Dell Data Lakehouse #Improper Access Control #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:47:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_46608 #Dell Data Lakehouse #Improper Access Control #privilege escalation
Daily CyberSecurity
Critical Dell Data Lakehouse Vulnerability (CVE-2025-46608) Allows Privilege Escalation
Dell patched a Critical (CVSS 9.1) flaw (CVE-2025-46608) in Dell Data Lakehouse that allows a high-privileged remote attacker to escalate privileges and gain unauthorized administrative control. Update to v1.6.0.0.
⤷ Title: 2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
Medium
2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
Hello Hackers 👋
⤷ Title: Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 01:35:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35616 #Enterprise Security #exploited in the wild #FortiClient EMS #Fortinet #Hotfix #Improper Access Control #infosec #rce #security patch #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 01:35:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35616 #Enterprise Security #exploited in the wild #FortiClient EMS #Fortinet #Hotfix #Improper Access Control #infosec #rce #security patch #zero_day
Daily CyberSecurity
Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
Security teams are on high alert as Fortinet confirms that a critical vulnerability in its FortiClient EMS (Endpoint Management Server) is currently being leveraged by attackers in active campaign…
⤷ Title: Bug Bounty Journey — Valid Report Part 11
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:58:02 GMT
════════════════════════
⌗ Tags: #web_application_security #bug_bounty #improper_access_control #intigriti
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:58:02 GMT
════════════════════════
⌗ Tags: #web_application_security #bug_bounty #improper_access_control #intigriti
Medium
Bug Bounty Journey — Valid Report Part 11
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities. 😊…
⤷ Title: How a Throwaway Email Walked Me Into Someone Else’s Tenant — Unauthorized PII Information Access
════════════════════════
𐀪 Author: Thamotharan Vajramani
════════════════════════
ⴵ Time: Wed, 20 May 2026 16:41:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
════════════════════════
𐀪 Author: Thamotharan Vajramani
════════════════════════
ⴵ Time: Wed, 20 May 2026 16:41:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
Medium
How a Throwaway Email Walked Me Into Someone Else’s Tenant — Unauthorized PII Information Access
By Thamotharan Vajramani
⤷ Title: Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 13:30:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_58319 #database security #improper authentication #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 13:30:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_58319 #database security #improper authentication #Vulnerability
Daily CyberSecurity
Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
TL;DR The Apache Doris project has patched a critical Apache Doris vulnerability, tracked as CVE-2026-58319. Some Frontend (FE) HTTP REST admin APIs were reachable without authentication. As a res…