Daily Writeups
3.53K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
πŸ”–New Writeup❗️
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ—“Date: Mon, 03 Apr 2023 15:32:19 GMT
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
✏️Title: Are open-source NPM packages always secure to use?
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ“ŽLink: https://medium.com/p/215e9d3902be
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Tags: #npm #nodejs #dependency_management #security
πŸ”–New Writeup❗️
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ—“Date: Mon, 17 Apr 2023 15:02:15 GMT
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
✏️Title: Flawed choices: Developers continue to use vulnerable open-source dependencies
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ“ŽLink: https://medium.com/p/b12092fb9abd
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Tags: #application_security #cybersecurity #dependency_management #open_source #software_development
πŸ”–New Writeup❗️
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ—“Date: Wed, 27 Sep 2023 10:35:21 GMT
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
✏️Title: Find Vulnerable Dependencies using OWASP Dependency Check
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ“ŽLink: https://medium.com/p/f3c130af6078
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Tags: #java #owasp #vulnerability #maven_plugin #dependency_check
β€· Title: AWS Lambda Layers Simplified: A Beginner’s Guide
════════════════════════
π€ͺ Author: Thushara Samaraweera
════════════════════════
β΄΅ Time: Thu, 26 Dec 2024 06:37:35 GMT
════════════════════════
βŒ— Tags: #aws_lambda_layer #aws_lambda #reusable #dependency_management
β€· Title: Dependency Confusion: A Threat Actor in the Modern Software Ecosystem
════════════════════════
π€ͺ Author: Batuhan Sancak
════════════════════════
β΄΅ Time: Thu, 10 Apr 2025 05:28:51 GMT
════════════════════════
βŒ— Tags: #dependency_injection #cybersecurity #appsec #software_development #security
β€· Title: Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Mon, 14 Apr 2025 00:16:26 +0000
════════════════════════
βŒ— Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
β€· Title: How I Discovered a Live Dependency Confusion Vulnerability in a GraphQL-Based Web Application
════════════════════════
π€ͺ Author: Sanaullah Aman Korai
════════════════════════
β΄΅ Time: Sat, 05 Jul 2025 17:38:20 GMT
════════════════════════
βŒ— Tags: #ethical_hacking #dependency_confusion #supply_chain_security #bug_bounty #cybersecurity
β€· Title: The Hidden Threat in Your Code: How Malicious PyPI and npm Packages Are Weaponizing Developer Trust…
════════════════════════
π€ͺ Author: Ismail Tasdelen
════════════════════════
β΄΅ Time: Mon, 18 Aug 2025 15:46:03 GMT
════════════════════════
βŒ— Tags: #dependency_injection #code #application_security #cybersecurity #supply_chain_security
β€· Title: Ketorolac Injection Market Growth in 2025–2034: Dynamics, Opportunities, and Strategies
════════════════════════
π€ͺ Author: Prajval Jadhav
════════════════════════
β΄΅ Time: Wed, 03 Sep 2025 05:45:58 GMT
════════════════════════
βŒ— Tags: #dependency_injection #ketorolac #ketorolac_injection #injection #sql_injection
β€· Title: Turning Dependency Confusion Research into a Profitable Stack
════════════════════════
π€ͺ Author: Abdelrhman Allam (sl4x0)
════════════════════════
β΄΅ Time: Wed, 08 Oct 2025 15:23:43 GMT
════════════════════════
βŒ— Tags: #infosec #dependency_confusion #cybersecurity #bug_bounty #supply_chain
β€· Title: Hunting Dependency Confusion: Supply Chain Vulnerabilities for Bug Bounties
════════════════════════
π€ͺ Author: Aman Bhuiyan
════════════════════════
β΄΅ Time: Sat, 11 Oct 2025 19:11:46 GMT
════════════════════════
βŒ— Tags: #bug_hunting #dependency_injection #hacking #bug_bounty
β€· Title: So, β€œShift-Left” Failed. What Comes Next?
════════════════════════
π€ͺ Author: Ali Naqvi
════════════════════════
β΄΅ Time: Wed, 07 Jan 2026 15:40:44 GMT
════════════════════════
βŒ— Tags: #dependency_management #application_security #devtools #software_development #shiftleft
β€· Title: Finding Remote Code Execution in Google: A Bug Hunter’s Story
════════════════════════
π€ͺ Author: zabit majeed
════════════════════════
β΄΅ Time: Sun, 11 Jan 2026 17:49:36 GMT
════════════════════════
βŒ— Tags: #cve #google #bug_bounty #dependency_injection #hacking
β€· Title: How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
════════════════════════
π€ͺ Author: Ahmed Tarek
════════════════════════
β΄΅ Time: Sat, 17 Jan 2026 19:06:39 GMT
════════════════════════
βŒ— Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby