Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
Title: The Shittrix Disclosure: 89 Flaws Collapse 20 Years of Trust in Citrix and XCP-ng
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 29 Apr 2026 13:04:55 +0000
════════════════════════
Tags: #Vulnerability Report #API security #Bootkit #Citrix #Cloud Security #CVSS 9.9 #Hypervisor #infosec #Jakob Wolffhechel #Shittrix #Storage Security #Virtualization Security #XCP_ng #XenServer
Title: 40,000+ Sites Exposed: Critical 9.8 CVSS Flaw Grants Total WordPress Account Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 09:17:45 +0000
════════════════════════
Tags: #Vulnerability Report #Account Takeover #Authentication Bypass #CVE_2026_7567 #CVSS 9.8 #infosec #PHP Logic Bypass #Plugin Vulnerability #Temporary Login #wordpress #wordpress security
Title: 44,000 IPs Hijacked: cPanel’s 9.8 CVSS Authentication Bypass Triggers Global Ransomware Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 02:04:53 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #CISA KEV #CPanel #CVE_2026_41940 #CVSS 9.8 #cybersecurity #infosec #Mirai botnet #ransomware #Server Security #WebPros #WHM
Title: The CVE Watchtower: Weekly Threat Intelligence Briefing (April 27 – May 3, 2026)
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 04 May 2026 01:57:05 +0000
════════════════════════
Tags: #Weekly Recap #CISA KEV #CPanel #CVE_2026_41940 #CVSS 10 #cybersecurity #Express.js #infosec #patch management #Vulnerability Digest #WHM
Title: Sentry’s 9.1 CVSS SSO Flaw Lets Attackers “Link” Their Way Into Your Account
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 04 May 2026 12:45:03 +0000
════════════════════════
Tags: #Vulnerability Report #2FA #Account Takeover #CVE_2026_42354 #CVSS 9.1 #cybersecurity #Identity Linking #infosec #SAML SSO #Self_Hosted Sentry #sentry #SSO Bypass
Title: CVE-2026-29200: A 9.9 CVSS Comet Backup Flaw Granting Total Cross-Tenant Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 04 May 2026 09:05:44 +0000
════════════════════════
Tags: #Vulnerability Report #Account Takeover #API security #cloud backup #Comet Backup #Cross_Tenant Takeover #CVE_2026_29200 #CVSS 9.9 #cybersecurity #IDOR #infosec #Patch Alert
Title: Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 05 May 2026 01:00:34 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_40281 #CVSS 10 #Docker Security #ExifTool #Gotenberg #infosec #Patch Alert #PDF API #rce #SSRF Bypass #Web Security
Title: 5.7 Million Users at Risk: Multiple 9.8 CVSS Breakthroughs Enable Remote Code Execution in vm2 Sandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 01:33:32 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_26956 #CVSS 9.8 #infosec #JavaScript Security #Node.js #Patch Alert #rce #Sandbox Escape #V8 Engine #vm2 #WebAssembly