⤷ Title: CVE-2025-59789: Critical Flaw in Apache bRPC Framework Exposes High-Performance Systems to Crash Risks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 04:25:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache bRPC #cybersecurity #Denial of Service #JSON Parsing #Open Source Security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 04:25:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache bRPC #cybersecurity #Denial of Service #JSON Parsing #Open Source Security #Vulnerability
Daily CyberSecurity
CVE-2025-59789: Critical Flaw in Apache bRPC Framework Exposes High-Performance Systems to Crash Risks
A critical vulnerability in Apache bRPC (CVE-2025-59789) allows attackers to crash servers using deep JSON data. Upgrade to version 1.15.0 now to fix it.
⤷ Title: JWT Authentication Bypass via JWK Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 03:40:35 GMT
════════════════════════
⌗ Tags: #json_web_token #jwt_exploitation #jwt_authentication_bypass #jwk_header_injection #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 03:40:35 GMT
════════════════════════
⌗ Tags: #json_web_token #jwt_exploitation #jwt_authentication_bypass #jwk_header_injection #bug_bounty
Medium
JWT Authentication Bypass via JWK Header Injection
A detailed look at how insecure JWK handling leads to full authentication compromise.
⤷ Title: JWT Authentication Bypass via jku Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:51:54 GMT
════════════════════════
⌗ Tags: #jwt_authentication_bypass #jku_header_injection #json_web_token #jwks_manipulation #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:51:54 GMT
════════════════════════
⌗ Tags: #jwt_authentication_bypass #jku_header_injection #json_web_token #jwks_manipulation #bug_bounty
Medium
JWT Authentication Bypass via jku Header Injection
Inside the JWT Misconfiguration That Lets Attackers Become Admins with a Single Header Injection
⤷ Title: Deserialization for Hackers: How Server Logic Gets Hijacked
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
Medium
Deserialization for Hackers: How Server Logic Gets Hijacked
Hello everyone! Have you ever sent a JSON object to a server and thought, “It’s just data”?
Most of us do. We use JSON every day without…
Most of us do. We use JSON every day without…
⤷ Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Daily CyberSecurity
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
Apache NiFi patches a High-severity flaw (CVE-2025-66524) in the GetAsanaObject processor. Unfiltered deserialization risks system compromise. Update now!
⤷ Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Medium
Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
Greetings, fellow cybersecurity enthusiasts and CTF players! In this writeup, we’ll walk through the solution of the “Smart Home” web…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Daily CyberSecurity
HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
A high-severity vulnerability has been discovered in Axios, the immensely popular HTTP client used by millions of developers for Node.js and browser-based applications. The flaw, tracked as CVE-20…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the “End-of-Life” Security Gap
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
Penetration Testing Tools
Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the "End-of-Life" Security Gap
The proliferation of “abandoned” technologies at the periphery of corporate networks has increasingly evolved into an auspicious point