Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: CVE-2025-59789: Critical Flaw in Apache bRPC Framework Exposes High-Performance Systems to Crash Risks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 01 Dec 2025 04:25:59 +0000
════════════════════════
Tags: #Vulnerability Report #Apache bRPC #cybersecurity #Denial of Service #JSON Parsing #Open Source Security #Vulnerability
Title: JWT Authentication Bypass via JWK Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Wed, 03 Dec 2025 03:40:35 GMT
════════════════════════
Tags: #json_web_token #jwt_exploitation #jwt_authentication_bypass #jwk_header_injection #bug_bounty
Title: JWT Authentication Bypass via jku Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Wed, 03 Dec 2025 08:51:54 GMT
════════════════════════
Tags: #jwt_authentication_bypass #jku_header_injection #json_web_token #jwks_manipulation #bug_bounty
Title: Deserialization for Hackers: How Server Logic Gets Hijacked
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
Tags: #bug_bounty #json #bug_bounty_tips #hacking
Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
Tags: #bug_bounty #json #bug_bounty_tips #hacking
Title: Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the “End-of-Life” Security Gap
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026