Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: AI Interface Hijacked: Open WebUI Exploited for Cryptominers and Stealthy AI Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 04 Jun 2025 00:19:06 +0000
════════════════════════
Tags: #Cybercriminals #Malware #AI #cryptomining #cybersecurity #Infostealer #LLM #malware #Open WebUI #Software Supply Chain #Sysdig #threat research
Title: Next-Gen Malware: EtherRAT Uses Ethereum Smart Contract for Stealth C2
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sat, 13 Dec 2025 10:38:12 +0000
════════════════════════
Tags: #Malware #Vulnerability #C2 #CVE_2025_55182 #cybersecurity #Ethereum #EtherRAT #Node.js #React2Shell #Remote Access Trojan #Smart Contract #Sysdig
Title: Exposed AWS Credentials Lead to AI-Assisted Cloud Breach in 8 Minutes
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Wed, 04 Feb 2026 10:31:10 +0000
════════════════════════
Tags: #Security #Cyber Attacks #AI #AWS #Cloud security #Cyber Attack #Cybersecurity #security #Sysdig #Vulnerability
Title: The 8-Minute Admin: How AI-Powered “LLMjacking” Crushed AWS Defenses in Record Time
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 09 Feb 2026 03:47:06 +0000
════════════════════════
Tags: #Cybercriminals #AI_assisted attack #Amazon Bedrock #AWS security #cloud breach 2026 #cybersecurity news #GPU resource abuse #IAM privilege escalation #LLMjacking #S3 bucket misconfiguration #Sysdig report
Title: Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Title: Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
Title: PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
Title: SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 18 May 2026 08:06:31 +0000
════════════════════════
Tags: #Cybercriminals #AI Pipeline Security #CISA KEV #container escape #CVE_2026_33017 #Distributed Messaging #infosec #Langflow #NATS_as_C2 #Patch Alert #Remote Code Execution #Sysdig TRT
Title: NATS-as-C2: Critical Langflow Exploit Exploded to Fuel “LLMjacking” and Cloud Credential Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting