Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
πŸ”–New Writeup❗️
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ—“Date: Thu, 13 Jul 2023 13:58:46 GMT
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
✏️Title: The Hidden Risks of Package Management Systems: Shedding Light on the Dependency Confusion…
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ“ŽLink: https://medium.com/p/18bae0f14532
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Tags: #hacking #red_team_security #package_management #bug_bounty #infosec
πŸ”–New Writeup❗️
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ—“Date: Sun, 23 Jul 2023 22:57:32 GMT
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
✏️Title: Linux Debian Package Manager β€œdpkg”
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
πŸ“ŽLink: https://medium.com/p/3ae978e0b0c9
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Tags: #debian #linux #hacking #package_manager #kali_linux
β€· Title: Easiest way to Find RCE (Package Dependency)
════════════════════════
π€ͺ Author: JEETPAL
════════════════════════
β΄΅ Time: Fri, 28 Feb 2025 03:56:24 GMT
════════════════════════
βŒ— Tags: #package_dependency #cybersecurity #bug_bounty #rce #bug_bounty_writeup
β€· Title: Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Mon, 14 Apr 2025 00:16:26 +0000
════════════════════════
βŒ— Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
β€· Title: Malicious npm Packages Backdoor Telegram Bot Developers
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Tue, 22 Apr 2025 00:12:46 +0000
════════════════════════
βŒ— Tags: #Malware #cybersecurity #malware #Node.js #npm #package security #Software security #ssh backdoor #supply chain attack #Telegram Bots
β€· Title: dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Thu, 03 Jul 2025 00:22:25 +0000
════════════════════════
βŒ— Tags: #Vulnerability #cybersecurity #Debian #Denial of Service #Disk Quota #dos #dpkg_deb #Linux #Package Management #Temporary Files
β€· Title: How to Fix the β€œNO_PUBKEY” Error in Kali Linux
════════════════════════
π€ͺ Author: Uzoukwu Eric Ikenna
════════════════════════
β΄΅ Time: Thu, 10 Jul 2025 01:57:20 GMT
════════════════════════
βŒ— Tags: #package_management #gpg_key #linux #cybersecurity #linux_troubleshooting
β€· Title: Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Fri, 11 Jul 2025 00:00:15 +0000
════════════════════════
βŒ— Tags: #Vulnerability Report #Chart.lock #Chart.yaml #CVE_2025_53547 #cybersecurity #Kubernetes #LCE #Local Code Execution #Package manager #Symlinks #Vulnerability
β€· Title: PyPI Bans Inbox.ru After Massive Spam Campaign and 1,500+ Fake Project Uploads
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Thu, 17 Jul 2025 01:40:07 +0000
════════════════════════
βŒ— Tags: #Cybercriminals #cybersecurity #inbox.ru #open_source #Package Impersonation #PyPI #Python Package Index #Slopsquatting #Spam #Supply Chain Security
β€· Title: How to Migrate Your Vite + React + TypeScript Project from npm to Yarn (The Clean Way)
════════════════════════
π€ͺ Author: AIAlchemist_Ab1r
════════════════════════
β΄΅ Time: Fri, 12 Sep 2025 08:39:14 GMT
════════════════════════
βŒ— Tags: #seo #software_development #package_management #webdev #hacking
β€· Title: Typosquatting in Package Managers: The Attack That Preys on a Single Keystroke
════════════════════════
π€ͺ Author: InstaTunnel
════════════════════════
β΄΅ Time: Sun, 21 Sep 2025 07:55:34 GMT
════════════════════════
βŒ— Tags: #malicious_package #typosquatting #package_manager #cybersecurity #supply_chain_attack
β€· Title: 373 Malicious Packages a Day: Why Software Supply Chain Compromise Is Inevitable
════════════════════════
π€ͺ Author: Peter Hanneman
════════════════════════
β΄΅ Time: Tue, 21 Oct 2025 23:39:55 GMT
════════════════════════
βŒ— Tags: #software_development #cyber_security_awareness #package_manager #web_development #cybersecurity
β€· Title: Alpine Linux 3.23 Released: Adopts 6.18 LTS Kernel & Unveils APK 3.0 Package Manager
════════════════════════
π€ͺ Author: ddos
════════════════════════
β΄΅ Time: Mon, 08 Dec 2025 04:31:10 +0000
════════════════════════
βŒ— Tags: #Linux #Alpine Linux #APK 3.0.0 #Containers #Linux 3.23 #Linux 6.18 #LTS Kernel #Minimalist OS #musl libc #Package Manager
β€· Title: The Trojan Coding Assistant: How a Compromised Token Pushed a Shadow Release of Cline
════════════════════════
π€ͺ Author: ddos
════════════════════════
β΄΅ Time: Mon, 23 Feb 2026 03:15:17 +0000
════════════════════════
βŒ— Tags: #Malware #Cline CLI #GitHub Actions #npm security #OIDC #OpenClaw #package.json #software provenance #supply chain attack #Tech News 2026 #web shells
β€· Title: Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Fri, 27 Feb 2026 04:25:06 +0000
════════════════════════
βŒ— Tags: #Cybercriminals #.NET Security #Financial Cybercrime #infosec #malware #NuGet #Package Impersonation #ReversingLabs #Stripe.net #supply chain attack #Typosquatting
β€· Title: Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Fri, 10 Apr 2026 13:03:02 +0000
════════════════════════
βŒ— Tags: #Vulnerability Report #CVE_2026_39860 #infosec #Linux Security #Nix #NixOS #Package Management #privilege escalation #root access #Sandbox Escape
β€· Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
π€ͺ Author: ddos
════════════════════════
β΄΅ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
βŒ— Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
β€· Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
π€ͺ Author: Ddos
════════════════════════
β΄΅ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
βŒ— Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack