Daily Writeups
3.55K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Sun, 27 Jul 2025 07:01:21 GMT
════════════════════════
Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
Title: Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Mon, 28 Jul 2025 06:03:17 GMT
════════════════════════
Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
Title: Password Reset Poisoning via Dangling Markup
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Mon, 28 Jul 2025 08:16:37 GMT
════════════════════════
Tags: #password_reset_poisoning #host_header_injection #dangling_markup #account_takeover #bug_bounty
Title: Web Cache Poisoning via Ambiguous Requests Lead to XSS
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Tue, 29 Jul 2025 07:53:53 GMT
════════════════════════
Tags: #web_cache_poisoning #bug_bounty #bug_bounty_tips #xss_via_cache_poisoning #host_header_injection
Title: Password Reset Poisoning via Middleware: The Hidden Flaw That Can Lead to Account Takeover
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Wed, 13 Aug 2025 04:17:18 GMT
════════════════════════
Tags: #password_reset_attack #account_takeover #bug_bounty #host_header_injection #password_reset_poisoning
Title: HTTP Host header attacks
════════════════════════
𐀪 Author: Usama Hanif
════════════════════════
Time: Thu, 21 Aug 2025 22:09:23 GMT
════════════════════════
Tags: #ssrf #host_header_injection #portswigger #portswigger_lab #http_host_header_attack
Title: eJPT — 3.1 CTF 2System/Host Based Attacks
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
Time: Sun, 21 Sep 2025 20:53:22 GMT
════════════════════════
Tags: #linux_exploitation #host_based_attack #penetration_testing #infosec #ethical_hacking
Title: Tap-and-Steal: Over 760 Android Apps Exploit NFC/HCE for Payment Card Theft in Global Financial Scam
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 03 Nov 2025 00:32:14 +0000
════════════════════════
Tags: #Cybercriminals #Android NFC #Brazil #financial fraud #Host Card Emulation #Payment Card Theft #russia #Telegram C2
Title: NGate NFC Malware Steals Cash from ATMs by Relaying EMV Data and PINs from Victim’s Phone
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 05 Nov 2025 00:58:26 +0000
════════════════════════
Tags: #Malware #Android Malware #ATM Fraud #Banking Trojan #CERT Polska #EMV Theft #Host Card Emulation #NFC_relay #NGate
Title: Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 10 Dec 2025 00:00:32 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_67494 #host header injection #Identity Management #ssrf #XSS #ZITADEL
Title: The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 09 Jan 2026 00:22:17 +0000
════════════════════════
Tags: #Vulnerability Report #Cache Poisoning #Critical Vulnerability #CVE_2025_12543 #host header injection #Java security #JBoss EAP #Undertow #WildFly
Title: Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 14 Jan 2026 00:06:38 +0000
════════════════════════
Tags: #Vulnerability Report #Account Takeover #API security #Appsmith #CVE_2026_22794 #host header injection #Low Code Platform #Open Source Security #Password Reset Vulnerability
Title: Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 09 Feb 2026 00:46:57 +0000
════════════════════════
Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2026_25520 #CVE_2026_25586 #CVSS 10.0 #Host Prototype Pollution #JavaScript Security #Patch Alert #Sandbox Escape #SandboxJS #Web Security
Title: CVE-2025-62878: Critical 10.0 Vulnerability Found in Kubernetes Local Path Provisioner
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 09 Feb 2026 00:11:07 +0000
════════════════════════
Tags: #Vulnerability Report #container security #CVE_2025_62878 #CVSS 10.0 #Host Escape #K8s #Kubernetes #Local Path Provisioner #Patch Alert #Path Traversal #Rancher
Title: Critical Undertow Flaw (CVSS 9.6) Strikes HPE Telco Service Activator
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 23 Feb 2026 04:20:19 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_12543 #Cyber Security #Host Header Validation #HPE Service Activator #Patch Alert #Session Hijacking #Telecommunications Security #Undertow HTTP Server #Web Cache Poisoning