Daily Writeups
3.55K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Account Takeover Attacks: The Most Popular Sport in Cybercrime
════════════════════════
𐀪 Author: Wes Young
════════════════════════
Time: Tue, 11 Feb 2025 14:28:15 GMT
════════════════════════
Tags: #phishing #threat_intelligence #ato #cybersecurity #alpha_hunt
Title: Day 16: Massive Users Account Takeovers (Chaining Vulnerabilities to IDOR)
════════════════════════
𐀪 Author: dani3l
════════════════════════
Time: Fri, 21 Feb 2025 16:52:41 GMT
════════════════════════
Tags: #ethical_hacking #pen_testing_tool #bug_bounty #ato
Title: Day 17: [$5K] Misconfigured Reset Password Leads to Account Takeover (No User Interaction ATO)
════════════════════════
𐀪 Author: dani3l
════════════════════════
Time: Sat, 22 Feb 2025 18:06:02 GMT
════════════════════════
Tags: #account_takeover #ato #bug_bounty
Title: Day 18: How a Researcher Hacked One of the Biggest Airlines Group in the World
════════════════════════
𐀪 Author: dani3l
════════════════════════
Time: Sun, 23 Feb 2025 17:39:05 GMT
════════════════════════
Tags: #ethical_hacking #account_takeover #ato #bug_bounty
Title: Legacy SDK Flaws Cause Stored XSS and Account Takeover (ATO)
════════════════════════
𐀪 Author: MindPatch
════════════════════════
Time: Fri, 14 Mar 2025 00:54:48 GMT
════════════════════════
Tags: #bugbounty_writeup #pentesting #ato #xss_attack
Title: The story of XSS that leads to ATO
════════════════════════
𐀪 Author: SahandAmi
════════════════════════
Time: Mon, 24 Mar 2025 10:59:09 GMT
════════════════════════
Tags: #ato #account_takeover #csrf_token #bug_bounty #xs
Title: Day 29 — CSRF Bypass Using Domain Confusion Leads To Account Takeover (ATO)
════════════════════════
𐀪 Author: dani3l
════════════════════════
Time: Sat, 05 Apr 2025 09:48:00 GMT
════════════════════════
Tags: #bug_bounty #ato #account_takeover #cybersecurity
Title: Bug Bounty | Istifadəçi hesablarının oğurlanmasına səbəb ola biləcək bir boşluq tapdım (Account…
════════════════════════
𐀪 Author: Zeynalxan Quliyev
════════════════════════
Time: Mon, 14 Apr 2025 12:04:41 GMT
════════════════════════
Tags: #bug_bounty_writeup #bug_bounty #ato #account_takeover #hacker
Title: Sensitive Data Exposure + Public Recon = Instant Account Takeover
════════════════════════
𐀪 Author: Aya Ayman(GERR4Y)
════════════════════════
Time: Tue, 22 Apr 2025 16:20:58 GMT
════════════════════════
Tags: #bug_bounty #ato #osint
Title: TeamFiltration Weaponized: UNK_SneakyStrike Campaign Targets 80,000+ Microsoft Entra ID Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 13 Jun 2025 00:30:01 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #ATO #AWS #cyberattack #cybersecurity #Microsoft 365 #Microsoft Entra ID #OAuth #Password Spraying #Proofpoint #TeamFiltration
Title: CVE-2025–56676 | Critical Vulnerability in Zender Gateway Allows Account Takeover
════════════════════════
𐀪 Author: DarkLotus
════════════════════════
Time: Sat, 27 Sep 2025 03:42:36 GMT
════════════════════════
Tags: #bug_bounty #cve #cwe_639 #ato #cve_2025
Title: Account Takeover: What Is It and How to Fight It
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
Time: Thu, 06 Nov 2025 23:02:20 +0000
════════════════════════
Tags: #Security #Account Takeover #ATO #Cybersecurity
Title: 8 Recommended Account Takeover Security Providers
════════════════════════
𐀪 Author: Uzair Amir
════════════════════════
Time: Tue, 11 Nov 2025 23:33:53 +0000
════════════════════════
Tags: #Security #Account Takeover #ATO #Cybersecurity #Privacy
Title: Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 24 Dec 2025 01:47:08 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #ATO #Bing Ads #DOJ #fbi #Financial Crime #Google Ads #Malvertising #Northern District of Georgia #Search Engine Fraud #web3adspanels.org
Title: Escalating a Duplicate Finding to a CVSS 10.0: Chaining Logic and Session Flaws for Persistent ATO
════════════════════════
𐀪 Author: K4r33m
════════════════════════
Time: Mon, 23 Feb 2026 02:27:02 GMT
════════════════════════
Tags: #session_misconfiguration #ato #bug_bounty #account_takeover #rate_limiting
Title: Full Organization Account Takeover (ATO) by Changing One Parameter
════════════════════════
𐀪 Author: Mohamed Fares
════════════════════════
Time: Mon, 23 Feb 2026 03:48:12 GMT
════════════════════════
Tags: #ato #bug_bounty #bug_bounty_tips #hackerone #bug_bounty_writeup
Title: Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 27 Feb 2026 03:50:52 +0000
════════════════════════
Tags: #Vulnerability Report #Account Takeover #ATO #Cloud Security #CVE_2026_27822 #infosec #Object Storage #Patch Alert #Rust Programming #RustFS #S3 Storage #Stored XSS
Title: Stored xss exposed cookies via .svg in [ cisco] = P3 Bug → P1 bug
════════════════════════
𐀪 Author: Sai Jayanth
════════════════════════
Time: Sun, 01 Mar 2026 07:30:37 GMT
════════════════════════
Tags: #stored_xss #bug_bounty #cybersecurity #ato #cisco
Title: The Fall of a Phishing Giant: How International Law Enforcement Crushed the Tycoon 2FA Empire
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 06 Mar 2026 07:25:19 +0000
════════════════════════
Tags: #Cybercriminals #ATO Jumping #cybercrime takedown #Europol #MFA Bypass #Microsoft 365 security #Phishing_as_a_Service #Saad Afridi #Session Hijacking #Storm_1747 #Tech News 2026 #Tycoon 2FA
Title: Attackers Weaponize Mailbox Rules to Control Your Inbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 15 Apr 2026 09:01:24 +0000
════════════════════════
Tags: #Cybercriminals #Account Takeover #ATO #ATOLS #Cloud Security #data exfiltration #Email Security #infosec #Mailbox Rules #Microsoft 365 #persistence #Proofpoint