Daily Writeups
3.55K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: The “Fifty Command” Limit: How a Single Line of Code Paralyses Anthropic’s Claude Code Security
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 03 Apr 2026 07:57:29 +0000
════════════════════════
Tags: #Vulnerability #Adversa #AI Vulnerability #Anthropic #Bash Exploitation #CI/CD Security #Claude Code #Cybersecurity 2026 #Infosec #LLM Security #Prompt Injection
Title: The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 03 Apr 2026 09:40:11 +0000
════════════════════════
Tags: #Data Leak #API Key Theft #aws security #CERT_EU #CI/CD security #data leak #EU Security #European Commission #infosec #ShinyHunters #supply chain attack #TeamPCP #Trivy
Title: Shadow Nodes: Deciphering the Rise of Ashab al-Yamin in the European Cyber Landscape
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 21 Apr 2026 09:14:15 +0000
════════════════════════
Tags: #Cybercriminals #Ashab al_Yamin #BreachForums #ChaCha20_Poly1305 #CI/CD Security #Cyber Propaganda #Cybercrime 2026 #Double Extortion #European Security #Geopolitical Threats #Harakat Ashab al_Yamin al_Islamia #Information Warfare #Iranian Proxy #LiteLLM #RaaS #Sabereen News #supply chain attack #TeamPCP #Tech Against Terrorism #Telegram Security #Trivy #Vect Ransomware
Title: The Assembly Line of Extortion: How Vect and TeamPCP Weaponized the Global Software Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 21 Apr 2026 09:11:14 +0000
════════════════════════
Tags: #Cybercriminals #BreachForums #ChaCha20_Poly1305 #CI/CD Security #Cybercrime 2026 #Double Extortion #LiteLLM #RaaS #supply chain attack #TeamPCP #Trivy #Vect Ransomware
Title: Critical RCE Alert: Bamboo Data Center Vulnerable to OS Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 22 Apr 2026 02:51:01 +0000
════════════════════════
Tags: #Vulnerability Report #Atlassian #Bamboo #CI/CD security #CVE_2026_21571 #DevOps #infosec #os command injection #Patch Alert #rce #Supply Chain
Title: High-Severity PHPUnit Vulnerability Enables Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 22 Apr 2026 13:45:16 +0000
════════════════════════
Tags: #Vulnerability Report #Automation Security #CI/CD security #CVE_2026_41570 #DevSecOps #infosec #Patch Alert #PHP Security #PHPUnit #Poisoned Pipeline #rce
Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
Title: The “Mini Shai-Hulud” Attack Hijacking SAP Developer Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 29 Apr 2026 15:04:51 +0000
════════════════════════
Tags: #Malware #@cap_js/sqlite #aws security #Azure #Bun runtime #CI/CD security #credential stealer #infosec #Kubernetes #mbt #Mini Shai_Hulud #npm malware #SAP #supply chain attack
Title: High-Severity RCE and XSS Flaws Found in Popular CI/CD Jenkins Plugins
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 30 Apr 2026 02:10:43 +0000
════════════════════════
Tags: #Vulnerability Report #CI/CD security #CVE_2026_42520 #CVE_2026_42523 #cybersecurity #DevSecOps #infosec #Jenkins #Patch Alert #plugin security #rce #Vulnerability Research #XSS