Daily Writeups
3.49K subscribers
2 photos
128K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 03:06:43 +0000
════════════════════════
Tags: #Vulnerability Report #Apache HTTP Server #CVE_2025_59775 #NTLM Leak #ssrf #suexec Bypass #Windows Security
Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Title: The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 02:21:24 +0000
════════════════════════
Tags: #Vulnerability Report
Title: “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
Title: Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:35:53 +0000
════════════════════════
Tags: #Malware #Adaptix C2 #DUPERUNNER #HR Targets #LNK Exploit #Process injection #russia #spear_phishing
Title: High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:30:10 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_20386 #Incorrect Permissions #privilege escalation #Splunk #Universal Forwarder #Windows Security
Title: High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:22:39 +0000
════════════════════════
Tags: #Vulnerability Report #Cacti #Command Injection #CVE_2025_66399 #network monitoring #rce #security patch #SNMP Community String
Title: Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:19:51 +0000
════════════════════════
Tags: #Cyber Security #AitM Phishing #Calisto #COLDRIVER #Espionage #Reporters Without Borders #RSF #Russian APT #social engineering
Title: NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:11:50 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #CVE_2025_33211 #Denial of Service #dos #Inference Server #MLOps #NVIDIA Triton
Title: AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50%
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 05 Dec 2025 00:03:14 +0000
════════════════════════
Tags: #Technology #AI Sales #Azure #enterprise AI #Microsoft #Microsoft Foundry #Sales Quota #Stock Price #The Information
Title: ️ How I Walked Into LaunchDarkly’s Internal Jira Portal Through a Public Signup Bug
════════════════════════
𐀪 Author: Anshubind
════════════════════════
Time: Fri, 05 Dec 2025 05:25:28 GMT
════════════════════════
Tags: #bug_bounty #ethical_hacking #security_misconfiguration #hackerone #hacking
Title: ️‍♂️ How I Stumbled Into My First Uber Bug: The Unexpected Win That Earned Me $780
════════════════════════
𐀪 Author: Anshubind
════════════════════════
Time: Fri, 05 Dec 2025 05:20:43 GMT
════════════════════════
Tags: #bug_bounty #ethical_hacking #cybersecurity #storytelling #hackerone
Title: Breaking the Web (Part 6): Insecure Direct Object References (IDOR) — When Access Control Fails
════════════════════════
𐀪 Author: Mohammed Fahad
════════════════════════
Time: Fri, 05 Dec 2025 05:17:34 GMT
════════════════════════
Tags: #pentesting #bug_bounty #cybersecurity #web_application_security #cyber_security_awareness
Title: Bug Bounty Hunting — Complete Guide (Part-155)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
Time: Fri, 05 Dec 2025 04:40:33 GMT
════════════════════════
Tags: #hacking #ethical_hacking #bug_bounty_tips #bug_bounty #cybersecurity
Title: Bug Bounty Hunting — Complete Guide (Part-154)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
Time: Fri, 05 Dec 2025 04:38:38 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty_tips #bug_bounty #ethical_hacking #hacking
Title: How Misconfigured Authentication Broke One App - And How We Fixed It (Sanitized Walkthrough)
════════════════════════
𐀪 Author: Krutik Thakar — Secure Developer | VAPT Associate
════════════════════════
Time: Fri, 05 Dec 2025 05:37:22 GMT
════════════════════════
Tags: #application_security #cybersecurity #vapt #secure_development #authentication
Title: Path Traversal: Because Hackers Also Love Taking Shortcuts
════════════════════════
𐀪 Author: TheCyberAryan
════════════════════════
Time: Fri, 05 Dec 2025 04:49:32 GMT
════════════════════════
Tags: #vulnerability #path_traversal #hacking #web_development #cybersecurity
Title: IOT Connect Writeup — MobileHackingLab
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
Time: Fri, 05 Dec 2025 04:26:28 GMT
════════════════════════
Tags: #hacking #android #mobile #ctf #penetration_testing
Title: React2Shell (CVE-2025–55182): What Developers Need to Know
════════════════════════
𐀪 Author: HectoGen
════════════════════════
Time: Fri, 05 Dec 2025 05:57:10 GMT
════════════════════════
Tags: #cybersecurity #nextjs #hacking #react
Title: SQL Injection Explained: From Basic to Advanced Exploitation (Complete Technical Guide)
════════════════════════
𐀪 Author: Handev Code
════════════════════════
Time: Fri, 05 Dec 2025 05:53:17 GMT
════════════════════════
Tags: #information_security #web_security #hacking #cybersecurity #backend_development