Daily Writeups
3.45K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Deserialization for Hackers: How Server Logic Gets Hijacked
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
Tags: #bug_bounty #json #bug_bounty_tips #hacking
Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
Tags: #bug_bounty #json #bug_bounty_tips #hacking
Title: Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the “End-of-Life” Security Gap
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
Title: JSON.parse(JSON.stringify()) VS structuredClone()
════════════════════════
𐀪 Author: Gutu Galuppo
════════════════════════
Time: Thu, 19 Feb 2026 11:43:49 GMT
════════════════════════
Tags: #hacking #javascript #json #json_stringify #object_oriented
Title: JSON Injection: The Silent API Killer You’re Probably Ignoring
════════════════════════
𐀪 Author: Tejas Shirsat
════════════════════════
Time: Thu, 19 Feb 2026 16:14:58 GMT
════════════════════════
Tags: #json #appsec #api_security #cybersecurity
Title: Top Technology Stacks for MVP Development in 2026
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
Time: Mon, 23 Feb 2026 13:53:40 +0000
════════════════════════
Tags: #Technology #API #Developers #Freshcode #javascript #JSON #MVP #React
Title: Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
Title: Critical 10.0 CVSS Flaw in pac4j-jwt Lets Hackers Forge Admin Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 05 Mar 2026 02:00:37 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #CodeAnt AI #CVE_2026_29000 #CVSS 10.0 #infosec #Java security #JSON Web Tokens #JWT Security #pac4j_jwt #Vulnerability
Title: The Null-Signature Trap: Unmasking the 10.0 CVSS Authentication Bypass in pac4j-jwt
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 06 Mar 2026 08:13:07 +0000
════════════════════════
Tags: #Vulnerability #authentication bypass #CodeAnt AI #CVE_2026_29000 #identity theft #Java security #JSON Web Encryption #JWE #JWT #pac4j_jwt #RSA #Tech News 2026
Title: Couch (THM) Tryhackme WriteUp And Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
Time: Sun, 15 Mar 2026 03:36:42 GMT
════════════════════════
Tags: #ctf_writeup #json #cybersecurity #hacking #tryhackme
Title: How JWT Authentication Actually Works (Step-by-Step Guide)
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
Time: Sat, 11 Apr 2026 07:05:31 GMT
════════════════════════
Tags: #web_security #json_web_token #jwt_authentication #stateless_authentication #application_security
Title: JWT Attacks You Should Know (Beyond the Basics)
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
Time: Tue, 14 Apr 2026 15:58:40 GMT
════════════════════════
Tags: #web_application_security #security #json_web_token #jwt_authentication #hacking
Title: Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
Title: Hacking JSON Web Tokens: How Attackers Exploit API Authentication
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
Time: Thu, 28 May 2026 17:53:25 GMT
════════════════════════
Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
Title: Hacking JSON Web Tokens: How Attackers Exploit API Authentication
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
Time: Fri, 29 May 2026 09:15:40 GMT
════════════════════════
Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
Title: JSON_EXTRACT Injection: When Prepared Statements Aren’t Enough
════════════════════════
𐀪 Author: Isuka sanuj
════════════════════════
Time: Thu, 11 Jun 2026 15:15:27 GMT
════════════════════════
Tags: #json #sql_injection #jsonpath