Daily Writeups
3.45K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: The AI-Powered Cybercrime Factory: Unmasking the Bluekit “All-in-One” Phishing Revolution
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 05 May 2026 06:30:20 +0000
════════════════════════
Tags: #Cybercriminals #AI Phishing #Bluekit #Credential Theft #cybersecurity #infosec #Phishing_as_a_Service #Quishing #Session Hijacking #social engineering #Threat Intel #Varonis
Title: Cookies Explained: How Websites Remember You, And How Attackers Exploit It
════════════════════════
𐀪 Author: Amarachi Onyekachi
════════════════════════
Time: Tue, 05 May 2026 06:42:46 GMT
════════════════════════
Tags: #ethical_hacking #cybersecurity #cookies #web_security #session_management
Title: Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 01:01:32 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Wicket #CVE_2026_40010 #CVE_2026_43646 #CVE_2026_43975 #infosec #Java security #Patch Alert #Path Traversal #Session Fixation #web development #XSS
Title: A Simple Session Management Bug Every Beginner Bug Hunter Should Test.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Fri, 15 May 2026 10:23:43 GMT
════════════════════════
Tags: #simple_bugs #bug_bounty #session_management #p4_bugs
Title: Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
Title: Anonymity Stripped: Unsecured Kibana and Dozzle Dashboards Leak 22 Million FTF Live Video Chat Records
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 21 May 2026 07:26:05 +0000
════════════════════════
Tags: #Data Leak #Burhan LTD #Cooy Ads Ltd #Data Leak Cybernews #De_anonymization Risk #Dozzle Docker Logs #FTF Live Video Chat #Real_time Token Leak #Regional CERT Escalation #Session Metadata Exposure #Unsecured Kibana Dashboard
Title: Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 07:26:35 +0000
════════════════════════
Tags: #Malware #Chromium Browsers #Clipboard Hijacker #Control Flow Flattening #Cyber Security #Discord Token Stealer #Gremlin Stealer #infosec #Infostealer #MFA Bypass #Session Hijacking #Unit 42
Title: Splunk Patches High-Severity Bugs Granting DoS and Internal Log Leaks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 22 May 2026 01:20:03 +0000
════════════════════════
Tags: #Vulnerability Report #access control bypass #CVE_2026_20238 #CVE_2026_20239 #CVE_2026_20240 #Cyber Security #Denial of Service #infosec #Log Leak #Session Cookie Exposure #Splunk AI Toolkit #Splunk Enterprise
Title: A Simple Session Management Bug Every Beginner Bug Hunter Should Test.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Sat, 23 May 2026 08:18:09 GMT
════════════════════════
Tags: #simple_bugs #bug_bounty #session_management #p4_bugs
Title: VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 29 May 2026 09:41:23 +0000
════════════════════════
Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
Title: Cryptographic Paradigm Shift: Google Officially Launches Device Bound Session Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
Title: Weaponizing Management Consoles: The FortiClient EMS Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 01 Jun 2026 03:25:22 +0000
════════════════════════
Tags: #Vulnerability #Arctic Wolf Labs report #CVE_2026_35616 vulnerability #EKZ Infostealer analysis #endpoint security bypass #FortiClient EMS exploit #session cookie hijacking
Title: phpBB Authentication Bypass Fixed in Version 3.3.17
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 16 Jun 2026 03:35:00 +0000
════════════════════════
Tags: #Vulnerability #Aikido Security #authentication bypass #Forum Security #phpBB #Session Hijacking #Web Vulnerability
Title: Payroll Pirate Hijacks Sessions to Steal Paychecks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 17 Jun 2026 07:25:30 +0000
════════════════════════
Tags: #Cybercriminals #AiTM Phishing #Business Email Compromise #MFA Bypass #Payroll Fraud #Payroll Pirate #Session Hijacking
Title: $900 Session Flaw: Deprovisioned Users Retain Access After Permission Removal
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
Time: Fri, 19 Jun 2026 01:31:01 GMT
════════════════════════
Tags: #information_security #session_flaw #bug_bounty #programming #cybersecurity
Title: Session Fixation
════════════════════════
𐀪 Author: Ahemd ashraf
════════════════════════
Time: Tue, 07 Jul 2026 21:06:39 GMT
════════════════════════
Tags: #session_fixation #bugbounty_writeup #bug_bounty_tips
Title: pretix Patches Two Critical Session Takeover and SSRF Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Wed, 08 Jul 2026 13:14:14 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Leak #CVE_2026_13602 #CVE_2026_13603 #Payment Plugins #pretix #Session Takeover #ssrf
Title: The Wristband Problem
════════════════════════
𐀪 Author: Sentinel Layer
════════════════════════
Time: Mon, 13 Jul 2026 03:01:02 GMT
════════════════════════
Tags: #web_security #authentication #application_security #cybersecurity #session_hijacking
Title: Session Management | TryHackMe WalkThrough
════════════════════════
𐀪 Author: Cyrus Isaac
════════════════════════
Time: Fri, 17 Jul 2026 06:57:38 GMT
════════════════════════
Tags: #tryhackme #tryhackme_walkthrough #session_management #tryhackme_writeup
Title: Logout Security Testing Checklist
════════════════════════
𐀪 Author: Varshith Reddy
════════════════════════
Time: Wed, 22 Jul 2026 06:20:27 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty #session_management #authentication #web_security