Daily Writeups
3.49K subscribers
2 photos
128K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Major xAI Security Lapse: DOGE Employee Leaks Confidential API Key for 50+ AI Models
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 16 Jul 2025 03:04:18 +0000
════════════════════════
Tags: #Data Leak #API Key #cybersecurity #Department of Defense #DOGE #Elon Musk #Github #Grok #language models #security breach #xAI
Title: ️ KeySentry v2 — Stop API Key Leaks Before They Stop You
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
Time: Sun, 17 Aug 2025 17:28:32 GMT
════════════════════════
Tags: #bug_bounty_tips #api_key #bug_bounty_writeup #cybersecurity #bug_bounty
Title: ️ KeySentry v2 — Stop API Key Leaks Before They Stop You
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
Time: Fri, 22 Aug 2025 07:37:00 GMT
════════════════════════
Tags: #bug_bounty_tips #api_key #bug_bounty_writeup #cybersecurity #bug_bounty
Title: Is Your API Key Alive or Dead? — Validate in Minutes with SecurityToolkits API Key Testing Tool
════════════════════════
𐀪 Author: Haxshadow
════════════════════════
Time: Sat, 06 Sep 2025 06:32:44 GMT
════════════════════════
Tags: #security #bugbounty_tips #temp_mail_api_key #bug_bounty #api_key
Title: From Free Nuggets to Full Access: How a Snack Craving Unwrapped McDonald’s Security Flaws
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
Time: Fri, 26 Sep 2025 03:31:48 GMT
════════════════════════
Tags: #mcdonalds #ethical_hacking #api_key_exposure #vulnerability_disclosure #cybersecurity
Title: Critical Nagios Flaw CVE-2025-44823 (CVSS 9.9) Leaks Plaintext Admin API Keys, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 08 Oct 2025 03:57:58 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Leak #Critical Vulnerability #CVE_2025_44823 #Elasticsearch #Nagios Log Server #privilege escalation #security advisory
Title: Critical Auth Bypass (CVE-2025-61928) in Better Auth Allows Hackers to Steal User API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 13 Oct 2025 00:30:48 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Theft #Authentication Bypass #Better Auth #Critical Vulnerability #CVE_2025_61928 #Next.js #TypeScript
Title: API Keys, Tokens & Secrets: How They Leak and How Developers can Avoid it
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
Time: Tue, 30 Dec 2025 01:21:19 GMT
════════════════════════
Tags: #api #sdlc #credentials #api_key #application_security
Title: Malicious Chrome Extension Drains Crypto via Secret API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 14 Jan 2026 00:01:12 +0000
════════════════════════
Tags: #Malware #API Key Theft #Chrome Extension Malware #crypto security #Cryptocurrency Scam #MEXC Exchange #Russian cybercrime #Socket Threat Research #Wallet drainer
Title: “Distillation” Theft: Attackers Target AI Models in New Wave of Intellectual Property Heists
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 16 Feb 2026 00:21:01 +0000
════════════════════════
Tags: #Cybercriminals #AI security #API Key Theft #artificial intelligence #DeepMind #Distillation Attack #Google Threat Intelligence #Intellectual Property #Model Extraction #One API #Xanthorox
Title: From $180 to $82,000 in 48 Hours: The Gemini API Key Leak Bankrupting Small Dev Teams
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 04 Mar 2026 04:26:40 +0000
════════════════════════
Tags: #Data Leak #API Key Leak #billing alert #Cloud Security #Cybersecurity 2026 #developer cautionary tale #Gemini API #Google AI Studio #Google Cloud #Shared Responsibility Model #tech bankruptcy
Title: The Skeleton Key: How Google’s “Safe” Maps Keys Silently Became Gemini Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 04 Mar 2026 07:09:01 +0000
════════════════════════
Tags: #Data Leak #AIStudio #API key security #cybersecurity research #Data Breach 2026 #firebase #Gemini API #google cloud #privilege escalation #Tech News 2026 #Truffle Security
Title: The $82,000 Mistake: Google AI Studio Finally Launches API Spending Ceilings
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 14 Mar 2026 06:56:26 +0000
════════════════════════
Tags: #Technology #AI Model Costs #API Key Security #Cloud Billing #Cyber Security #Developer Tools #Financial Guardrails #Google AI Studio #Google Cloud #Google Gemini #Spending Limits #Tech News 2026
Title: The $100 Fast Track: Google Slashes Gemini API Tier 2 Requirements and Adds Critical Spend Caps
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 18 Mar 2026 04:35:23 +0000
════════════════════════
Tags: #Technology #API Key Safety #API Rate Limits #cyber security 2026 #Developer Tools #Gemini API #Google AI Studio #Google Cloud Billing #Google DeepMind #Spend Caps #Tier 2 Upgrade
Title: The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 03 Apr 2026 09:40:11 +0000
════════════════════════
Tags: #Data Leak #API Key Theft #aws security #CERT_EU #CI/CD security #data leak #EU Security #European Commission #infosec #ShinyHunters #supply chain attack #TeamPCP #Trivy
Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Title: Critical 9.8 CVSS Flaws Hit ArcGIS Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 12:02:03 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Vulnerability #ArcGIS #CVE_2026_33518 #CVE_2026_33519 #cybersecurity #Esri #GIS Security #infosec #OAuth 2.0 #Patch Alert #Portal for ArcGIS
Title: A Secret Key in Plain Sight:
How I Earned My First $200 Finding a Hidden
API Leak

════════════════════════
𐀪 Author: Theankitsaini16
════════════════════════
Time: Sun, 24 May 2026 17:16:28 GMT
════════════════════════
Tags: #ethical_hacking #reconnaissance #infosec #bug_bounty #api_key
Title: Lock Down Your APIs: A Guide to API Key Authentication
════════════════════════
𐀪 Author: Naduni Pamudika
════════════════════════
Time: Mon, 25 May 2026 08:02:31 GMT
════════════════════════
Tags: #wso2_api_manager #api_security #api_key #wso2
Title: pretix Patches Two Critical Session Takeover and SSRF Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Wed, 08 Jul 2026 13:14:14 +0000
════════════════════════
Tags: #Vulnerability Report #API Key Leak #CVE_2026_13602 #CVE_2026_13603 #Payment Plugins #pretix #Session Takeover #ssrf