Daily Writeups
3.49K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Title: Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Title: The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
Title: Shift Security Left: Detecting Code Vulnerabilities Early with CodeQL in GitHub Actions
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
Time: Thu, 04 Jun 2026 05:36:39 GMT
════════════════════════
Tags: #shift_left_security #github_actions #application_security #codeql #devsecops
Title: Building a Parallel Security Gate in CI: Combining Secret Scanning, Dependency Audits, and SAST…
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
Time: Fri, 05 Jun 2026 05:58:28 GMT
════════════════════════
Tags: #cicd #application_security #github_actions #shift_left_security #devsecops
1
Title: Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
Title: Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
Title: GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
Title: GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 23 Jul 2026 02:29:19 +0000
════════════════════════
Tags: #Cybercriminals #cPanel and WHM exploitation #Credential Theft #CVE_2026_41940 #GitHub Actions abuse #Packagist #supply chain attack
Title: Analyzing GitHub Actions workflows at scale
════════════════════════
𐀪 Author: Kulkan Security
════════════════════════
Time: Tue, 04 Aug 2026 13:44:03 GMT
════════════════════════
Tags: #prompt_injection_attack #penetration_testing #supply_chain_security #vulnerability #github_actions