Daily Writeups
3.49K subscribers
2 photos
128K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Title: Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Title: The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
Title: The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Title: Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
Title: Signed, Trusted, and Abused: Proxy Execution via WebView2
════════════════════════
𐀪 Author: BHIS
════════════════════════
Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
Title: “Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
Title: KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
Title: The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
Title: Romanian Hacker Sentenced to Prison Following Government Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
Title: DriveSurge Threat Cluster Exploits Thousands of Websites Globally
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 04 Jun 2026 10:54:47 +0000
════════════════════════
Tags: #Cybercriminals #ClickFix #DriveSurge #FakeUpdates #Infrastructure Fingerprinting #initial access broker #malware delivery #social engineering #zTDS
Title: FortiBleed Turns Hacked FortiGate Firewalls Into Credential Collectors
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
Time: Thu, 25 Jun 2026 04:06:14 +0000
════════════════════════
Tags: #Data Leak #Credential Theft #FortiBleed #FortiGate #FortigateSniffer #Fortinet #Initial Access Broker
Title: Edgecution Malware Turns a Microsoft Edge Extension Into a Backdoor
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Mon, 29 Jun 2026 06:11:32 +0000
════════════════════════
Tags: #Malware #Edgecution #initial access broker #malicious Edge extension #microsoft edge #Native Messaging #Payouts King ransomware #Python backdoor #Zscaler ThreatLabz
Title: GoGRPC Backdoor Spreads Through Microsoft Teams Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Fri, 31 Jul 2026 08:09:09 +0000
════════════════════════
Tags: #Cybercriminals #BlindDoor #GoGRPC #initial access broker #Microsoft Teams vishing #Quick Assist #ransomware #RSOX #Vishing #Zscaler ThreatLabz