Daily Writeups
3.45K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Apache MINA Fixes Critical RCE Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 04 May 2026 02:30:51 +0000
════════════════════════
Tags: #Vulnerability Report #Apache MINA #CVE_2026_42778 #CVE_2026_42779 #Deserialization #infosec #IoBuffer #Java security #patch management #rce #Vulnerability Research
Title: Apache Neethi Patches Triple Threat of DoS and Redirection Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 05 May 2026 01:25:08 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Neethi #CVE_2026_42402 #CVE_2026_42403 #CVE_2026_42404 #Denial of Service #infosec #Java security #Patch Alert #ssrf #Web Services #WS_Policy
Title: The Five-Day Race: Hackers Weaponize Critical Weaver E-cology RCE via Exposed Debugging API
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 05 May 2026 07:42:03 +0000
════════════════════════
Tags: #Vulnerability #CVE_2026_22679 #Debugging API #enterprise security #Java Vulnerability #Office Automation Security #Patch Management #RCE #remote code execution #Tomcat #Vega Research #Weaver E_cology
Title: Critical Flaws in Apache Thrift Threaten Multi-Language
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 01:00:24 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Thrift #CVE_2026_43868 #CVE_2026_43869 #CVE_2026_43870 #Denial of Service #infosec #Java security #Man in the Middle #Microservices Security #Node.js #Rust Security
Title: Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 12:38:06 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_41901 #cybersecurity #infosec #Java security #Patch Alert #rce #Sandbox Bypass #Server Side Template Injection #ssti #Thymeleaf #web development
Title: Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 01:01:32 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Wicket #CVE_2026_40010 #CVE_2026_43646 #CVE_2026_43975 #infosec #Java security #Patch Alert #Path Traversal #Session Fixation #web development #XSS
Title: Apache Tomcat RCE Details and Exploit Code Now Public
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 12 May 2026 03:22:16 +0000
════════════════════════
Tags: #Vulnerability #apache Tomcat #Cyber Security #EncryptInterceptor #Exploit PoC #infosec #Java security #Patch Alert #rce #vulnerability disclosure
Title: Critical 9.2 CVSS RCE Found in Amazon Redshift JDBC Driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 15 May 2026 01:36:20 +0000
════════════════════════
Tags: #Vulnerability Report #Amazon Redshift #aws security #CVE_2026_8178 #Cyber Security #Data Warehouse #database security #infosec #Java security #JDBC Driver #Patch Alert #rce
Title: Java Persistence API 】- 複雜查詢只能退回寫原生 SQL?掌握 JPQL 寫出優雅的物件導向查詢
════════════════════════
𐀪 Author: CoreyLi
════════════════════════
Time: Fri, 15 May 2026 12:01:00 GMT
════════════════════════
Tags: #sql_injection #orm #jpa #java #spring_data_jpa
Title: How I Found a P2 Cryptographic Vulnerability in Android’s KeyManager — Google VRP
════════════════════════
𐀪 Author: Rajagiri Sai Ganesh
════════════════════════
Time: Thu, 28 May 2026 19:55:39 GMT
════════════════════════
Tags: #android_security #java_security #bug_bounty #google_vrp #cryptography
Title: The Sabotage of Automation: Open-Source Project jqwik Poisoned Against AI Agents
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Sun, 31 May 2026 10:08:30 +0000
════════════════════════
Tags: #Technology #ANSI escape sequence terminal hiding #automated build log stream exploitation #Claude Code payload detection #indirect prompt injection software safety #Java testing dependencies boycott #jqwik hidden prompt injection #JUnit 5 platform alternative migration #Maven Central supply chain vulnerability #printMessageForCodingAgents source bytecode #protestware open source security risks
Title: Understanding Rate Limiting: A Deep Dive
════════════════════════
𐀪 Author: Dimuthu Harshamal
════════════════════════
Time: Sun, 31 May 2026 11:46:55 GMT
════════════════════════
Tags: #api_security #java #spring_boot #api #rate_limiting
Title: Apache Fesod SSRF Vulnerability Exposes Internal Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 02 Jun 2026 03:55:30 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Fesod #CVE_2026_49328 #Java Library #Server Security #SSRF vulnerability
Title: Apache Fory Vulnerability: High Severity Flaw Bypasses Core Java Serialization Checks
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 04 Jun 2026 16:36:07 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Fory #CVE_2026_50076 #deserialization flaw #fory_core #Java security #Software Patch
Title: Spring Boot 4.1’s New SSRF Filter Never Touched My Feign Calls — Here’s the Trap
════════════════════════
𐀪 Author: HobbiesPark
════════════════════════
Time: Thu, 25 Jun 2026 17:37:36 GMT
════════════════════════
Tags: #spring_security #java #spring_boot #microservices #ssrf
Title: How Spring Data JPA Protects You from SQL Injection Without You Knowing
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
Time: Tue, 30 Jun 2026 09:24:52 GMT
════════════════════════
Tags: #spring_boot #backend_development #sql_injection #java #cybersecurity
Title: Unlock Your Future with Java Training: The Ultimate Guide to Mastering Programming
════════════════════════
𐀪 Author: KOMAL PAL
════════════════════════
Time: Tue, 14 Jul 2026 02:34:40 GMT
════════════════════════
Tags: #javascript #java #digital_marketing #ethical_hacking #python
Title: How Your Spring Boot API Leaks Data (And Why Adding an Auth Check Isn’t the Fix)
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
Time: Tue, 21 Jul 2026 15:28:25 GMT
════════════════════════
Tags: #cybersecurity #idor #application_security #java #spring_boot
Title: Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Wed, 22 Jul 2026 13:18:16 +0000
════════════════════════
Tags: #Vulnerability Report #Deserialization #Fastjson #fastjson2 #FearsOff #java #proof_of_concept #QVD_2026_43021 #Remote Code Execution #SafeMode #Spring Boot
Title: Web Frameworks: Java | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
Time: Fri, 24 Jul 2026 11:01:01 GMT
════════════════════════
Tags: #red_team #java #cybersecurity #tryhackme