Daily Writeups
3.48K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 02 Mar 2026 00:43:46 +0000
════════════════════════
Tags: #Malware #APT31 #cryptography #CVE_2026 #go #Golang #infosec #Linux Security #malware #Open Source Security #Rekoobe #supply chain attack
Title: Security Alert: “Hackerbot-Claw” Autonomous Campaign Exploits GitHub Actions
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 03 Mar 2026 04:53:27 +0000
════════════════════════
Tags: #Vulnerability Report #2026 cyber threats #autonomous bot #Christopher Robinson #CI/CD security #Cloud Security #DevSecOps #GitHub Actions #hackerbot_claw #Open Source Security #OpenSSF #pwn request #supply chain attack
Title: Critical Vulnerabilities in AVideo: From SQL Injection to Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 04 Mar 2026 00:43:35 +0000
════════════════════════
Tags: #Vulnerability Report #AVideo #CVE_2026_28501 #CVE_2026_28502 #infosec #Open Source Security #Patch Alert #rce #Remote Code Execution #sql injection #sqli #Video Streaming Security
Title: Stream Hijacked: Critical Zero-Click Command Injection Flaw Exposed in AVideo-Encoder
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 06 Mar 2026 00:22:50 +0000
════════════════════════
Tags: #Vulnerability Report #AVideo_Encoder #Command Injection #CVE_2026_29058 #cybersecurity #infosec #Open Source Security #Patch Alert #unauthenticated RCE #Vulnerability #YouPHPTube
Title: Beyond the Perimeter: Auditing Active Directory Security with ADPulse’s 35-Point Automated Scan
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Fri, 06 Mar 2026 08:28:31 +0000
════════════════════════
Tags: #Open Source Tool #Active Directory #AD misconfiguration #AD security #ADPulse #Domain Controller #IT Administration #LDAP auditing #open source security #Penetration Testing #security reporting
Title: AI vs. Bugs: OpenAI Launches “Codex Security” to Revolutionize AppSec
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 07 Mar 2026 02:45:12 +0000
════════════════════════
Tags: #Technology #Agentic AI #Application Security #AppSec #Codex Security #cybersecurity #DevSecOps #infosec #Open Source Security #OpenAI #vulnerability management
Title: Broadcast Lockdown: The CVSS 9.8 Flaw in AVideo That Grants Total Server Control
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 10 Mar 2026 03:54:01 +0000
════════════════════════
Tags: #Vulnerability #AVideo #Command Injection #CVE_2026_29058 #CWE_78 #FFmpeg exploit #open source security #RCE #Server Hijacking #Tech News 2026 #Video Streaming Security
Title: Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 16 Mar 2026 09:24:16 +0000
════════════════════════
Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
Title: The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
Title: Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
Title: Budibase Patches Critical RCE and SSRF Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
Title: The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
Title: The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
Title: Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
Title: Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Title: Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
Title: How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
Title: From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for…
════════════════════════
𐀪 Author: eL Njas!
════════════════════════
Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
Tags: #vulnhunter #open_source #infosec #open_source_security #finance