Daily Writeups
3.51K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Python Cheatsheet for Exploit Payload Crafting: For Pentest Tools and Offensive Security
════════════════════════
𐀪 Author: Riki Satya Graha
════════════════════════
Time: Tue, 04 Feb 2025 04:49:31 GMT
════════════════════════
Tags: #ethical_hacking #exploit_payloads #pentest_techniques #offensive_security #python_security
Title: Python Web API 5 — Securing Your Python Web API: Authentication and Authorization Techniques
════════════════════════
𐀪 Author: Ayşe Kübra Kuyucu
════════════════════════
Time: Mon, 10 Feb 2025 14:02:07 GMT
════════════════════════
Tags: #api_best_practices #python_security #python_authentication #api_security #web_api_authorization
Title: Reinforcement Learning 20 — Securing Reinforcement Learning Systems: Best Practices in Python
════════════════════════
𐀪 Author: Ayşe Kübra Kuyucu
════════════════════════
Time: Wed, 09 Jul 2025 00:26:02 GMT
════════════════════════
Tags: #machine_learning #best_practices #python_security #cybersecurity #reinforcement_learning
Title: Secure Coding Part 8 — Command Injection Attack: Python eval()
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
Time: Wed, 06 Aug 2025 11:25:56 GMT
════════════════════════
Tags: #application_security #command_injection #web_penetration_testing #secure_coding #python_security
Title: Secure Coding Part 9— Command Injection Attack: Python exec() & Seccomp to the rescue
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
Time: Mon, 11 Aug 2025 15:53:16 GMT
════════════════════════
Tags: #command_injection #application_security #seccomp #python_security #secure_coding
Title: SQL Injection Deep Dive: Techniques, Tricks, Prevention & Python Secure Coding
════════════════════════
𐀪 Author: Vaibhav Tiwari
════════════════════════
Time: Wed, 03 Sep 2025 08:54:37 GMT
════════════════════════
Tags: #cybersecurity #sql_injection #python_security #secure_coding #webexploit
Title: File Path Traversal — Why a one-pass ../ filter fails and how to fix it
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
Time: Tue, 16 Sep 2025 20:49:29 GMT
════════════════════════
Tags: #web_security #path_traversal #application_security #python_security #secure_coding
Title: A Practical Guide to Server-Side Template Injection (SSTI)
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
Time: Sat, 29 Nov 2025 09:06:59 GMT
════════════════════════
Tags: #cybersecurity #penetration_testing #web_security #web_development #python_security
Title: The “lc” Leak: Critical 9.3 Severity LangChain Flaw Turns Prompt Injections into Secret Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:22:06 +0000
════════════════════════
Tags: #Vulnerability Report #AI Agents #CVE_2025_68664 #data exfiltration #Environment Variables #Information Disclosure #LangChain #LLM Security #Prompt injection #Python Security #Serialization Injection
Title: n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 06 Jan 2026 09:44:11 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_68668 #DevSecOps #n8n #Pyodide #Python Security #rce #Sandbox Escape #Vulnerability Analysis #Workflow Automation
Title: CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 07 Jan 2026 01:53:23 +0000
════════════════════════
Tags: #Vulnerability Report #Arbitrary Code Execution #CERT/CC #CVE_2025_14026 #DLP (Data Loss Prevention) #Enterprise Security #Forcepoint #Python Security #Sandbox Escape
Title: 4 Million Downloads at Risk: Critical Unstructured Flaw (CVSS 9.8) Allows RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 06 Feb 2026 00:23:34 +0000
════════════════════════
Tags: #Vulnerability Report #AI supply chain #CVE_2025_64712 #CVSS 9.8 #LLM Data #Malicious MSG #Patch Alert #Path Traversal #Python Security #rce #Unstructured Library
Title: Splunk Windows Flaws Expose Servers to System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 19 Feb 2026 14:44:13 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_20140 #CVE_2026_20143 #Cyber Security #DLL hijacking #infosec #Local Privilege Escalation #LPE #Patch Alert #Python Security #Splunk Enterprise #Windows Security
Title: Critical SQL Injection Vulnerability Found in ‘ormar’ Python Library
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 26 Feb 2026 00:00:54 +0000
════════════════════════
Tags: #Vulnerability Report #AppSec #CVE_2026_26198 #database security #FastAPI #infosec #ormar #Patch Alert #Python Security #sql injection #SQLalchemy #Vulnerability
Title: Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 17 Mar 2026 12:02:37 +0000
════════════════════════
Tags: #Vulnerability Report #Authlib #CVE_2026_27962 #CVE_2026_28490 #CVE_2026_28498 #cybersecurity #JWT Security #OAuth #OpenID Connect #Padding Oracle #Python Security
Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Title: Langflow Alert: Path Traversal Flaw in Knowledge Bases API Risks Total Data Wipeout
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 28 Apr 2026 12:48:40 +0000
════════════════════════
Tags: #Vulnerability Report #AI security #CVE_2026_42048 #cybersecurity #Data Loss #infosec #Langflow #Path Traversal #Python Security #shutil.rmtree #Vulnerability Research
Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
Title: Critical Defect Exposed: Flaw In Apache Fory Bypasses Deserialization Protections
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 27 May 2026 02:44:39 +0000
════════════════════════
Tags: #Vulnerability Report #Apache Fory #CVE_2026_48207 #Deserialization Bypass #Pyfory #Python Security #Remote Code Execution