writeups.xyz writeups.xyz / Yakir Kadkoda

Title Vulnerabilities Programs Authors
Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources
Phantom Secrets: Undetected Secrets Expose Major Corporations
CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE
Threat Alert: Private npm Packages Disclosed via Timing Attacks
CVE-2022-32223 Discovery: DLL Hijacking via npm CLI
Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages?
New npm Flaws Let Attackers Better Target Packages for Account Takeover