Filter
Exclude
Time range
-
Near
Never trust template rendering of user supplied input. Profile search and email features often expose hidden SSTI vulnerabilities. Manual testing consistently outperforms automated scanners here. #BugBounty #TemplateInjection #WebSecurity #InfoSec
2
66
CVE 2025 9556 in LangChainGo let attackers use Jinja2 directives to read sensitive files. The fix blocks file access by default and adds RenderTemplateFS. Upgrade now. #AIsecurity #LangChainGo #TemplateInjection #PromptSecurity #SoftwareVulnerability #ZeroTrust #DevSecOps #LLM
2
104
🚨 New Writeup Alert! 🚨 "Easy $300: Template Injection" by Abhijeet Kumawat is now live on IW! Check it out here: infosecwriteups.com/2ea1fc32… #infosec #bugbounty #templateinjection #hacking #cybersecurity

1
5
830
Detecting Out-of-Band (OOB) Template Injection vulnerabilities remains a critical challenge for security teams. Without automation, these flaws can lead to Remote Code Execution (RCE) and data leaks. In this blog, @DhiyaneshDK explores how DAST Nuclei Templates can help: ⚛️ Automate security testing using YAML-based templates ⚛️ Identify and exploit template injection flaws ⚛️ Leverage OOB exploitation techniques for deep assessments ⚛️ Upload findings to ProjectDiscovery Cloud Read the full guide here: projectdiscovery.io/blog/cra… #CyberSecurity #BugBounty #DAST #AppSec #TemplateInjection
1
5
31
2,157
9 Aug 2024
5
2
147
17 Feb 2024
We published a new post! Check out Alysha's new series about Template Injection blog.rehack.xyz/2024/02/intr… #rehackxyz #pentest #bugbounty #templateinjection #ssti

2
11
920
🚨Well Designed DOCX File with Low Detection🚨 Filename: Shotdown of Chipmixer(DOJ Report).docx
MD5:f6a130e5ddcb1f63b1d12fe19ec57c53
 DDE: Detected
SuspiciousURL: Detected
TemplateInjection: Detected IOCs: documentuser[.]us[.]org

Analysis Report: app.docguard.io/bdeb94b7aa7a…
2
17
41
6,240
#APT #Kimsuky #TemplateInjection url:http://k22012.c1[.]biz/paypal.dotm hash:9e916c4f58334aafcb033705e7fac6a217d8e2da131c8c1fd904edda7d026226 #CyberAttack #threatintelligence #threatintel
5
20
Filename: westele.docx SHA256: 812f20d2efdf9807d425cb63ea737d4bbc4774af375dbc6d3164b913c450b1be Verdict: Malicious DDE: Detected SuspiciousURL: Detected TemplateInjection: Detected Analysis Report: app.docguard.io/812f20d2efdf…

2
#cybercrime, l’exploit #Follina usa #Office per attaccare. Gli esperti di #CyberSecurity di @yoroisecurity: E’ la concatenazione di un attacco già noto e dello sfruttamento di componenti legittimi su Windows: #TemplateInjection e #Lolbin. #infosec difesaesicurezza.com/cyber/c…

3
4
18 Aug 2020
Interesting #Danish #maldoc related #COVID19 targeting #Sydslesvigsekretariatet (Ministry of Culture) #Denmark Bilag 1 Gennemgang af midtvejsrapporter 2020.DOCX ☣️7bf5cdf9caea7247dfdfa47240342210 #TemplateInjection🔃 dep-esdh[.kum.]dk:443/360Templates/Notat.docx #Gamaredon #APT
3
4
A close look at the advanced techniques used in a Malaysian-focused APT campaign #APT #TemplateInjection #Elastic dlvr.it/RZLqtJ
2
4
18 Jun 2020
Possible #Gamaredon targeting #Malaysia 🔃 Bubar Parlimen.docx ☣️ afbe00e755a2cf963f0eedbb4e310198 🔃 RemoteLoad.dotm 🔛 armybar[.hopto.]org ☣️ 8114e5e15d4086843cf33e3fca7c945b #TemplateInjection #APT #Macros #Exploit
1
5
12
2 Jun 2020
Potential #Gamaredon targeting #Ukraine people 🔃 🔛 kasim.freedynamicdns[.]org #Запит.docx #request ☣️ 33856c6f22c01808a4a4ae4034bc7141 🔃 #TemplateInjection ↔️ .../root/backups/IVCbXw.dot ☣️ e843e003470dff3703bb079fca83779f #T1221 #PrimitiveBear #Pteranodon #Pterodo
3
7