With high profile Linux package vulns, our team at @wiz_io needs to keep with which distros have patches available so we can rapidly update our detections. I couldn't find a public centralized view for this information, so we built one 🙂
https://t.co/9pno6zkJcF
🚨 Research alert: Another npm supply chain attack is targeting developers.this time through popular packages in the keyv and cacheable ecosystems.
Check affected versions, IOCs, and mitigation steps 👇
https://t.co/nKRT04ACS0
🚨 🪱 Ongoing Shai-Hulud software supply chain attack affecting dozens of npm packages across the Keyv and Cacheable ecosystems
The malware targets cloud credentials, GitHub tokens, CI/CD secrets, Kubernetes and Terraform configurations, and more.
Affected organizations should remove malicious versions, rebuild impacted environments, rotate credentials, and investigate for unauthorized access.
.@shahardorf has spent the past few months investigating all sorts of compromised virtual appliances - here's what we've learned about how threat actors target FortiGate devices for exploitation and leverage that access for lateral movement:
OSS Shai-Hulud has been leveraged in a supply chain attack against 32 [@]redhat-cloud-services packages.
80k weekly downloads, but takedown in progress
more to come ->
https://t.co/au4fhGoLnn
🎙️ NEW PODCAST: AI just uncovered a #Linux bug hiding since 2017 👀
Eden & @AmitaiCo sit with @tjbecker & Jacob Newman from @xint_official to unpack CopyFail, the privilege escalation flaw their autonomous AI agents discovered affecting Linux machines worldwide.
npm package "intercom-client" version 7.0.4 is compromised (still available to download as of now), likely related to Mini Shai Hulud campaign by TeamPCP based on shared characteristics
We hacked the AWS JavaScript SDK, a core library powering the entire @AWScloud ecosystem - including the AWS Console itself 🤯
How did we do it? Just two missing characters was all it took.
This is the story of #CodeBreach 🧵👇
Wiz Research has published a new simple Nuclei template for reliably detecting MongoBleed (CVE-2025-14847). We've also updated our blogpost with additional guidance on determining exploitability depending on how you're using MongoDB:
We were analyzing the new RSC vulnerability and its impact. RSC is a React feature, but most apps use it through Next.js, which bundles RSC widely. So it will likely surface most often as Next.js CVE-2025-66478. Patch snippet below 🧐 Initial analysis: https://t.co/cMvEbTeWLq
With all the talk about the Next.js PoC, many people missed that the React2Shell vulnerability (CVE-2025-55182) affects the underlying RSC implementation itself. This means other popular frameworks that rely on RSC are also vulnerable. We are still analyzing the impact and ease of exploitation across additional platforms. For example, the commonly used Vite RSC plugin, when running with its default configuration, is also vulnerable with only minor modifications to the existing PoC. Patch your environments as soon as possible 🏃♀️
"Sha1-Hulud: The Continued Coming."
A potential second phase just hit - making private repos public, with a single victim so far
We'll continue to keep our blog post up to date
🚨 Shai-Hulud 2.0: 25k+ npm packages compromised.
New variant runs immediately via preinstall to hijack CI/CD runners and persist. Attack flow attached 👇
Check out our blog on the @wiz_io website
Our recent research reveals how malware-less database ransomware actually scales ⚡️
Finding: MongoDB is the most dominant target, and a newly exposed DB can be discovered and hijacked within minutes - without dropping a single binary. 👾 (1/5)🧵
🚨 Wiz spotted a #JDWP RCE attack deploying a stealthy cryptominer within hours. Custom XMRig, no CLI flags, deep persistence.
Debug mode ≠ safe mode.
Read the full breakdown 👉 https://t.co/Ub05XbKkmK
Hackers ❤️ your #PostgreSQL
Wiz Research just found a stealthy campaign hitting 1.5 K+ cloud environments-evading detection
- multiple payloads
- customized malware for each victim
- establishing persistence on the service
🎙️ New #CryingOutCloud episode! 🚨 @AmitaiCo & Eden Naftali chat with @nirohfeld on #IngressNightmare — an unauth RCE in NGINX Ingress Controller.
Listen now:
🎧https://t.co/5oDulZrszu
🍏 https://t.co/VBTjgG3aJX
We (+@sagitz_@ronenshh@hillai) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX".
The impact?
From zero permissions ➡️ to complete cluster takeover 🤯
This is the story of #IngressNightmare 🧵⬇️
😺 Cat's out of the bag
We've updated our blog post on the `tj-actions` / `reviewdog` incident to disclose the target. We also have new details on the root cause of the `reviewdog` element.
h/t @sshaybbc for a ton of leg work here
🚨 Wiz Research has uncovered new malware by the #Diicot threat group, targeting #Linux & #Cloud systems with advanced, cloud-aware techniques.
#ThreatIntel