⤷ Title: Ingress-NGINX Under Siege: A Deep Dive into CVE-2025–1974 and Cluster Security
════════════════════════
𐀪 Author: Anindya Sankar Roy
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 17:38:54 GMT
════════════════════════
⌗ Tags: #nginx_ingress #web_hacking #wiz #bug_bounty #rce
════════════════════════
𐀪 Author: Anindya Sankar Roy
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 17:38:54 GMT
════════════════════════
⌗ Tags: #nginx_ingress #web_hacking #wiz #bug_bounty #rce
Medium
Ingress-NGINX Under Siege: A Deep Dive into CVE-2025–1974 and Cluster Security
In March 2025, a critical set of vulnerabilities, collectively termed IngressNightmare, was disclosed in the Kubernetes Ingress-NGINX…
⤷ Title: JINX-0132: Cryptojackers Exploit Misconfigured DevOps Environments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:46:19 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Consul #Cryptojacking #cybersecurity #DevOps #Docker API #Gitea #HashiCorp Nomad #JINX_0132 #misconfiguration #Monero #Wiz Threat Research #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:46:19 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Consul #Cryptojacking #cybersecurity #DevOps #Docker API #Gitea #HashiCorp Nomad #JINX_0132 #misconfiguration #Monero #Wiz Threat Research #XMRig
Daily CyberSecurity
JINX-0132: Cryptojackers Exploit Misconfigured DevOps Environments
Wiz uncovers JINX-0132, a cryptojacking campaign exploiting misconfigured Nomad, Consul, Docker, and Gitea in DevOps environments to mine Monero.
⤷ Title: Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:07:06 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #rce #Remote Code Execution #TeamCity #Wiz Research Team
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:07:06 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #rce #Remote Code Execution #TeamCity #Wiz Research Team
Daily CyberSecurity
Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
Wiz Research Team uncovers rapid exploitation of exposed JDWP interfaces, deploying XMRig cryptominers in TeamCity and other Java environments within hours of exposure.
⤷ Title: Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:24:42 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #RCE #remote code execution #TeamCity #Wiz Research Team
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:24:42 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #RCE #remote code execution #TeamCity #Wiz Research Team
Penetration Testing Tools
Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
Wiz Research Team uncovers rapid exploitation of exposed JDWP interfaces, deploying XMRig cryptominers in TeamCity and other Java environments within hours of exposure.
⤷ Title: Soco404: New Stealthy Cryptojacking Campaign Exploits Cloud Misconfigurations and PostgreSQL to Mine Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cryptojacking #Cybercrime #Linux #malware #PostgreSQL #Soco404 #Stealth #windows #Wiz Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cryptojacking #Cybercrime #Linux #malware #PostgreSQL #Soco404 #Stealth #windows #Wiz Research
Daily CyberSecurity
Soco404: New Stealthy Cryptojacking Campaign Exploits Cloud Misconfigurations and PostgreSQL to Mine Crypto
Wiz Research uncovers Soco404, an evolving cryptojacking operation exploiting cloud misconfigurations and PostgreSQL to stealthily mine cryptocurrency across Linux and Windows.
⤷ Title: Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Platform #Authentication Bypass #Base44 #cybersecurity #Single Sign_On #SSO #Vulnerability #Wix #Wiz Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Platform #Authentication Bypass #Base44 #cybersecurity #Single Sign_On #SSO #Vulnerability #Wix #Wiz Research
Daily CyberSecurity
Critical Flaw in Wix's New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
Wiz Research uncovered a critical flaw in Wix's new AI platform, Base44, that allowed unauthorized access to private enterprise applications and sensitive data by bypassing SSO.
⤷ Title: Critical Flaw in Wix’s Base44 AI Platform Allowed Access to Private Enterprise Apps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Platform #authentication bypass #Base44 #cybersecurity #Single Sign_On #SSO #vulnerability #Wix #Wiz Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Platform #authentication bypass #Base44 #cybersecurity #Single Sign_On #SSO #vulnerability #Wix #Wiz Research
Penetration Testing Tools
Critical Flaw in Wix's Base44 AI Platform Allowed Access to Private Enterprise Apps
Wiz Research uncovered a critical vulnerability in Base44, Wix's AI-powered coding platform, that allowed unauthorized access to private enterprise applications by bypassing SSO.
⤷ Title: Critical Triton Flaws (CVSS 9.8) Expose AI Servers to Remote Takeover – Patch Now!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:35:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #rce #Remote Code Execution #Vulnerability #Wiz Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:35:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #rce #Remote Code Execution #Vulnerability #Wiz Research
Daily CyberSecurity
Critical Triton Flaws (CVSS 9.8) Expose AI Servers to Remote Takeover – Patch Now!
NVIDIA has patched multiple critical flaws (CVSS 9.8) in its Triton Inference Server. A vulnerability chain allows unauthenticated attackers to gain RCE and seize AI servers.
⤷ Title: Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
Penetration Testing Tools
Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
NVIDIA has patched multiple critical flaws (CVSS 9.8) in its Triton Inference Server. A vulnerability chain allows unauthenticated attackers to gain RCE and seize AI servers.
⤷ Title: 50,000 Emails a Day: How a Cloud Flaw Is Fueling Phishing Campaigns
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #aws security #Cloud Security #Cybercrime #email abuse #Phishing Campaign #Wiz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #aws security #Cloud Security #Cybercrime #email abuse #Phishing Campaign #Wiz
Daily CyberSecurity
50,000 Emails a Day: How a Cloud Flaw Is Fueling Phishing Campaigns
A new report reveals how a compromised AWS key was used to bypass security controls in Amazon SES, enabling a 50,000-email-per-day phishing campaign.