<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Cloud Threat Landscape</title>
        <link>https://threats.wiz.io/</link>
        <description>A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques. Powered by Wiz Research.</description>
        <lastBuildDate>Mon, 15 Jun 2026 18:02:17 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <image>
            <title>Cloud Threat Landscape</title>
            <url>https://www.wiz.io/rss_feed_logo.jpg</url>
            <link>https://threats.wiz.io/</link>
        </image>
        <copyright>All rights reserved 2026, Wiz Inc.</copyright>
        <item>
            <title><![CDATA[JINX-0164 Targeting Cryptocurrency Development Infrastructure (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/jinx-0164-targeting-cryptocurrency-development-infrastructure</link>
            <guid isPermaLink="false">36ed8c76-b6ae-80dd-9dd8-d6d5eb4379a1</guid>
            <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research identified an active threat campaign targeting cryptocurrency organizations and software development infrastructure through social engineering, malicious meeting lures, and supply chain compromise activity. The campaign leveraged fake business interactions and tro...]]></description>
            <content:encoded><![CDATA[Wiz Research identified an active threat campaign targeting cryptocurrency organizations and software development infrastructure through social engineering, malicious meeting lures, and supply chain compromise activity. The campaign leveraged fake business interactions and tro...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Campaign Targeting Composer and GitHub Repositories (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-campaign-targeting-composer-and-github-repositories</link>
            <guid isPermaLink="false">36ed8c76-b6ae-80ce-80b0-cc8b2b811531</guid>
            <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified multiple coordinated software supply chain attacks targeting Composer/Packagist packages and upstream GitHub repositories. The activity involved malicious postinstall hooks, compromised Git tags, CI/CD payload execution, and credential-stealing malware d...]]></description>
            <content:encoded><![CDATA[Researchers identified multiple coordinated software supply chain attacks targeting Composer/Packagist packages and upstream GitHub repositories. The activity involved malicious postinstall hooks, compromised Git tags, CI/CD payload execution, and credential-stealing malware d...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Megalodon Campaign Backdoors GitHub Repositories via CI Workflow Compromise (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/megalodon-campaign-backdoors-github-repositories-via-ci-workflow-compromise</link>
            <guid isPermaLink="false">36ed8c76-b6ae-8035-86e3-e9f654267a3f</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers disclosed a large-scale software supply chain campaign dubbed “Megalodon,” in which attackers reportedly compromised thousands of GitHub repositories by injecting malicious GitHub Actions workflows designed to exfiltrate secrets and cloud credentials. The campaign ...]]></description>
            <content:encoded><![CDATA[Researchers disclosed a large-scale software supply chain campaign dubbed “Megalodon,” in which attackers reportedly compromised thousands of GitHub repositories by injecting malicious GitHub Actions workflows designed to exfiltrate secrets and cloud credentials. The campaign ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TeamPCP Claims Breach of Internal GitHub Repositories (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/teampcp-claims-breach-of-internal-github-repositories</link>
            <guid isPermaLink="false">366d8c76-b6ae-809d-8879-f3cbd588aea2</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[According to GitHub’s public statement, the company detected unauthorized access involving internal repositories and initiated an ongoing investigation into the scope and potential impact of the incident. GitHub stated that it is closely monitoring its infrastructure for follo...]]></description>
            <content:encoded><![CDATA[According to GitHub’s public statement, the company detected unauthorized access involving internal repositories and initiated an ongoing investigation into the scope and potential impact of the incident. GitHub stated that it is closely monitoring its infrastructure for follo...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[New Mini-Shai-Hulud Wave Targets NPM, PyPi Packages and VSCode Extension (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/new-mini-shai-hulud-wave-targets-npm-pypi-packages-and-vscode-extension</link>
            <guid isPermaLink="false">366d8c76-b6ae-8033-b91f-f62800ef85a8</guid>
            <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified a broad TeamPCP-linked supply chain campaign involving malicious NPM packages, compromised GitHub Actions, a trojanized VSCode extension, and malicious PyPI packages targeting cloud and CI/CD environments. The campaign includes large-scale credential the...]]></description>
            <content:encoded><![CDATA[Researchers identified a broad TeamPCP-linked supply chain campaign involving malicious NPM packages, compromised GitHub Actions, a trojanized VSCode extension, and malicious PyPI packages targeting cloud and CI/CD environments. The campaign includes large-scale credential the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[node-ipc npm Distribution Compromised (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/node-ipc-npm-distribution-compromised</link>
            <guid isPermaLink="false">366d8c76-b6ae-80b0-b08c-e0d4b4a6c707</guid>
            <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Multiple trojanized versions of the @node-ipc package have were uploaded to npm on 14 May 2026. The malicious versions are: node-ipc@9.1.6, node-ipc@9.2.3, node-ipc@12.0.1 The malicious code collects data and exfiltrates it via dns tunneling.On 14 May 2026 three malicious vers...]]></description>
            <content:encoded><![CDATA[Multiple trojanized versions of the @node-ipc package have were uploaded to npm on 14 May 2026. The malicious versions are: node-ipc@9.1.6, node-ipc@9.2.3, node-ipc@12.0.1 The malicious code collects data and exfiltrates it via dns tunneling.On 14 May 2026 three malicious vers...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Tanstack and other Packages Compromised in Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/tanstack-and-other-packages-compromised-in-supply-chain-attack</link>
            <guid isPermaLink="false">366d8c76-b6ae-8036-9187-c51b6b2d5320</guid>
            <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[On May 11, 2026, TeamPCP launched coordinated software supply chain attacks targeting the npm and PyPI ecosystems. Over roughly six hours, the attacker published dozens of trojanized packages across multiple namespaces, including several high-profile and trusted publishers.The...]]></description>
            <content:encoded><![CDATA[On May 11, 2026, TeamPCP launched coordinated software supply chain attacks targeting the npm and PyPI ecosystems. Over roughly six hours, the attacker published dozens of trojanized packages across multiple namespaces, including several high-profile and trusted publishers.The...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DDoS Botnet Leveraging Jenkins Misconfigurations for Initial Access (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ddos-botnet-leveraging-jenkins-misconfigurations-for-initial-access</link>
            <guid isPermaLink="false">366d8c76-b6ae-8091-85cd-e258bd2b8ce5</guid>
            <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The attack begins with unauthorized access to exposed Jenkins instances, often enabled by weak credentials. Threat actors abuse the scriptText endpoint, which allows execution of Groovy scripts, to achieve remote code execution. The malicious script delivers platform-specific ...]]></description>
            <content:encoded><![CDATA[The attack begins with unauthorized access to exposed Jenkins instances, often enabled by weak credentials. Threat actors abuse the scriptText endpoint, which allows execution of Groovy scripts, to achieve remote code execution. The malicious script delivers platform-specific ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Compromise of Checkmarx Jenkins AST Plugin by TeamPCP (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/compromise-of-checkmarx-jenkins-ast-plugin-by-teampcp</link>
            <guid isPermaLink="false">366d8c76-b6ae-809f-b986-ce7faf172f53</guid>
            <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Previously, the attackers gained access to internal resources, and used it to extract sensitive credentials, including publishing credentials for Jenkins plugins. Using this access, they modified and redistributed the Checkmarx AST Scanner Jenkins Plugin via the official plugi...]]></description>
            <content:encoded><![CDATA[Previously, the attackers gained access to internal resources, and used it to extract sensitive credentials, including publishing credentials for Jenkins plugins. Using this access, they modified and redistributed the Checkmarx AST Scanner Jenkins Plugin via the official plugi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Lightning and Intercom Packages Compromised in Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/lightning-and-intercom-packages-compromised-in-supply-chain-attack</link>
            <guid isPermaLink="false">366d8c76-b6ae-809f-8ed1-d4ef858df6f4</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[In the PyPI package lightning, malicious code is triggered automatically upon import. The code downloads and installs the Bun runtime and executes a large (~11 MB) obfuscated JavaScript payload. This behavior enables credential harvesting from developer environments and CI/CD ...]]></description>
            <content:encoded><![CDATA[In the PyPI package lightning, malicious code is triggered automatically upon import. The code downloads and installs the Bun runtime and executes a large (~11 MB) obfuscated JavaScript payload. This behavior enables credential harvesting from developer environments and CI/CD ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-campaign-targets-sap-npm-packages-with-credential-stealing-malware</link>
            <guid isPermaLink="false">35dd8c76-b6ae-8079-b8ea-c82c12dbd074</guid>
            <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Malicious versions of legitimate SAP ecosystem packages (e.g., @cap-js/sqlite, @cap-js/postgres) were created by modifying them to include a preinstall script that executes setup.mjs automatically during npm install. This script downloads the Bun runtime and executes an obfusc...]]></description>
            <content:encoded><![CDATA[Malicious versions of legitimate SAP ecosystem packages (e.g., @cap-js/sqlite, @cap-js/postgres) were created by modifying them to include a preinstall script that executes setup.mjs automatically during npm install. This script downloads the Bun runtime and executes an obfusc...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Critical SQL Injection Vulnerability in LiteLLM Exploited in-the-Wild (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/critical-sql-injection-vulnerability-in-litellm-exploited-in-the-wild</link>
            <guid isPermaLink="false">35dd8c76-b6ae-809c-a4ce-d660a29006a9</guid>
            <pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The vulnerability exists in LiteLLM’s authentication flow, where the Authorization: Bearer header is directly concatenated into a SQL query without proper parameterization. This flaw allows attackers to inject arbitrary SQL statements prior to authentication, enabling direct a...]]></description>
            <content:encoded><![CDATA[The vulnerability exists in LiteLLM’s authentication flow, where the Authorization: Bearer header is directly concatenated into a SQL query without proper parameterization. This flaw allows attackers to inject arbitrary SQL statements prior to authentication, enabling direct a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Elementary Data Compromised in Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/elementary-data-compromised-in-supply-chain-attack</link>
            <guid isPermaLink="false">35dd8c76-b6ae-806f-ad8a-e53ff3df2be9</guid>
            <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The compromise originated from a GitHub Actions script injection vulnerability in a workflow that improperly handled untrusted input from pull request comments. An attacker exploited this flaw to execute arbitrary commands within the CI pipeline, gaining access to the reposito...]]></description>
            <content:encoded><![CDATA[The compromise originated from a GitHub Actions script injection vulnerability in a workflow that improperly handled untrusted input from pull request comments. An attacker exploited this flaw to execute arbitrary commands within the CI pipeline, gaining access to the reposito...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Checkmarx KICS and Bitwarden CLI Compromised in Fresh Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/checkmarx-kics-and-bitwarden-cli-compromised-in-fresh-supply-chain-attack</link>
            <guid isPermaLink="false">351d8c76-b6ae-8018-99e2-d768cb38ef41</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Multiple malicious versions of Checkmarx projects have been published, including Docker images and VS Code extensions (this included both publishing new malicious image versions and pointing existing tags to malicious instances). This is a new incident, separate from the March...]]></description>
            <content:encoded><![CDATA[Multiple malicious versions of Checkmarx projects have been published, including Docker images and VS Code extensions (this included both publishing new malicious image versions and pointing existing tags to malicious instances). This is a new incident, separate from the March...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Xinference Compromised in Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/xinference-compromised-in-supply-chain-attack</link>
            <guid isPermaLink="false">351d8c76-b6ae-80b2-b35c-e029b9d64592</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The attackers compromised legitimate xinference releases rather than publishing a typosquat package, embedding malicious code directly into xinference/init.py. This ensures execution whenever the package is imported, including during application startup or dependency resolutio...]]></description>
            <content:encoded><![CDATA[The attackers compromised legitimate xinference releases rather than publishing a typosquat package, embedding malicious code directly into xinference/init.py. This ensures execution whenever the package is imported, including during application startup or dependency resolutio...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Context.ai OAuth Token Compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/contextai-oauth-token-compromise</link>
            <guid isPermaLink="false">351d8c76-b6ae-8048-a997-da10f4564956</guid>
            <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[On April 19th, 2026, Vercel disclosed a security incident involving unauthorized access to their internal systems. According to their incident report, the attacker compromised an employee’s Google Workspace account via a third-party AI tool named Context.ai, who have since con...]]></description>
            <content:encoded><![CDATA[On April 19th, 2026, Vercel disclosed a security incident involving unauthorized access to their internal systems. According to their incident report, the attacker compromised an employee’s Google Workspace account via a third-party AI tool named Context.ai, who have since con...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PolinRider Campaign: DPRK-Linked Supply Chain Attack Infects GitHub Repositories (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/polinrider-campaign-dprk-linked-supply-chain-attack-infects-github-repositories</link>
            <guid isPermaLink="false">351d8c76-b6ae-8046-84bc-ec5e210991cf</guid>
            <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A supply chain campaign attributed to a DPRK-linked threat actor, PolinRider, has resulted in the compromise of over 1,900 GitHub repositories through malicious npm packages, VS Code artifacts, and injected JavaScript payloads. The campaign leverages stealthy code injection an...]]></description>
            <content:encoded><![CDATA[A supply chain campaign attributed to a DPRK-linked threat actor, PolinRider, has resulted in the compromise of over 1,900 GitHub repositories through malicious npm packages, VS Code artifacts, and injected JavaScript payloads. The campaign leverages stealthy code injection an...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Stolen SaaS Integration Tokens Enable Data Theft Across Snowflake Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/stolen-saas-integration-tokens-enable-data-theft-across-snowflake-environments</link>
            <guid isPermaLink="false">351d8c76-b6ae-80e3-bfdf-e0be01280192</guid>
            <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The attack originated reportedly from a security incident affecting Anodot, a SaaS analytics and anomaly detection platform that integrates with multiple cloud services (e.g., Snowflake, S3, and streaming pipelines). Threat actors reportedly obtained authentication tokens asso...]]></description>
            <content:encoded><![CDATA[The attack originated reportedly from a security incident affecting Anodot, a SaaS analytics and anomaly detection platform that integrates with multiple cloud services (e.g., Snowflake, S3, and streaming pipelines). Threat actors reportedly obtained authentication tokens asso...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[O365 Device Code Phishing Campaign using EvilTokens and Abusing Railway Platform (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/o365-device-code-phishing-campaign-using-eviltokens-and-abusing-railway-platform</link>
            <guid isPermaLink="false">351d8c76-b6ae-80fb-8587-ca88042578f3</guid>
            <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A phishing campaign has been reported leveraging the EvilTokens Phishing-as-a-Service platform to target O365 users. The attackers use device code phishing to bypass Multi-Factor Authentication (MFA), and they also utilize Railway to host their malicious infrastructure. The ca...]]></description>
            <content:encoded><![CDATA[A phishing campaign has been reported leveraging the EvilTokens Phishing-as-a-Service platform to target O365 users. The attackers use device code phishing to bypass Multi-Factor Authentication (MFA), and they also utilize Railway to host their malicious infrastructure. The ca...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exploitation Campaign of Vulnerable GitHub Workflows (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/exploitation-campaign-of-vulnerable-github-workflows</link>
            <guid isPermaLink="false">351d8c76-b6ae-8036-8a28-f4edb7a0349e</guid>
            <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[An unknown threat actor has been conducting an opportunistic campaign of automated malicious pull requests to attempt to initiate supply chain compromise against various open source repositories. In at least two cases, the attacker has been able to inject malicious code that u...]]></description>
            <content:encoded><![CDATA[An unknown threat actor has been conducting an opportunistic campaign of automated malicious pull requests to attempt to initiate supply chain compromise against various open source repositories. In at least two cases, the attacker has been able to inject malicious code that u...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UAT-10608 Campaign Abuses React2Shell for Cloud Credential Harvesting (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/uat-10608-campaign-abuses-react2shell-for-cloud-credential-harvesting</link>
            <guid isPermaLink="false">351d8c76-b6ae-80f0-bb14-eccecc6c92c5</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[An automated campaign attributed to threat cluster UAT-10608 is exploiting vulnerable Next.js applications to achieve pre-authentication remote code execution and deploy a multi-phase credential harvesting framework. The operation has compromised hundreds of hosts across cloud...]]></description>
            <content:encoded><![CDATA[An automated campaign attributed to threat cluster UAT-10608 is exploiting vulnerable Next.js applications to achieve pre-authentication remote code execution and deploy a multi-phase credential harvesting framework. The operation has compromised hundreds of hosts across cloud...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Axios supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/axios-supply-chain-attack</link>
            <guid isPermaLink="false">339d8c76-b6ae-8044-8fb6-c4b002172341</guid>
            <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The malicious versions of axios differed from legitimate releases by including a dependency on plain-crypto-js, a trojanized package. These versions were published directly via a compromised maintainer account and later removed from npm following disclosure. Due to the short e...]]></description>
            <content:encoded><![CDATA[The malicious versions of axios differed from legitimate releases by including a dependency on plain-crypto-js, a trojanized package. These versions were published directly via a compromised maintainer account and later removed from npm following disclosure. Due to the short e...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Apifox supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/apifox-supply-chain-attack</link>
            <guid isPermaLink="false">332d8c76-b6ae-80c1-b4ec-c7fa2740c2e9</guid>
            <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The Apifox incident is a client-side supply chain attack in which attackers compromised an official CDN-hosted JavaScript resource (apifox-app-event-tracking.min.js) and injected heavily obfuscated malicious code into a trusted analytics script. Because the Apifox desktop clie...]]></description>
            <content:encoded><![CDATA[The Apifox incident is a client-side supply chain attack in which attackers compromised an official CDN-hosted JavaScript resource (apifox-app-event-tracking.min.js) and injected heavily obfuscated malicious code into a trusted analytics script. Because the Apifox desktop clie...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BuddyBoss supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/buddyboss-supply-chain-attack</link>
            <guid isPermaLink="false">339d8c76-b6ae-807b-a6fa-eb5760fbdbb1</guid>
            <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The BuddyBoss campaign (Parts 1 & 2) represents a full-spectrum software supply chain attack against the WordPress ecosystem, where the threat actor compromised the BuddyBoss plugin/theme distribution pipeline and leveraged it to infect hundreds of downstream websites. The ini...]]></description>
            <content:encoded><![CDATA[The BuddyBoss campaign (Parts 1 & 2) represents a full-spectrum software supply chain attack against the WordPress ecosystem, where the threat actor compromised the BuddyBoss plugin/theme distribution pipeline and leveraged it to infect hundreds of downstream websites. The ini...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LiteLLM supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/litellm-supply-chain-attack</link>
            <guid isPermaLink="false">32ed8c76-b6ae-8091-ab18-eabbb85c27da</guid>
            <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Malicious versions of the LiteLLM python package (1.82.7 and 1.82.8) were published on the morning of 24 March 2026. The compromised packages employed two different methods to deliver their payload. The packages were published at approximately 8:30 UTC and quarantined by PyPI ...]]></description>
            <content:encoded><![CDATA[Malicious versions of the LiteLLM python package (1.82.7 and 1.82.8) were published on the morning of 24 March 2026. The compromised packages employed two different methods to deliver their payload. The packages were published at approximately 8:30 UTC and quarantined by PyPI ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[KICS supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/kics-supply-chain-attack</link>
            <guid isPermaLink="false">32ed8c76-b6ae-801b-b77f-fd0139d5bff4</guid>
            <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The Checkmarx KICS GitHub Action was compromised by TeamPCP between 12:58 and 16:50 UTC on March 23, during which users pinning to affected tags were served credential-stealing malware before the repository was taken down. This marks the second major open source security scann...]]></description>
            <content:encoded><![CDATA[The Checkmarx KICS GitHub Action was compromised by TeamPCP between 12:58 and 16:50 UTC on March 23, during which users pinning to affected tags were served credential-stealing malware before the repository was taken down. This marks the second major open source security scann...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exploitation of S1ngularity-exposed cloud keys for lateral movement (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/exploitation-of-s1ngularity-exposed-cloud-keys-for-lateral-movement</link>
            <guid isPermaLink="false">32ed8c76-b6ae-80eb-b6be-dc88d80e9d93</guid>
            <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The UNC6426 campaign demonstrates a multi-stage supply chain intrusion that transitioned from developer environment compromise to full cloud takeover within ~72 hours. The attack originated from a prior compromise of the nx npm package, where a malicious postinstall script dep...]]></description>
            <content:encoded><![CDATA[The UNC6426 campaign demonstrates a multi-stage supply chain intrusion that transitioned from developer environment compromise to full cloud takeover within ~72 hours. The attack originated from a prior compromise of the nx npm package, where a malicious postinstall script dep...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[xygeni-action repository hijack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/xygeni-action-repository-hijack</link>
            <guid isPermaLink="false">31fd8c76-b6ae-80e0-b3d8-f70b93619195</guid>
            <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The compromise of the xygeni-action represents a CI/CD supply chain attack in which a threat actor leveraged tag poisoning to distribute a backdoored GitHub Action at scale. The attacker first gained access to the repository via compromised maintainer credentials and a GitHub ...]]></description>
            <content:encoded><![CDATA[The compromise of the xygeni-action represents a CI/CD supply chain attack in which a threat actor leveraged tag poisoning to distribute a backdoored GitHub Action at scale. The attacker first gained access to the repository via compromised maintainer credentials and a GitHub ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PolinRider supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/polinrider-supply-chain-attack</link>
            <guid isPermaLink="false">31fd8c76-b6ae-80fc-99dd-f71a373a5e0d</guid>
            <pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The PolinRider campaign represents a highly automated software supply chain attack in which a threat actor—assessed to be DPRK-linked—leveraged a compromised developer environment to achieve large-scale propagation across GitHub repositories. The initial access vector was a tr...]]></description>
            <content:encoded><![CDATA[The PolinRider campaign represents a highly automated software supply chain attack in which a threat actor—assessed to be DPRK-linked—leveraged a compromised developer environment to achieve large-scale propagation across GitHub repositories. The initial access vector was a tr...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LexisNexis breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/lexisnexis-breach</link>
            <guid isPermaLink="false">319d8c76-b6ae-80fc-85ee-de4863d959a4</guid>
            <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[LexisNexis confirmed a cloud-based data breach after threat actor FulcrumSec leaked ~2GB of stolen data. The attacker exploited an unpatched React2Shell vulnerability in a frontend application to gain access to the company’s AWS environment, leading to large-scale data exfiltr...]]></description>
            <content:encoded><![CDATA[LexisNexis confirmed a cloud-based data breach after threat actor FulcrumSec leaked ~2GB of stolen data. The attacker exploited an unpatched React2Shell vulnerability in a frontend application to gain access to the company’s AWS environment, leading to large-scale data exfiltr...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Trivy supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/trivy-supply-chain-attack</link>
            <guid isPermaLink="false">319d8c76-b6ae-80be-a64f-e4986d24cd9c</guid>
            <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[On March 19, 2026, Aqua Security’s Trivy was compromised in a follow-on incident attributed to unrotated credentials from a prior breach. Attackers pushed spoofed commits to both actions/checkout and aquasecurity/trivy, triggering the release of a malicious v0.69.4 version tha...]]></description>
            <content:encoded><![CDATA[On March 19, 2026, Aqua Security’s Trivy was compromised in a follow-on incident attributed to unrotated credentials from a prior breach. Attackers pushed spoofed commits to both actions/checkout and aquasecurity/trivy, triggering the release of a malicious v0.69.4 version tha...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SANDWORM_MODE: Typosquatted npm Packages Used to Hijack CI Workflows (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sandwormmode-typosquatted-npm-packages-used-to-hijack-ci-workflows</link>
            <guid isPermaLink="false">310d8c76-b6ae-8031-89f2-ec56d27c7286</guid>
            <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[According to Socket, the campaign operates as a typosquatting worm: the attacker publishes malicious packages that mimic trusted names (e.g., look-alikes of common utilities and AI coding tools). When one of these malicious packages is installed and imported, it executes a sta...]]></description>
            <content:encoded><![CDATA[According to Socket, the campaign operates as a typosquatting worm: the attacker publishes malicious packages that mimic trusted names (e.g., look-alikes of common utilities and AI coding tools). When one of these malicious packages is installed and imported, it executes a sta...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SSHStalker Linux Botnet campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sshstalker-linux-botnet-campaign</link>
            <guid isPermaLink="false">306d8c76-b6ae-8076-958a-f60a3023e801</guid>
            <pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2026-02-09, a campaign was reported, involving SSHStalker, gaining initial access via Password attack, to achieve Resource hijacking, Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2026-02-09, a campaign was reported, involving SSHStalker, gaining initial access via Password attack, to achieve Resource hijacking, Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TeamPCP Cloud-Native Campaign Targeting Exposed Control Planes (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/teampcp-cloud-native-campaign-targeting-exposed-control-planes</link>
            <guid isPermaLink="false">302d8c76-b6ae-80b8-9780-e9f593dd004e</guid>
            <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[TeamPCP’s operations center on abusing unauthenticated or weakly protected orchestration and management interfaces rather than exploiting traditional endpoints. Initial access is achieved via exposed Docker and Kubernetes APIs, vulnerable React/Next.js applications (CVE-2025-2...]]></description>
            <content:encoded><![CDATA[TeamPCP’s operations center on abusing unauthenticated or weakly protected orchestration and management interfaces rather than exploiting traditional endpoints. Initial access is achieved via exposed Docker and Kubernetes APIs, vulnerable React/Next.js applications (CVE-2025-2...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-hijacking-of-notepad-updates-via-hosting-provider-compromise</link>
            <guid isPermaLink="false">2fbd8c76-b6ae-8032-b3e5-f4a10d310524</guid>
            <pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Between June and late 2025, threat actors compromised the shared hosting infrastructure used by Notepad++ and selectively hijacked update traffic destined for notepad-plus-plus.org. Rather than exploiting a vulnerability in Notepad++ code, the attackers abused access at the ho...]]></description>
            <content:encoded><![CDATA[Between June and late 2025, threat actors compromised the shared hosting infrastructure used by Notepad++ and selectively hijacked update traffic destined for notepad-plus-plus.org. Rather than exploiting a vulnerability in Notepad++ code, the attackers abused access at the ho...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply-Chain Attack via Force Pushes on Plone GitHub Repositories (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-attack-via-force-pushes-on-plone-github-repositories</link>
            <guid isPermaLink="false">2fbd8c76-b6ae-8045-a92f-f9c1ae59f17b</guid>
            <pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[In January 2026, the Plone security team disclosed a security incident affecting the Plone GitHub organization, in which an attacker used force pushes to insert malicious JavaScript code into multiple repositories. The activity was traced back to a compromised contributor acco...]]></description>
            <content:encoded><![CDATA[In January 2026, the Plone security team disclosed a security incident affecting the Plone GitHub organization, in which an attacker used force pushes to insert malicious JavaScript code into multiple repositories. The activity was traced back to a compromised contributor acco...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Operation Bizarre Bazaar: Commercialized LLMjacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/operation-bizarre-bazaar-commercialized-llmjacking</link>
            <guid isPermaLink="false">2fad8c76-b6ae-800c-b106-f7619cc206a9</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Between December 2025 and January 2026, researchers uncovered a large-scale, systematic campaign targeting exposed large language model (LLM) and Model Context Protocol (MCP) infrastructure. Dubbed Operation Bizarre Bazaar, the activity represents the first publicly documented...]]></description>
            <content:encoded><![CDATA[Between December 2025 and January 2026, researchers uncovered a large-scale, systematic campaign targeting exposed large language model (LLM) and Model Context Protocol (MCP) infrastructure. Dubbed Operation Bizarre Bazaar, the activity represents the first publicly documented...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cloud-Native Phishing Infrastructure via Abused AWS WorkMail (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cloud-native-phishing-infrastructure-via-abused-aws-workmail</link>
            <guid isPermaLink="false">2fad8c76-b6ae-80b3-a994-d924953b0fcd</guid>
            <pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Threat actors abused native AWS email services to build phishing and spam infrastructure inside a compromised cloud environment. After obtaining exposed long-term AWS credentials, the attackers conducted IAM and service reconnaissance to assess email-sending capabilities. Whil...]]></description>
            <content:encoded><![CDATA[Threat actors abused native AWS email services to build phishing and spam infrastructure inside a compromised cloud environment. After obtaining exposed long-term AWS credentials, the attackers conducted IAM and service reconnaissance to assess email-sending capabilities. Whil...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Canonical Snap Store Hijacking Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/canonical-snap-store-hijacking-campaign</link>
            <guid isPermaLink="false">2fad8c76-b6ae-80df-931f-cf5544306009</guid>
            <pubDate>Sat, 17 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2026-01-17, a campaign was reported, involving an unknown actor, gaining initial access via Dangling resource,.]]></description>
            <content:encoded><![CDATA[On 2026-01-17, a campaign was reported, involving an unknown actor, gaining initial access via Dangling resource,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[VoidLink: A Cloud-Native Linux Malware Framework (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/voidlink-a-cloud-native-linux-malware-framework</link>
            <guid isPermaLink="false">2ecd8c76-b6ae-8063-8775-d58371e78375</guid>
            <pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers have uncovered VoidLink, a highly modular and cloud-native Linux malware framework featuring custom loaders, implants, kernel-level rootkits, and more than 30 in-memory plugins. Built in Zig and engineered for modern cloud and containerized environments, VoidLink a...]]></description>
            <content:encoded><![CDATA[Researchers have uncovered VoidLink, a highly modular and cloud-native Linux malware framework featuring custom loaders, implants, kernel-level rootkits, and more than 30 in-memory plugins. Built in Zig and engineered for modern cloud and containerized environments, VoidLink a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/geoserver-rce-exploited-in-coinminer-campaigns</link>
            <guid isPermaLink="false">2e6d8c76-b6ae-80b3-bf60-c2ae2796e3c8</guid>
            <pubDate>Fri, 26 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The activity centers on CVE-2024-36401, a remote code execution vulnerability disclosed in 2024 that allows unauthenticated attackers to execute arbitrary commands on vulnerable GeoServer instances. Since disclosure, multiple threat actors have systematically scanned for expos...]]></description>
            <content:encoded><![CDATA[The activity centers on CVE-2024-36401, a remote code execution vulnerability disclosed in 2024 that allows unauthenticated attackers to execute arbitrary commands on vulnerable GeoServer instances. Since disclosure, multiple threat actors have systematically scanned for expos...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Amadey Loader Abuses Compromised Self-Hosted GitLab to Deliver StealC Infostealer (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/amadey-loader-abuses-compromised-self-hosted-gitlab-to-deliver-stealc-infostealer</link>
            <guid isPermaLink="false">2d0d8c76-b6ae-804d-ba9f-f8a8a29ad5b5</guid>
            <pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Amadey, an established malware loader active since at least 2018, was observed downloading second-stage payloads from a hijacked self-hosted GitLab instance hosted on gitlab[.]bzctoons[.]net. The infrastructure appears to belong to a legitimate organization, with evidence sugg...]]></description>
            <content:encoded><![CDATA[Amadey, an established malware loader active since at least 2018, was observed downloading second-stage payloads from a hijacked self-hosted GitLab instance hosted on gitlab[.]bzctoons[.]net. The infrastructure appears to belong to a legitimate organization, with evidence sugg...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[China-nexus Campaign Exploits CVE-2025-20393 in Cisco Email Security Devices (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/china-nexus-campaign-exploits-cve-2025-20393-in-cisco-email-security-devices</link>
            <guid isPermaLink="false">2d0d8c76-b6ae-80db-be6d-d680c375f0b6</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On December 17, 2025 Cisco announced that they had detected a campaign exploiting a zero day in their email security devices. The vulnerability affects the physical and virtual versions of Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and ...]]></description>
            <content:encoded><![CDATA[On December 17, 2025 Cisco announced that they had detected a campaign exploiting a zero day in their email security devices. The vulnerability affects the physical and virtual versions of Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Shai-Hulud 2.0 Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/shai-hulud-20-supply-chain-attack</link>
            <guid isPermaLink="false">2bbd8c76-b6ae-8012-8da2-e1692c2e9c20</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A new wave of the Shai-Hulud–style supply-chain attack has trojanized hundreds of npm packages—including widely used components from Zapier, ENS Domains, PostHog, and Postman—resulting in more than 25,000 GitHub repositories populated with stolen secrets. Beginning on November...]]></description>
            <content:encoded><![CDATA[A new wave of the Shai-Hulud–style supply-chain attack has trojanized hundreds of npm packages—including widely used components from Zapier, ENS Domains, PostHog, and Postman—resulting in more than 25,000 GitHub repositories populated with stolen secrets. Beginning on November...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cryptomining Campaign Exploiting Exposed Ray AI Infrastructure (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cryptomining-campaign-exploiting-exposed-ray-ai-infrastructure</link>
            <guid isPermaLink="false">2b0d8c76-b6ae-8061-9ddf-eaecac5aac84</guid>
            <pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[ShadowRay 2.0 targets Ray clusters whose dashboard / Jobs API is exposed without authentication. Attackers first use interact.sh (oast.fun) for out-of-band discovery, posting test jobs to /api/jobs/ that trigger HTTP/DNS callbacks to identify exploitable Ray dashboards. Once a...]]></description>
            <content:encoded><![CDATA[ShadowRay 2.0 targets Ray clusters whose dashboard / Jobs API is exposed without authentication. Attackers first use interact.sh (oast.fun) for out-of-band discovery, posting test jobs to /api/jobs/ that trigger HTTP/DNS callbacks to identify exploitable Ray dashboards. Once a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cisco ISE Vulnerability Exploited as 0day by APT (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cisco-ise-vulnerability-exploited-as-0day-by-apt</link>
            <guid isPermaLink="false">2aad8c76-b6ae-80e5-bf97-c1a0a9d5e10b</guid>
            <pubDate>Thu, 13 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered an advanced persistent threat (APT) exploiting zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems (CitrixBleed2). The vulnerabilities, tracked as CVE-2025-20337 and CVE-2025-5777, were leveraged by the attackers to deploy ...]]></description>
            <content:encoded><![CDATA[Researchers uncovered an advanced persistent threat (APT) exploiting zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems (CitrixBleed2). The vulnerabilities, tracked as CVE-2025-20337 and CVE-2025-5777, were leveraged by the attackers to deploy ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unauthenticated-remote-access-via-triofox-vulnerability-exploited-by-unc6485</link>
            <guid isPermaLink="false">2add8c76-b6ae-8028-b81d-dd67d6ea0a21</guid>
            <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered active exploitation of an unauthenticated access vulnerability (CVE-2025-12480) in Gladinet’s Triofox remote access platform by the threat cluster UNC6485. The flaw, present in versions before 16.7.10368.56560, allowed attackers to bypass authentication u...]]></description>
            <content:encoded><![CDATA[Researchers uncovered active exploitation of an unauthenticated access vulnerability (CVE-2025-12480) in Gladinet’s Triofox remote access platform by the threat cluster UNC6485. The flaw, present in versions before 16.7.10368.56560, allowed attackers to bypass authentication u...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gambling Network Exploits Abandoned Subdomains (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gambling-network-exploits-abandoned-subdomains</link>
            <guid isPermaLink="false">2add8c76-b6ae-807c-9cf1-ceac0aa19893</guid>
            <pubDate>Tue, 11 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A routine asset scan for a major entertainment company uncovered a massive gambling operation hiding behind legitimate e-commerce infrastructure. The discovery began with a simple subdomain takeover on Shopify-an abandoned DNS mapping that had been left active after decommissi...]]></description>
            <content:encoded><![CDATA[A routine asset scan for a major entertainment company uncovered a massive gambling operation hiding behind legitimate e-commerce infrastructure. The discovery began with a simple subdomain takeover on Shopify-an abandoned DNS mapping that had been left active after decommissi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[China-Linked Actors Target U.S. Policy-Oriented Non-Profit Organisations (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/china-linked-actors-target-us-policy-oriented-non-profit-organisations</link>
            <guid isPermaLink="false">2aad8c76-b6ae-80a9-8204-f5135fea22e1</guid>
            <pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A China-linked espionage campaign targeted a U.S. non-profit organization engaged in influencing government policy, maintaining weeks of access in April 2025. The intrusion leveraged legitimate binaries for DLL sideloading and persistence, consistent with techniques observed i...]]></description>
            <content:encoded><![CDATA[A China-linked espionage campaign targeted a U.S. non-profit organization engaged in influencing government policy, maintaining weeks of access in April 2025. The intrusion leveraged legitimate binaries for DLL sideloading and persistence, consistent with techniques observed i...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TruffleNet Campaign Exploits AWS SES for Large-Scale Cloud Abuse and BEC Fraud (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/trufflenet-campaign-exploits-aws-ses-for-large-scale-cloud-abuse-and-bec-fraud</link>
            <guid isPermaLink="false">2aad8c76-b6ae-8062-9bb7-fa142dd164d0</guid>
            <pubDate>Fri, 31 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a coordinated campaign leveraging stolen AWS credentials to automate reconnaissance and abuse Amazon Simple Email Service (SES) for Business Email Compromise (BEC) operations. The attackers used a custom infrastructure dubbed TruffleNet, built around the ...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a coordinated campaign leveraging stolen AWS credentials to automate reconnaissance and abuse Amazon Simple Email Service (SES) for Business Email Compromise (BEC) operations. The attackers used a custom infrastructure dubbed TruffleNet, built around the ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Tata Motors Hardcoded AWS Keys and API Tokens Exposed  (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/tata-motors-hardcoded-aws-keys-and-api-tokens-exposed-</link>
            <guid isPermaLink="false">29bd8c76-b6ae-8064-a285-c882636315b2</guid>
            <pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Security researcher Eaton Zveare disclosed that in 2023 multiple public-facing Tata Motors applications (notably the E-Dukaan marketplace and the FleetEdge fleet product) contained hardcoded or client-recoverable cloud credentials and API tokens that allowed access to hundreds...]]></description>
            <content:encoded><![CDATA[Security researcher Eaton Zveare disclosed that in 2023 multiple public-facing Tata Motors applications (notably the E-Dukaan marketplace and the FleetEdge fleet product) contained hardcoded or client-recoverable cloud credentials and API tokens that allowed access to hundreds...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[IIS Backdoor Exploiting Exposed ASP.NET Machine Keys (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/iis-backdoor-exploiting-exposed-aspnet-machine-keys</link>
            <guid isPermaLink="false">299d8c76-b6ae-80f6-b518-f6bac5cfedbd</guid>
            <pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Initial access leverages IIS apps configured with reused/public machineKey (ValidationKey/DecryptionKey) values, enabling __VIEWSTATE deserialization to run arbitrary commands. Following foothold, REF3927 deploys Godzilla-family webshells (e.g., 1.aspx) and GotoHTTP for GUI ac...]]></description>
            <content:encoded><![CDATA[Initial access leverages IIS apps configured with reused/public machineKey (ValidationKey/DecryptionKey) values, enabling __VIEWSTATE deserialization to run arbitrary commands. Following foothold, REF3927 deploys Godzilla-family webshells (e.g., 1.aspx) and GotoHTTP for GUI ac...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PassiveNeuron Campaign: Espionage Campaign Targeting Windows Server Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/passiveneuron-campaign-espionage-campaign-targeting-windows-server-environments</link>
            <guid isPermaLink="false">299d8c76-b6ae-80b0-b59f-e626db2041bd</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Attackers obtain remote code execution through abuse of SQL-server environments (exploitation, SQL injection, or credential compromise) and attempt to install web shells. When detection (e.g., endpoint AV) blocks the web-shell stage they escalate to a multi-stage DLL loader ch...]]></description>
            <content:encoded><![CDATA[Attackers obtain remote code execution through abuse of SQL-server environments (exploitation, SQL injection, or credential compromise) and attempt to install web shells. When detection (e.g., endpoint AV) blocks the web-shell stage they escalate to a multi-stage DLL loader ch...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[F5 incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/f5-incident</link>
            <guid isPermaLink="false">299d8c76-b6ae-80bf-ae50-cf39e324dcb0</guid>
            <pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[F5 disclosed a security incident in which a nation-state threat actor maintained persistent access to the company’s internal systems, including its BIG-IP product development and engineering knowledge management environments. The actor exfiltrated source code and information a...]]></description>
            <content:encoded><![CDATA[F5 disclosed a security incident in which a nation-state threat actor maintained persistent access to the company’s internal systems, including its BIG-IP product development and engineering knowledge management environments. The actor exfiltrated source code and information a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[eBPF Rootkit Targeting AWS and Linux Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ebpf-rootkit-targeting-aws-and-linux-environments</link>
            <guid isPermaLink="false">28dd8c76-b6ae-807d-a929-d8f036db0bf1</guid>
            <pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The infection began with the exploitation of a vulnerable Jenkins server (CVE-2024-238976), which enabled lateral movement into AWS EKS clusters. The threat actor deployed a malicious Docker image (kvlnt/vv) containing a Rust-based downloader (vGet) that retrieved an encrypted...]]></description>
            <content:encoded><![CDATA[The infection began with the exploitation of a vulnerable Jenkins server (CVE-2024-238976), which enabled lateral movement into AWS EKS clusters. The threat actor deployed a malicious Docker image (kvlnt/vv) containing a Rust-based downloader (vGet) that retrieved an encrypted...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Risk in Axis Autodesk Revit Plugin Due to Exposed Azure Storage Credentials and Revit RCE Vulnerabilities (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-risk-in-axis-autodesk-revit-plugin-due-to-exposed-azure-storage-credentials-and-revit-rce-vulnerabilities</link>
            <guid isPermaLink="false">293d8c76-b6ae-807b-90b3-d12ba895c17a</guid>
            <pubDate>Wed, 08 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[researchers uncovered exposed Azure Storage Account credentials embedded in Axis Communications’ Autodesk Revit plugin, enabling unauthorized read/write access to cloud-hosted installers and RFA model files. When combined with multiple remote-code-execution (RCE) vulnerabiliti...]]></description>
            <content:encoded><![CDATA[researchers uncovered exposed Azure Storage Account credentials embedded in Axis Communications’ Autodesk Revit plugin, enabling unauthorized read/write access to cloud-hosted installers and RFA model files. When combined with multiple remote-code-execution (RCE) vulnerabiliti...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[“Crimson Collective” Claims Theft of Customer Data from Red Hat (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/crimson-collective-claims-theft-of-customer-data-from-red-hat</link>
            <guid isPermaLink="false">287d8c76-b6ae-8070-adfd-e95cb069278e</guid>
            <pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[An extortion group calling themselves "Crimson Collective" has claimed to have stolen nearly 570 GB of data from Red Hat's private GitLab repositories. Red Hat confirmed a security incident to BleepingComputer, saying "Red Hat is aware of reports regarding a security incident ...]]></description>
            <content:encoded><![CDATA[An extortion group calling themselves "Crimson Collective" has claimed to have stolen nearly 570 GB of data from Red Hat's private GitLab repositories. Red Hat confirmed a security incident to BleepingComputer, saying "Red Hat is aware of reports regarding a security incident ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cl0p Extortion Campaign Claims Theft via Oracle E-Business Suite (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cl0p-extortion-campaign-claims-theft-via-oracle-e-business-suite</link>
            <guid isPermaLink="false">287d8c76-b6ae-80e9-887b-c312a6844452</guid>
            <pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In an October 1st Bloomberg article, Halcyon, a cybersecurity company responding to a related incident, has stated that the attackers gained access to the data by compromising user emails and abusing the default password-reset function. On October 2nd, Oracle posted a statemen...]]></description>
            <content:encoded><![CDATA[In an October 1st Bloomberg article, Halcyon, a cybersecurity company responding to a related incident, has stated that the attackers gained access to the data by compromising user emails and abusing the default password-reset function. On October 2nd, Oracle posted a statemen...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Renewed "ArcaneDoor" Campaign Targeting 0-day Vulnerabilities in Cisco ASA (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/renewed-arcanedoor-campaign-targeting-0-day-vulnerabilities-in-cisco-asa</link>
            <guid isPermaLink="false">27ed8c76-b6ae-80c6-89f9-e27fb83bbd85</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Cisco has reported exploitation in the wild of two 0-day vulnerabilities affecting Cisco Adaptive Security Appliance (ASA), CVE-2025-20333 and CVE-2025-20362, allowing RCE and local privilege escalation, respectively. NCSC and CISA have corroborated these reports, noting the u...]]></description>
            <content:encoded><![CDATA[Cisco has reported exploitation in the wild of two 0-day vulnerabilities affecting Cisco Adaptive Security Appliance (ASA), CVE-2025-20333 and CVE-2025-20362, allowing RCE and local privilege escalation, respectively. NCSC and CISA have corroborated these reports, noting the u...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BRICKSTORM Espionage Backdoor Targeting U.S. Tech and Legal Sectors (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/brickstorm-espionage-backdoor-targeting-us-tech-and-legal-sectors</link>
            <guid isPermaLink="false">27ed8c76-b6ae-80a2-bcdf-cbfbf1dbf5f7</guid>
            <pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[BRICKSTORM is a Go backdoor (with SOCKS proxying) deployed preferentially on Linux/BSD network and edge appliances that often lack EDR coverage. Attackers favor devices like VMware vCenter/ESXi as pivot points, using valid credentials harvested from appliances to move laterall...]]></description>
            <content:encoded><![CDATA[BRICKSTORM is a Go backdoor (with SOCKS proxying) deployed preferentially on Linux/BSD network and edge appliances that often lack EDR coverage. Attackers favor devices like VMware vCenter/ESXi as pivot points, using valid credentials harvested from appliances to move laterall...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SonicWall MySonicWall Cloud Backup File Security Incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sonicwall-mysonicwall-cloud-backup-file-security-incident</link>
            <guid isPermaLink="false">27ed8c76-b6ae-8060-80ba-fb584554310a</guid>
            <pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[SonicWall has disclosed a security incident affecting its MySonicWall cloud backup service. Threat actors conducted brute force attacks on the MySonicWall.com portal and gained unauthorized access to a subset of firewall preference files. While fewer than 5% of firewall instal...]]></description>
            <content:encoded><![CDATA[SonicWall has disclosed a security incident affecting its MySonicWall cloud backup service. Threat actors conducted brute force attacks on the MySonicWall.com portal and gained unauthorized access to a subset of firewall preference files. While fewer than 5% of firewall instal...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Shai-Hulud: Ongoing Package Supply Chain Compromise Delivering Data-Stealing Malware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/shai-hulud-ongoing-package-supply-chain-compromise-delivering-data-stealing-malware</link>
            <guid isPermaLink="false">27ed8c76-b6ae-8073-aad7-d331ca08806c</guid>
            <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On September 15, 2025, malicious versions of multiple popular packages were published to npm with a post-install script that harvested sensitive developer assets and exfiltrated data to attacker-created public GitHub repos named Shai-Hulud. Wiz Research estimates that this act...]]></description>
            <content:encoded><![CDATA[On September 15, 2025, malicious versions of multiple popular packages were published to npm with a post-install script that harvested sensitive developer assets and exfiltrated data to attacker-created public GitHub repos named Shai-Hulud. Wiz Research estimates that this act...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Qix npm package supply chain compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/qix-npm-package-supply-chain-compromise</link>
            <guid isPermaLink="false">26fd8c76-b6ae-8072-83c0-e2309c1f3807</guid>
            <pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On September 8, 2025, malicious new versions of 18 popular npm packages maintained by a developer known as Qix (incl. debug@4.4.2, chalk@5.6.1) were published to npm. If those versions were pulled into a frontend build and served to users, the injected code runs in the browser...]]></description>
            <content:encoded><![CDATA[On September 8, 2025, malicious new versions of 18 popular npm packages maintained by a developer known as Qix (incl. debug@4.4.2, chalk@5.6.1) were published to npm. If those versions were pulled into a frontend build and served to users, the injected code runs in the browser...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GhostAction campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ghostaction-campaign</link>
            <guid isPermaLink="false">26fd8c76-b6ae-8011-be81-cb57e6d7dcaf</guid>
            <pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On September 5, 2025, GitGuardian reported a campaign titled "GhostAction": attackers with write access to GitHub repositories - gained by an unknown initial access vector - added a malicious GitHub Actions workflow that exfiltrates CI/CD secrets via HTTP POST to an attacker-c...]]></description>
            <content:encoded><![CDATA[On September 5, 2025, GitGuardian reported a campaign titled "GhostAction": attackers with write access to GitHub repositories - gained by an unknown initial access vector - added a malicious GitHub Actions workflow that exfiltrates CI/CD secrets via HTTP POST to an attacker-c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Compromised Salesloft Drift Tokens Enable Data Theft Across Integrations (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/compromised-salesloft-drift-tokens-enable-data-theft-across-integrations</link>
            <guid isPermaLink="false">27ed8c76-b6ae-80ae-928d-fdff278aade7</guid>
            <pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Google Threat Intelligence Group report a widespread data-theft campaign abusing OAuth tokens tied to Salesloft Drift. Initially observed against Salesforce orgs (Aug 8–18, 2025), the scope now includes other Drift integrations: on Aug 9, a small number of Google Workspace mai...]]></description>
            <content:encoded><![CDATA[Google Threat Intelligence Group report a widespread data-theft campaign abusing OAuth tokens tied to Salesloft Drift. Initially observed against Salesforce orgs (Aug 8–18, 2025), the scope now includes other Drift integrations: on Aug 9, a small number of Google Workspace mai...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Storm-0501 Deploys Cloud-Based Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/storm-0501-deploys-cloud-based-ransomware</link>
            <guid isPermaLink="false">25dd8c76-b6ae-807a-a9b5-fff42023b60b</guid>
            <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[After attaining domain admin on-prem, Storm-0501 evaded visibility gaps (checking Defender services), moved laterally with Evil-WinRM, and performed DCSync. They compromised Entra Connect Sync servers, used the Directory Synchronization Account (DSA) to enumerate identities/re...]]></description>
            <content:encoded><![CDATA[After attaining domain admin on-prem, Storm-0501 evaded visibility gaps (checking Defender services), moved laterally with Evil-WinRM, and performed DCSync. They compromised Entra Connect Sync servers, used the Directory Synchronization Account (DSA) to enumerate identities/re...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Nx Package Supply Chain Compromise Delivers Data-Stealing Malware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/nx-package-supply-chain-compromise-delivers-data-stealing-malware</link>
            <guid isPermaLink="false">25cd8c76-b6ae-8050-8fff-e7770e4ebc49</guid>
            <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The compromise introduced a malicious telemetry.js file triggered via a post-install script in the npm package. The payload executed only on Linux and macOS systems, systematically searching for sensitive files (wallets, keystores, .env, SSH keys) and extracting credentials (g...]]></description>
            <content:encoded><![CDATA[The compromise introduced a malicious telemetry.js file triggered via a post-install script in the npm package. The payload executed only on Linux and macOS systems, systematically searching for sensitive files (wallets, keystores, .env, SSH keys) and extracting credentials (g...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GENESIS PANDA's Cloud Intrusions: Persistent Control Plane Exploitation and Access Brokerage (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/genesis-pandas-cloud-intrusions-persistent-control-plane-exploitation-and-access-brokerage</link>
            <guid isPermaLink="false">25ad8c76-b6ae-808e-a03d-d84478c35821</guid>
            <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[GENESIS PANDA begins attacks by exploiting exposed services (e.g., Jenkins) and querying Instance Metadata Services (IMDS) on compromised cloud-hosted VMs to harvest credentials. With this access, the actor pivots into the cloud control plane, enabling actions like SSH access ...]]></description>
            <content:encoded><![CDATA[GENESIS PANDA begins attacks by exploiting exposed services (e.g., Jenkins) and querying Instance Metadata Services (IMDS) on compromised cloud-hosted VMs to harvest credentials. With this access, the actor pivots into the cloud control plane, enabling actions like SSH access ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Silk Typhoon Exploiting Trusted Relationships for Cloud Environments Compromise (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/silk-typhoon-exploiting-trusted-relationships-for-cloud-environments-compromise</link>
            <guid isPermaLink="false">25ad8c76-b6ae-8073-ac92-ff72def5951d</guid>
            <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Silk Typhoon (a.k.a Murky Panda) achieves initial access primarily through exploiting internet-facing appliances (e.g., Citrix NetScaler ADC, CVE-2023-3519) and has also been observed compromising SOHO devices to mask activity. Once inside, the adversary deploys web shells suc...]]></description>
            <content:encoded><![CDATA[Silk Typhoon (a.k.a Murky Panda) achieves initial access primarily through exploiting internet-facing appliances (e.g., Citrix NetScaler ADC, CVE-2023-3519) and has also been observed compromising SOHO devices to mask activity. Once inside, the adversary deploys web shells suc...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Salesloft Drift supply chain compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/salesloft-drift-supply-chain-compromise</link>
            <guid isPermaLink="false">26fd8c76-b6ae-808c-86bd-c7f600b6f642</guid>
            <pubDate>Thu, 21 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2025-08-21, an incident was reported, involving UNC6395, gaining initial access via Unknown, to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2025-08-21, an incident was reported, involving UNC6395, gaining initial access via Unknown, to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Warlock Ransomware Exploiting Sharepoint Vulnerabilities  (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/warlock-ransomware-exploiting-sharepoint-vulnerabilities-</link>
            <guid isPermaLink="false">256d8c76-b6ae-8079-8d28-de82f49eb40a</guid>
            <pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Warlock ransomware is exploiting Microsoft SharePoint vulnerabilities to infiltrate enterprise environments. Attackers gain initial access by uploading web shells through targeted HTTP POST requests, then escalate privileges via Group Policy abuse and compromised accounts. The...]]></description>
            <content:encoded><![CDATA[Warlock ransomware is exploiting Microsoft SharePoint vulnerabilities to infiltrate enterprise environments. Attackers gain initial access by uploading web shells through targeted HTTP POST requests, then escalate privileges via Group Policy abuse and compromised accounts. The...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DripDropper Malware Exploits Patched Apache ActiveMQ for Persistence on Cloud Linux Systems (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dripdropper-malware-exploits-patched-apache-activemq-for-persistence-on-cloud-linux-systems</link>
            <guid isPermaLink="false">261d8c76-b6ae-80ef-80ea-ce1eb0f3bbd0</guid>
            <pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The attack chain begins with exploitation of the Apache ActiveMQ RCE vulnerability (CVE-2023-46604) on cloud Linux hosts. Upon gaining access, the attacker installs the Sliver C2 implant and modifies sshd settings to permit root login over SSH, then downloads and executes the ...]]></description>
            <content:encoded><![CDATA[The attack chain begins with exploitation of the Apache ActiveMQ RCE vulnerability (CVE-2023-46604) on cloud Linux hosts. Upon gaining access, the attacker installs the Sliver C2 implant and modifies sshd settings to permit root login over SSH, then downloads and executes the ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UAT-7237 Targets Taiwanese Web Infrastructure Using Customized Open-Source Tools (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/uat-7237-targets-taiwanese-web-infrastructure-using-customized-open-source-tools</link>
            <guid isPermaLink="false">254d8c76-b6ae-805e-bfaf-eb577f757b5a</guid>
            <pubDate>Mon, 18 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a sophisticated intrusion by UAT-7237, a Chinese-speaking APT group active since at least 2022 and likely a subgroup of UAT-5918. The group recently compromised a Taiwanese web hosting provider, targeting its VPN and cloud infrastructure. Unlike its paren...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a sophisticated intrusion by UAT-7237, a Chinese-speaking APT group active since at least 2022 and likely a subgroup of UAT-5918. The group recently compromised a Taiwanese web hosting provider, targeting its VPN and cloud infrastructure. Unlike its paren...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Akira Ransomware Targeting Critical Vulnerability in SonicWall SSLVPN (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/akira-ransomware-targeting-critical-vulnerability-in-sonicwall-sslvpn</link>
            <guid isPermaLink="false">248d8c76-b6ae-80d9-8376-e2e2280ce5da</guid>
            <pubDate>Wed, 06 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified active exploitation of CVE-2024-40766 in SonicWall's seventh-generation firewalls, specifically impacting SSL VPN functionality. Threat actors are bypassing multi-factor authentication (MFA), gaining privileged access, and deploying Akira ransomware. The...]]></description>
            <content:encoded><![CDATA[Researchers identified active exploitation of CVE-2024-40766 in SonicWall's seventh-generation firewalls, specifically impacting SSL VPN functionality. Threat actors are bypassing multi-factor authentication (MFA), gaining privileged access, and deploying Akira ransomware. The...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Plague PAM-Based Backdoor for Linux (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/plague-pam-based-backdoor-for-linux</link>
            <guid isPermaLink="false">246d8c76-b6ae-80a5-9821-e7269f0734b7</guid>
            <pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A newly discovered Linux backdoor, dubbed Plague, was embedded as a malicious PAM (Pluggable Authentication Module) component. Designed to silently bypass system authentication, Plague grants attackers persistent SSH access while evading all known antivirus detection and leavi...]]></description>
            <content:encoded><![CDATA[A newly discovered Linux backdoor, dubbed Plague, was embedded as a malicious PAM (Pluggable Authentication Module) component. Designed to silently bypass system authentication, Plague grants attackers persistent SSH access while evading all known antivirus detection and leavi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Auto-Color Malware Exploits SAP Vulnerability for  Linux Backdoor (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/auto-color-malware-exploits-sap-vulnerability-for--linux-backdoor</link>
            <guid isPermaLink="false">254d8c76-b6ae-80cf-9165-d3018086facc</guid>
            <pubDate>Tue, 29 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In April 2025, a threat actor exploited CVE-2025-31324, a critical vulnerability in SAP NetWeaver, to deploy the Auto-Color backdoor malware on a US-based chemical company's network. The intrusion began with suspicious ZIP file downloads and DNS tunneling to test exploitabilit...]]></description>
            <content:encoded><![CDATA[In April 2025, a threat actor exploited CVE-2025-31324, a critical vulnerability in SAP NetWeaver, to deploy the Auto-Color backdoor malware on a US-based chemical company's network. The intrusion began with suspicious ZIP file downloads and DNS tunneling to test exploitabilit...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AWS CodeBuild Vulnerability Allows Build Process Secrets Extraction (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/aws-codebuild-vulnerability-allows-build-process-secrets-extraction</link>
            <guid isPermaLink="false">246d8c76-b6ae-809e-92fa-c7213e688c11</guid>
            <pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The vulnerability in AWS CodeBuild arises when a source code repository is configured to trigger builds based on pull requests or other actions from untrusted contributors. In such cases, an attacker can submit a pull request containing arbitrary code, which is then executed i...]]></description>
            <content:encoded><![CDATA[The vulnerability in AWS CodeBuild arises when a source code repository is configured to trigger builds based on pull requests or other actions from untrusted contributors. In such cases, an attacker can submit a pull request containing arbitrary code, which is then executed i...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Soco404 Cryptomining Campaign Exploits PostgreSQL and Cloud Misconfigurations (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/soco404-cryptomining-campaign-exploits-postgresql-and-cloud-misconfigurations</link>
            <guid isPermaLink="false">23ad8c76-b6ae-8049-b341-c6f1835de160</guid>
            <pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research has uncovered an ongoing, sophisticated cryptomining campaign dubbed Soco404, which targets both Linux and Windows systems in cloud environments. The campaign exploits exposed PostgreSQL instances and vulnerable Apache Tomcat servers to achieve initial access, the...]]></description>
            <content:encoded><![CDATA[Wiz Research has uncovered an ongoing, sophisticated cryptomining campaign dubbed Soco404, which targets both Linux and Windows systems in cloud environments. The campaign exploits exposed PostgreSQL instances and vulnerable Apache Tomcat servers to achieve initial access, the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mimo Targets Magento, Docker, and Cloud Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mimo-targets-magento-docker-and-cloud-environments</link>
            <guid isPermaLink="false">238d8c76-b6ae-8095-b053-f77e29e06ac4</guid>
            <pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat actor known as Mimo (or Mimo’lette) has expanded its intrusion operations from Craft CMS to the Magento ecommerce platform, Docker environments, and cloud instances. Mimo exploits PHP-FPM vulnerabilities in Magento to gain initial access, establishes persistence usi...]]></description>
            <content:encoded><![CDATA[The threat actor known as Mimo (or Mimo’lette) has expanded its intrusion operations from Craft CMS to the Magento ecommerce platform, Docker environments, and cloud instances. Mimo exploits PHP-FPM vulnerabilities in Magento to gain initial access, establishes persistence usi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Attack on npm Packages via Maintainer Phishing (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-attack-on-npm-packages-via-maintainer-phishing</link>
            <guid isPermaLink="false">240d8c76-b6ae-80c6-96a1-e7d12f9d1abe</guid>
            <pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A phishing attack targeting a popular npm maintainer led to the compromise of several widely used packages, including eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, and others. The attacker stole the maintainer’s npm token via a spoofed email and used it ...]]></description>
            <content:encoded><![CDATA[A phishing attack targeting a popular npm maintainer led to the compromise of several widely used packages, including eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, and others. The attacker stole the maintainer’s npm token via a spoofed email and used it ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[0day Vulnerability in Microsoft Sharepoint Exploited in-the-Wild (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/0day-vulnerability-in-microsoft-sharepoint-exploited-in-the-wild</link>
            <guid isPermaLink="false">23ad8c76-b6ae-807d-b2d4-f9a7ecda1a4a</guid>
            <pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft has disclosed two actively exploited zero-day vulnerabilities in on-premises SharePoint Server—CVE-2025-53770 (RCE via unsafe deserialization) and CVE-2025-53771 (authentication bypass via Referer header spoofing). These flaws form a chained exploit known as ToolShel...]]></description>
            <content:encoded><![CDATA[Microsoft has disclosed two actively exploited zero-day vulnerabilities in on-premises SharePoint Server—CVE-2025-53770 (RCE via unsafe deserialization) and CVE-2025-53771 (authentication bypass via Referer header spoofing). These flaws form a chained exploit known as ToolShel...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Linuxsys Cryptominer Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/linuxsys-cryptominer-campaign</link>
            <guid isPermaLink="false">238d8c76-b6ae-80c8-8968-fb2d42a28412</guid>
            <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The Linuxsys cryptominer is part of a long-running campaign active since at least 2021, consistently exploiting multiple web application vulnerabilities to deploy the Linuxsys coinminer on compromised systems. The attacker utilizes a stable methodology: exploiting n-day vulner...]]></description>
            <content:encoded><![CDATA[The Linuxsys cryptominer is part of a long-running campaign active since at least 2021, consistently exploiting multiple web application vulnerabilities to deploy the Linuxsys coinminer on compromised systems. The attacker utilizes a stable methodology: exploiting n-day vulner...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AWS Network Exploitation and Ransomware Detonation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/aws-network-exploitation-and-ransomware-detonation</link>
            <guid isPermaLink="false">232d8c76-b6ae-8003-aed9-e72797efa49f</guid>
            <pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[AWS customer faced a compromise through a SonicWall SMA 500v EC2 instance that was improperly exposed to the internet. The attacker connected via multiple Vultr VPS endpoints, performed network scans, and moved laterally between EC2 instances using RDP. Over 700 GB of data was...]]></description>
            <content:encoded><![CDATA[AWS customer faced a compromise through a SonicWall SMA 500v EC2 instance that was improperly exposed to the internet. The attacker connected via multiple Vultr VPS endpoints, performed network scans, and moved laterally between EC2 instances using RDP. Over 700 GB of data was...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AWS Data Exfiltration and Attempted Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/aws-data-exfiltration-and-attempted-ransomware</link>
            <guid isPermaLink="false">232d8c76-b6ae-80ba-affe-cbcd51163601</guid>
            <pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In February 2025, a UK-based AWS environment was infiltrated using compromised VPN credentials. The threat actor conducted internal reconnaissance with Nmap and staged data exfiltration using the Rclone tool, transferring sensitive files from AWS file servers, particularly fin...]]></description>
            <content:encoded><![CDATA[In February 2025, a UK-based AWS environment was infiltrated using compromised VPN credentials. The threat actor conducted internal reconnaissance with Nmap and staged data exfiltration using the Rclone tool, transferring sensitive files from AWS file servers, particularly fin...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Azure Account Hijack via Stolen Tokens (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/azure-account-hijack-via-stolen-tokens</link>
            <guid isPermaLink="false">232d8c76-b6ae-803b-9000-d72bf68b1217</guid>
            <pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In early 2024, a Darktrace customer’s Azure environment was compromised after attackers stole access tokens linked to an external consultant’s account, obtained via cracked software. Using these tokens, the attacker authenticated into the Azure environment, modified security r...]]></description>
            <content:encoded><![CDATA[In early 2024, a Darktrace customer’s Azure environment was compromised after attackers stole access tokens linked to an external consultant’s account, obtained via cracked software. Using these tokens, the attacker authenticated into the Azure environment, modified security r...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[In-Memory IIS Attacks via View State Deserialization (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/in-memory-iis-attacks-via-view-state-deserialization</link>
            <guid isPermaLink="false">22bd8c76-b6ae-807b-9fe7-e044435f7bc9</guid>
            <pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Unit 42 researchers uncovered a campaign by a threat actor they call TGR-CRI-0045—assessed with medium confidence to be part of the Gold Melody (UNC961/Prophet Spider) group—targeting ASP.NET IIS servers using compromised Machine Keys. This group, acting as an Initial Access B...]]></description>
            <content:encoded><![CDATA[Unit 42 researchers uncovered a campaign by a threat actor they call TGR-CRI-0045—assessed with medium confidence to be part of the Gold Melody (UNC961/Prophet Spider) group—targeting ASP.NET IIS servers using compromised Machine Keys. This group, acting as an Initial Access B...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC5174 Exploits Ivanti CSA Zero-Days in “Houken” Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc5174-exploits-ivanti-csa-zero-days-in-houken-campaign</link>
            <guid isPermaLink="false">225d8c76-b6ae-801c-9f0d-f785984de144</guid>
            <pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The attacker chained Ivanti CSA zero-days to execute a base64-encoded Python script, which extracted the admin password from a local PostgreSQL database. Using this access, the attacker created or modified PHP scripts to serve as webshells and sometimes deployed a custom Linux...]]></description>
            <content:encoded><![CDATA[The attacker chained Ivanti CSA zero-days to execute a base64-encoded Python script, which extracted the admin password from a local PostgreSQL database. Using this access, the attacker created or modified PHP scripts to serve as webshells and sometimes deployed a custom Linux...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[JDWP Exploited in the Wild (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/jdwp-exploited-in-the-wild</link>
            <guid isPermaLink="false">22fd8c76-b6ae-8025-b305-e0fd80a9e671</guid>
            <pubDate>Wed, 02 Jul 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2025-07-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting JDWP, TeamCity to achieve Resource hijacking. The following tools were observed: XMRig.]]></description>
            <content:encoded><![CDATA[On 2025-07-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting JDWP, TeamCity to achieve Resource hijacking. The following tools were observed: XMRig.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Linux SSH Servers Compromised to Deploy Proxies (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/linux-ssh-servers-compromised-to-deploy-proxies</link>
            <guid isPermaLink="false">224d8c76-b6ae-80df-84eb-f538ea1149ec</guid>
            <pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In one attack chain, a Bash script retrieved from 0x0[.]st was used to install TinyProxy via common package managers like apt, yum, or dnf. The script then modified configuration files to allow unrestricted external access (Allow 0.0.0.0/0), exposing the proxy service on port ...]]></description>
            <content:encoded><![CDATA[In one attack chain, a Bash script retrieved from 0x0[.]st was used to install TinyProxy via common package managers like apt, yum, or dnf. The script then modified configuration files to allow unrestricted external access (Allow 0.0.0.0/0), exposing the proxy service on port ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Attacks on Korean IIS & Linux Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/attacks-on-korean-iis--linux-servers</link>
            <guid isPermaLink="false">222d8c76-b6ae-8099-808a-f52afa1ccc1c</guid>
            <pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In June 2025 researchers documented a campaign that breaches vulnerable South-Korean IIS web servers—and sometimes adjacent Linux hosts—by uploading ASP/ASPX web shells through file-upload flaws. Once the shell is in place, the operators fan out: they run basic host discovery ...]]></description>
            <content:encoded><![CDATA[In June 2025 researchers documented a campaign that breaches vulnerable South-Korean IIS web servers—and sometimes adjacent Linux hosts—by uploading ASP/ASPX web shells through file-upload flaws. Once the shell is in place, the operators fan out: they run basic host discovery ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Langflow Vulnerability Exploited to Deliver Flodrix Botnet (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/langflow-vulnerability-exploited-to-deliver-flodrix-botnet</link>
            <guid isPermaLink="false">21ad8c76-b6ae-80fe-beb0-f10f22dd3f77</guid>
            <pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[CVE-2025-3248 is an unauthenticated remote code execution (RCE) vulnerability in Langflow, a popular Python-based framework for building AI applications. The flaw lies in the code validation endpoint, which fails to enforce authentication or sandboxing when parsing and executi...]]></description>
            <content:encoded><![CDATA[CVE-2025-3248 is an unauthenticated remote code execution (RCE) vulnerability in Langflow, a popular Python-based framework for building AI applications. The flaw lies in the code validation endpoint, which fails to enforce authentication or sandboxing when parsing and executi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SFireTruck: Malicious JavaScript Campaign Using Obfuscation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sfiretruck-malicious-javascript-campaign-using-obfuscation</link>
            <guid isPermaLink="false">21ad8c76-b6ae-800b-bbee-d87d42b7191a</guid>
            <pubDate>Thu, 12 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a large-scale malvertising campaign, active primarily between March 26 and April 25, 2025, during which over 269,000 legitimate websites were compromised with highly obfuscated JavaScript code dubbed “JSFireTruck” (a euphemism for JSF*ck). Using only six ...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a large-scale malvertising campaign, active primarily between March 26 and April 25, 2025, during which over 269,000 legitimate websites were compromised with highly obfuscated JavaScript code dubbed “JSFireTruck” (a euphemism for JSF*ck). Using only six ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TeamFiltration Account Takeover Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/teamfiltration-account-takeover-campaign</link>
            <guid isPermaLink="false">214d8c76-b6ae-80c1-b197-d5e65530985b</guid>
            <pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2025-06-11, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Resource enumeration, targeting Microsoft OneDrive, Microsoft Outlook, Microsoft Teams to achieve Data exfiltration. The following tools were observed: TeamFiltration.]]></description>
            <content:encoded><![CDATA[On 2025-06-11, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Resource enumeration, targeting Microsoft OneDrive, Microsoft Outlook, Microsoft Teams to achieve Data exfiltration. The following tools were observed: TeamFiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[NPM Supply Chain Attack Compromises 16 Popular React Native and GlueStack Packages (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/npm-supply-chain-attack-compromises-16-popular-react-native-and-gluestack-packages</link>
            <guid isPermaLink="false">20dd8c76-b6ae-8041-892a-c11d4b52d0bf</guid>
            <pubDate>Sat, 07 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A threat actor compromised 16 highly popular React Native and GlueStack packages, collectively downloaded over a million times weekly. The attackers inserted a stealthy backdoor into these packages using whitespace obfuscation to hide malicious code. The payload is a Remote Ac...]]></description>
            <content:encoded><![CDATA[A threat actor compromised 16 highly popular React Native and GlueStack packages, collectively downloaded over a million times weekly. The attackers inserted a stealthy backdoor into these packages using whitespace obfuscation to hide malicious code. The payload is a Remote Ac...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Open WebUI Misconfiguration Exploited for Cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/open-webui-misconfiguration-exploited-for-cryptojacking</link>
            <guid isPermaLink="false">208d8c76-b6ae-8076-918a-ec035ee75f83</guid>
            <pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered an active exploitation of a misconfigured Open WebUI instance—a self-hosted interface for large language models (LLMs)—that was exposed to the internet with administrator access enabled and no authentication. A threat actor leveraged this misconfiguratio...]]></description>
            <content:encoded><![CDATA[Researchers discovered an active exploitation of a misconfigured Open WebUI instance—a self-hosted interface for large language models (LLMs)—that was exposed to the internet with administrator access enabled and no authentication. A threat actor leveraged this misconfiguratio...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cryptojacking Campaign Targets Misconfigured DevOps Tools (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cryptojacking-campaign-targets-misconfigured-devops-tools</link>
            <guid isPermaLink="false">208d8c76-b6ae-8012-b496-d934dc305a3f</guid>
            <pubDate>Mon, 02 Jun 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[JINX-0132 targets exposed Nomad servers lacking ACL protections by submitting malicious jobs through the API, effectively gaining remote code execution. These jobs download and run the XMRig miner from public GitHub releases, bypassing traditional IOC-based detection. Gitea in...]]></description>
            <content:encoded><![CDATA[JINX-0132 targets exposed Nomad servers lacking ACL protections by submitting malicious jobs through the API, effectively gaining remote code execution. These jobs download and run the XMRig miner from public GitHub releases, bypassing traditional IOC-based detection. Gitea in...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Earth Lamia Custom Toolkit Targets Multiple Sectors via Web Vulnerabilities (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/earth-lamia-custom-toolkit-targets-multiple-sectors-via-web-vulnerabilities</link>
            <guid isPermaLink="false">202d8c76-b6ae-8087-9633-f517f3a921a2</guid>
            <pubDate>Thu, 29 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Earth Lamia, a suspected China-nexus APT group active since at least 2023, has expanded its cyber espionage campaigns across Brazil, India, and Southeast Asia. The group targets multiple industries — shifting from financial services to logistics, online retail, and currently I...]]></description>
            <content:encoded><![CDATA[Earth Lamia, a suspected China-nexus APT group active since at least 2023, has expanded its cyber espionage campaigns across Brazil, India, and Southeast Asia. The group targets multiple industries — shifting from financial services to logistics, online retail, and currently I...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DragonForce Exploits SimpleHelp Vulnerabilities in Ransomware Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dragonforce-exploits-simplehelp-vulnerabilities-in-ransomware-campaign</link>
            <guid isPermaLink="false">202d8c76-b6ae-80e4-a4e7-f4827a74fc53</guid>
            <pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[DragonForce gained access to an MSP’s SimpleHelp instance and weaponized its remote management capabilities to deliver a malicious installer to client environments. Once executed, the installer enabled credential harvesting, network reconnaissance, and ransomware deployment. T...]]></description>
            <content:encoded><![CDATA[DragonForce gained access to an MSP’s SimpleHelp instance and weaponized its remote management capabilities to deliver a malicious installer to client environments. Once executed, the installer enabled credential harvesting, network reconnaissance, and ransomware deployment. T...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Coordinated One-Day Cloud Scanning Operation Targets 75 Exposure Points (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/coordinated-one-day-cloud-scanning-operation-targets-75-exposure-points</link>
            <guid isPermaLink="false">201d8c76-b6ae-80b0-8987-f74a36066295</guid>
            <pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On May 8, 2025, GreyNoise observed a tightly coordinated and large-scale reconnaissance campaign launched from 251 malicious IP addresses, all hosted on Amazon AWS and geolocated in Japan. These IPs were active for only one day and collectively triggered 75 distinct scanning b...]]></description>
            <content:encoded><![CDATA[On May 8, 2025, GreyNoise observed a tightly coordinated and large-scale reconnaissance campaign launched from 251 malicious IP addresses, all hosted on Amazon AWS and geolocated in Japan. These IPs were active for only one day and collectively triggered 75 distinct scanning b...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mimo Exploits Craft CMS RCE to Deploy Cryptominer and Proxyware in Coordinated Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mimo-exploits-craft-cms-rce-to-deploy-cryptominer-and-proxyware-in-coordinated-campaign</link>
            <guid isPermaLink="false">201d8c76-b6ae-80eb-a22b-ef458a66f26a</guid>
            <pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Between February and May 2025, the intrusion set known as Mimo exploited CVE-2025-32432, a critical unauthenticated RCE in Craft CMS, to deploy a multi-stage infection chain observed via honeypots. The attack began by injecting a PHP webshell through a crafted GET request, fol...]]></description>
            <content:encoded><![CDATA[Between February and May 2025, the intrusion set known as Mimo exploited CVE-2025-32432, a critical unauthenticated RCE in Craft CMS, to deploy a multi-stage infection chain observed via honeypots. The attack began by injecting a PHP webshell through a crafted GET request, fol...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ivanti-epmm-rce-vulnerability-chain-exploited-in-the-wild</link>
            <guid isPermaLink="false">201d8c76-b6ae-8064-85f6-d21d0c6cf9f9</guid>
            <pubDate>Tue, 20 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research has confirmed active in-the-wild exploitation of a vulnerability chain in Ivanti Endpoint Manager Mobile (EPMM), comprising CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (post-auth RCE). Exploited together, these flaws enable unauthenticated remot...]]></description>
            <content:encoded><![CDATA[Wiz Threat Research has confirmed active in-the-wild exploitation of a vulnerability chain in Ivanti Endpoint Manager Mobile (EPMM), comprising CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (post-auth RCE). Exploited together, these flaws enable unauthenticated remot...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UTG-Q-015 Exploits 0-Days for Espionage in Asia (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/utg-q-015-exploits-0-days-for-espionage-in-asia</link>
            <guid isPermaLink="false">208d8c76-b6ae-8024-bbae-e07e4a9649c7</guid>
            <pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[UTG-Q-015, a Southeast Asia-based threat actor, escalated its operations in early 2025 by shifting to more aggressive tactics. Initially exposed in December 2024 for mounting attacks on Chinese developer forums, UTG-Q-015 evolved to exploit both 0-day and N-day vulnerabilities...]]></description>
            <content:encoded><![CDATA[UTG-Q-015, a Southeast Asia-based threat actor, escalated its operations in early 2025 by shifting to more aggressive tactics. Initially exposed in December 2024 for mounting attacks on Chinese developer forums, UTG-Q-015 evolved to exploit both 0-day and N-day vulnerabilities...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From stolen cloud key to persistence-as-a-service (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-stolen-cloud-key-to-persistence-as-a-service</link>
            <guid isPermaLink="false">1f7d8c76-b6ae-8047-b706-df2ea6b7e19f</guid>
            <pubDate>Tue, 13 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A recent incident revealed attacker activity stemming from a leaked long-term AWS access key (AKIA*) belonging to a user in an organization’s AWS management account. Over a 150-minute period, five IP addresses abused the credentials to perform both well-known and novel cloud a...]]></description>
            <content:encoded><![CDATA[A recent incident revealed attacker activity stemming from a leaked long-term AWS access key (AKIA*) belonging to a user in an organization’s AWS management account. Over a 150-minute period, five IP addresses abused the credentials to perform both well-known and novel cloud a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RedisRaider Linux Cryptojacking Campaign Targets Redis Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/redisraider-linux-cryptojacking-campaign-targets-redis-servers</link>
            <guid isPermaLink="false">201d8c76-b6ae-80dd-8558-dc24ae1c4f96</guid>
            <pubDate>Thu, 08 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[RedisRaider begins by indiscriminately scanning the IPv4 space for Redis servers open on port 6379. Upon identifying a target, the malware checks the server OS and uses Redis commands to inject a base64-encoded shell script as a cron job. It writes this payload to disk by reco...]]></description>
            <content:encoded><![CDATA[RedisRaider begins by indiscriminately scanning the IPv4 space for Redis servers open on port 6379. Upon identifying a target, the malware checks the server OS and uses Redis commands to inject a base64-encoded shell script as a cron job. It writes this payload to disk by reco...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ComfyUI exploitation campaign   (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/comfyui-exploitation-campaign--</link>
            <guid isPermaLink="false">1ebd8c76-b6ae-80bf-9b3c-c550e6f635ad</guid>
            <pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Baidu reports an exploitation campaign targeting publicly-exposed instances of ComfyUI. ComfyUI provides a GUI for AI image generation workflows. By default, it does not implement authentication. A popular extension, ComfyUI-Manager, allows an attacker to execute remote code v...]]></description>
            <content:encoded><![CDATA[Baidu reports an exploitation campaign targeting publicly-exposed instances of ComfyUI. ComfyUI provides a GUI for AI image generation workflows. By default, it does not implement authentication. A popular extension, ComfyUI-Manager, allows an attacker to execute remote code v...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Compromise of  (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-compromise-of-</link>
            <guid isPermaLink="false">1fbd8c76-b6ae-80e0-9c22-cd8757b8abab</guid>
            <pubDate>Mon, 05 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers detected a malicious update to the popular npm package rand-user-agent, used for generating randomized user-agent strings. The attacker published multiple unauthorized versions (1.0.110, 2.0.83, 2.0.84) containing heavily obfuscated code designed to covertly instal...]]></description>
            <content:encoded><![CDATA[Researchers detected a malicious update to the popular npm package rand-user-agent, used for generating randomized user-agent strings. The attacker published multiple unauthorized versions (1.0.110, 2.0.83, 2.0.84) containing heavily obfuscated code designed to covertly instal...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[xAI leaked API key (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/xai-leaked-api-key</link>
            <guid isPermaLink="false">1f7d8c76-b6ae-80d5-a7b4-e10734683843</guid>
            <pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A security lapse at xAI, led to the exposure of a private API key on GitHub by a company employee. The leaked credential, discovered by Philippe Caturegli and validated by GitGuardian, provided access to at least 60 private and unreleased large language models (LLMs), includin...]]></description>
            <content:encoded><![CDATA[A security lapse at xAI, led to the exposure of a private API key on GitHub by a company employee. The leaked credential, discovered by Philippe Caturegli and validated by GitGuardian, provided access to at least 60 private and unreleased large language models (LLMs), includin...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Larva-25003: IIS Native Module Malware Used in Targeted Web Server Attacks (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/larva-25003-iis-native-module-malware-used-in-targeted-web-server-attacks</link>
            <guid isPermaLink="false">1edd8c76-b6ae-803e-916e-f50c673f1bc5</guid>
            <pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In early 2025, AhnLab Security Intelligence Center (ASEC) discovered a targeted attack campaign dubbed Larva-25003, believed to be operated by Chinese-speaking threat actors. The attackers gained access to poorly secured Microsoft IIS web servers in South Korea and deployed a ...]]></description>
            <content:encoded><![CDATA[In early 2025, AhnLab Security Intelligence Center (ASEC) discovered a targeted attack campaign dubbed Larva-25003, believed to be operated by Chinese-speaking threat actors. The attackers gained access to poorly secured Microsoft IIS web servers in South Korea and deployed a ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Node.js repository CI/CD vulnerable to RCE (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/nodejs-repository-cicd-vulnerable-to-rce</link>
            <guid isPermaLink="false">1edd8c76-b6ae-8078-af3f-f38b8357f11f</guid>
            <pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A security researcher uncovered a critical vulnerability in the Node.js CI/CD pipeline that allowed for remote code execution on internal Jenkins agents and posed a significant supply chain risk. The attack stemmed from how Node.js orchestrated workflows using GitHub Actions, ...]]></description>
            <content:encoded><![CDATA[A security researcher uncovered a critical vulnerability in the Node.js CI/CD pipeline that allowed for remote code execution on internal Jenkins agents and posed a significant supply chain risk. The attack stemmed from how Node.js orchestrated workflows using GitHub Actions, ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Grafana GitHub Action attempted supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/grafana-github-action-attempted-supply-chain-attack</link>
            <guid isPermaLink="false">1e4d8c76-b6ae-8048-9f60-e33ee39939ce</guid>
            <pubDate>Sun, 27 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Grafana Labs detected suspicious activity via a triggered canary token, leading to the discovery of unauthorized access enabled by a misconfigured GitHub Action. An attacker exploited the workflow by forking a Grafana repository, injecting a malicious curl command to extract e...]]></description>
            <content:encoded><![CDATA[Grafana Labs detected suspicious activity via a triggered canary token, leading to the discovery of unauthorized access enabled by a misconfigured GitHub Action. An attacker exploited the workflow by forking a Grafana repository, injecting a malicious curl command to extract e...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Password spray attack leads to containers being used for cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/password-spray-attack-leads-to-containers-being-used-for-cryptomining</link>
            <guid isPermaLink="false">1f2d8c76-b6ae-802a-a60c-e9793ae01ade</guid>
            <pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In the past year Microsoft observed AzureChecker(Storm-1977) launching password spray attacks, against cloud tenants in the education sector.
The actor used AzureChecker.exe (CLI tool that is being used by a wide range of actors)]]></description>
            <content:encoded><![CDATA[In the past year Microsoft observed AzureChecker(Storm-1977) launching password spray attacks, against cloud tenants in the education sector.
The actor used AzureChecker.exe (CLI tool that is being used by a wide range of actors)]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Hybrid attack discovered by Mandiant (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/hybrid-attack-discovered-by-mandiant</link>
            <guid isPermaLink="false">1e3d8c76-b6ae-8008-9a68-fd4814841d81</guid>
            <pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[During an investigation, Mandiant identified evidence that a threat actor had discovered cloud access keys stored in plain text on a compromised on-premises network. The threat actor was able to use the keys to access and steal data from the client’s cloud storage buckets. Whe...]]></description>
            <content:encoded><![CDATA[During an investigation, Mandiant identified evidence that a threat actor had discovered cloud access keys stored in plain text on a compromised on-premises network. The threat actor was able to use the keys to access and steal data from the client’s cloud storage buckets. Whe...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Apache Druid cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apache-druid-cryptojacking</link>
            <guid isPermaLink="false">1e2d8c76-b6ae-8096-819b-d727d406f613</guid>
            <pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...]]></description>
            <content:encoded><![CDATA[ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Apache Druid cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apache-druid-cryptojacking</link>
            <guid isPermaLink="false">1e2d8c76-b6ae-8086-8133-db7c9f981ebd</guid>
            <pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...]]></description>
            <content:encoded><![CDATA[ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SAP NetWeaver Visual Composer exploitation campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sap-netweaver-visual-composer-exploitation-campaign</link>
            <guid isPermaLink="false">1e4d8c76-b6ae-808e-9e34-fc84f017a4df</guid>
            <pubDate>Tue, 22 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[CVE-2025-31324 is a critical zero-day vulnerability in the SAP NetWeaver Visual Composer component (CVSS 10.0) that enables unauthenticated remote code execution (RCE). The flaw, caused by missing authorization checks in the Metadata Uploader interface, allows attackers to upl...]]></description>
            <content:encoded><![CDATA[CVE-2025-31324 is a critical zero-day vulnerability in the SAP NetWeaver Visual Composer component (CVSS 10.0) that enables unauthenticated remote code execution (RCE). The flaw, caused by missing authorization checks in the Metadata Uploader interface, allows attackers to upl...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Multi-Layered Cryptojacking via Docker (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/multi-layered-cryptojacking-via-docker</link>
            <guid isPermaLink="false">1dfd8c76-b6ae-8064-ab18-dba3ceba3890</guid>
            <pubDate>Tue, 22 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A recent malware campaign targeting Docker showcases a novel form of cryptojacking that abuses legitimate Web3 services for profit while employing heavy layers of obfuscation to evade detection. By leveraging publicly hosted Docker images, the attackers deploy Python scripts t...]]></description>
            <content:encoded><![CDATA[A recent malware campaign targeting Docker showcases a novel form of cryptojacking that abuses legitimate Web3 services for profit while employing heavy layers of obfuscation to evade detection. By leveraging publicly hosted Docker images, the attackers deploy Python scripts t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Rspack supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/rspack-supply-chain-attack</link>
            <guid isPermaLink="false">1f7d8c76-b6ae-804c-a45d-e1f5bc4b1728</guid>
            <pubDate>Thu, 17 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a supply chain attack carried out by a threat actor labeled MUT-1692. Initially detected via a suspicious npm package (argus3-test) mimicking a legitimate tool, the investigation revealed a postinstall script that attempted to connect to a remote C2 serve...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a supply chain attack carried out by a threat actor labeled MUT-1692. Initially detected via a suspicious npm package (argus3-test) mimicking a legitimate tool, the investigation revealed a postinstall script that attempted to connect to a remote C2 serve...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC5174 Linux Espionage Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc5174-linux-espionage-campaign</link>
            <guid isPermaLink="false">1d7d8c76-b6ae-80b9-b878-e1f67f61d3f6</guid>
            <pubDate>Wed, 16 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[UNC5174, a suspected Chinese state-sponsored threat actor, has resurfaced in a stealthy espionage campaign targeting Linux systems across research institutions, government agencies, NGOs, and critical infrastructure sectors in Western and APAC countries. The campaign, active s...]]></description>
            <content:encoded><![CDATA[UNC5174, a suspected Chinese state-sponsored threat actor, has resurfaced in a stealthy espionage campaign targeting Linux systems across research institutions, government agencies, NGOs, and critical infrastructure sectors in Western and APAC countries. The campaign, active s...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CrazyHunter Ransomware Group Targets Critical Sectors in Taiwan (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/crazyhunter-ransomware-group-targets-critical-sectors-in-taiwan</link>
            <guid isPermaLink="false">1d7d8c76-b6ae-80a0-bc1e-dddf06371880</guid>
            <pubDate>Wed, 16 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[CrazyHunter is a newly emerged ransomware group that has rapidly gained attention for its focused attacks on Taiwan’s critical sectors, particularly healthcare, education, and manufacturing. The group’s operations demonstrate a high level of sophistication, leveraging both adv...]]></description>
            <content:encoded><![CDATA[CrazyHunter is a newly emerged ransomware group that has rapidly gained attention for its focused attacks on Taiwan’s critical sectors, particularly healthcare, education, and manufacturing. The group’s operations demonstrate a high level of sophistication, leveraging both adv...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AWS Breach at a SaaS Company (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/aws-breach-at-a-saas-company</link>
            <guid isPermaLink="false">1ded8c76-b6ae-80e3-942d-ec6cee500a32</guid>
            <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[an AWS security breach that severely impacted a growing SaaS company. An attacker gained access to administrator-level credentials and exploited architectural flaws to compromise both staging and production environments. The incident led to data exfiltration, deletion of criti...]]></description>
            <content:encoded><![CDATA[an AWS security breach that severely impacted a growing SaaS company. An attacker gained access to administrator-level credentials and exploited architectural flaws to compromise both staging and production environments. The incident led to data exfiltration, deletion of criti...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BPFDoor’s Hidden Controller Targets AMEA Sectors (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/bpfdoors-hidden-controller-targets-amea-sectors</link>
            <guid isPermaLink="false">1d5d8c76-b6ae-8042-80fa-d724e48a9083</guid>
            <pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Trend Micro uncovered a previously unseen controller used in BPFDoor campaigns, attributing it to Earth Bluecrow (also known as Red Menshen), a state-sponsored APT group. BPFDoor is a stealthy Linux backdoor leveraging Berkeley Packet Filtering (BPF) to silently activate via "...]]></description>
            <content:encoded><![CDATA[Trend Micro uncovered a previously unseen controller used in BPFDoor campaigns, attributing it to Earth Bluecrow (also known as Red Menshen), a state-sponsored APT group. BPFDoor is a stealthy Linux backdoor leveraging Berkeley Packet Filtering (BPF) to silently activate via "...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Atlas Lion Campaign Exploits Device Enrollment and MFA for Persistence (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/atlas-lion-campaign-exploits-device-enrollment-and-mfa-for-persistence</link>
            <guid isPermaLink="false">1ded8c76-b6ae-8020-a362-c5f88407aea5</guid>
            <pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The initial intrusion vector was an SMS phishing campaign that spoofed internal IT notifications to harvest user credentials and MFA codes. Atlas Lion then enrolled a VM from their Azure tenant into the organization’s domain by mimicking the legitimate Windows device setup pro...]]></description>
            <content:encoded><![CDATA[The initial intrusion vector was an SMS phishing campaign that spoofed internal IT notifications to harvest user credentials and MFA codes. Atlas Lion then enrolled a VM from their Azure tenant into the organization’s domain by mimicking the legitimate Windows device setup pro...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Long-Term Email Breach at OCC Exposes Sensitive Bank Oversight Data (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/long-term-email-breach-at-occ-exposes-sensitive-bank-oversight-data</link>
            <guid isPermaLink="false">1dbd8c76-b6ae-800e-a72d-f8963c9cf455</guid>
            <pubDate>Tue, 08 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Hackers infiltrated the Office of the Comptroller of the Currency (OCC) and monitored email accounts of approximately 103 bank regulators for over a year, accessing around 150,000 sensitive messages. The attackers gained entry via an administrative account, allowing them to ob...]]></description>
            <content:encoded><![CDATA[Hackers infiltrated the Office of the Comptroller of the Currency (OCC) and monitored email accounts of approximately 103 bank regulators for over a year, accessing around 150,000 sensitive messages. The attackers gained entry via an administrative account, allowing them to ob...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Europecar Gitlab Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/europecar-gitlab-breach</link>
            <guid isPermaLink="false">1cdd8c76-b6ae-8017-87c1-d0d24aac2417</guid>
            <pubDate>Fri, 04 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A hacker breached the GitLab repositories of Europcar Mobility Group and stole source code for Android and iOS apps, along with SQL backups and configuration files that included personal data. The attacker, using Europcar’s name as an alias, claimed to have extracted over 9,00...]]></description>
            <content:encoded><![CDATA[A hacker breached the GitLab repositories of Europcar Mobility Group and stole source code for Android and iOS apps, along with SQL backups and configuration files that included personal data. The attacker, using Europcar’s name as an alias, claimed to have extracted over 9,00...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Critical Ivanti Connect Secure Vulnerability Exploited by China-linked Actor (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/critical-ivanti-connect-secure-vulnerability-exploited-by-china-linked-actor</link>
            <guid isPermaLink="false">1cdd8c76-b6ae-8069-aa2a-e0e10856c6ef</guid>
            <pubDate>Thu, 03 Apr 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On April 3, 2025, Ivanti disclosed a critical vulnerability, CVE-2025-22457, affecting Ivanti Connect Secure (ICS) VPN appliances version 22.7R2.5 and earlier. The flaw, initially underestimated as a denial-of-service risk, was later found to be a buffer overflow that allows r...]]></description>
            <content:encoded><![CDATA[On April 3, 2025, Ivanti disclosed a critical vulnerability, CVE-2025-22457, affecting Ivanti Connect Secure (ICS) VPN appliances version 22.7R2.5 and earlier. The flaw, initially underestimated as a denial-of-service risk, was later found to be a buffer overflow that allows r...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Weaver Ant data exfiltration campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/weaver-ant-data-exfiltration-campaign</link>
            <guid isPermaLink="false">1c3d8c76-b6ae-80a9-bfe5-e3f366ebff26</guid>
            <pubDate>Mon, 24 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Sygnia uncovered a prolonged cyber-espionage campaign targeting a major Asian telecom provider, orchestrated by a China-nexus APT group dubbed Weaver Ant. The group maintained stealthy, long-term access to the network for over four years using advanced techniques centered arou...]]></description>
            <content:encoded><![CDATA[Sygnia uncovered a prolonged cyber-espionage campaign targeting a major Asian telecom provider, orchestrated by a China-nexus APT group dubbed Weaver Ant. The group maintained stealthy, long-term access to the network for over four years using advanced techniques centered arou...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Albabat Ransomware Targets Windows, Linux, and macOS Using GitHub Infrastructure (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/albabat-ransomware-targets-windows-linux-and-macos-using-github-infrastructure</link>
            <guid isPermaLink="false">1c6d8c76-b6ae-80fa-9bdd-fd7c3757f4f9</guid>
            <pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers have uncovered new and evolving versions of the Albabat ransomware, which now target Windows, Linux, and macOS systems. These updated variants (v2.0.0 and v2.5) show a notable expansion from the ransomware’s initial Windows-only focus and use GitHub for storing and...]]></description>
            <content:encoded><![CDATA[Researchers have uncovered new and evolving versions of the Albabat ransomware, which now target Windows, Linux, and macOS systems. These updated variants (v2.0.0 and v2.5) show a notable expansion from the ransomware’s initial Windows-only focus and use GitHub for storing and...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Oracle Cloud Potential Supply Chain Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/oracle-cloud-potential-supply-chain-breach</link>
            <guid isPermaLink="false">1c3d8c76-b6ae-80a2-810c-e1ea59fa1828</guid>
            <pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On March 21, 2025, CloudSEK reported that a threat actor using the alias "rose87168" is claiming to have exfiltrated over 6 million records from Oracle Cloud’s SSO and LDAP systems. According to CloudSEK’s assessment, the leaked data includes sensitive authentication materials...]]></description>
            <content:encoded><![CDATA[On March 21, 2025, CloudSEK reported that a threat actor using the alias "rose87168" is claiming to have exfiltrated over 6 million records from Oracle Cloud’s SSO and LDAP systems. According to CloudSEK’s assessment, the leaked data includes sensitive authentication materials...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exposed Jupyter Notebooks Targeted for Cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/exposed-jupyter-notebooks-targeted-for-cryptomining</link>
            <guid isPermaLink="false">1b8d8c76-b6ae-804f-88b0-f4aa39e2ea00</guid>
            <pubDate>Sun, 16 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Cado Security Labs has uncovered a cryptomining campaign exploiting misconfigured Jupyter Notebooks, affecting both Windows and Linux environments. The attackers use Jupyter as an entry point to deploy a cryptominer through a series of evasive techniques. On Windows, the attac...]]></description>
            <content:encoded><![CDATA[Cado Security Labs has uncovered a cryptomining campaign exploiting misconfigured Jupyter Notebooks, affecting both Windows and Linux environments. The attackers use Jupyter as an entry point to deploy a cryptominer through a series of evasive techniques. On Windows, the attac...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[tj-actions/changed-files supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/tj-actionschanged-files-supply-chain-attack</link>
            <guid isPermaLink="false">1b9d8c76-b6ae-807e-9136-e731eb583105</guid>
            <pubDate>Sat, 15 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The compromised version of tj-actions/changed-files injects malicious code into CI workflows, potentially capturing and exposing secrets from affected repositories. On public repositories, the secrets would then be visible to everyone as part of the workflow logs, though obfus...]]></description>
            <content:encoded><![CDATA[The compromised version of tj-actions/changed-files injects malicious code into CI workflows, potentially capturing and exposing secrets from affected repositories. On public repositories, the secrets would then be visible to everyone as part of the workflow logs, though obfus...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CDC dangling domain hijack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cdc-dangling-domain-hijack</link>
            <guid isPermaLink="false">1b3d8c76-b6ae-8048-959d-f7be78ad42e1</guid>
            <pubDate>Mon, 10 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Attackers exploited poor DNS hygiene at the U.S. Centers for Disease Control and Prevention (CDC) to deliver malicious content disguised under the CDC’s trusted domain. The attack was discovered when users searching for English Premier League match streams encountered links th...]]></description>
            <content:encoded><![CDATA[Attackers exploited poor DNS hygiene at the U.S. Centers for Disease Control and Prevention (CDC) to deliver malicious content disguised under the CDC’s trusted domain. The attack was discovered when users searching for English Premier League match streams encountered links th...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PHP-CGI Vulnerability Exploited in Attacks Targeting Japan (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/php-cgi-vulnerability-exploited-in-attacks-targeting-japan</link>
            <guid isPermaLink="false">1aed8c76-b6ae-80c9-83fd-c72f20704e14</guid>
            <pubDate>Thu, 06 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified an ongoing attack campaign targeting organizations in Japan across sectors like technology, telecommunications, education, entertainment, and e-commerce. Active since at least January 2025, the attacker exploits CVE-2024-4577, a critical PHP-CGI remote c...]]></description>
            <content:encoded><![CDATA[Researchers identified an ongoing attack campaign targeting organizations in Japan across sectors like technology, telecommunications, education, entertainment, and e-commerce. Active since at least January 2025, the attacker exploits CVE-2024-4577, a critical PHP-CGI remote c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Silk Typhoon Targeting IT and Cloud Applications (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/silk-typhoon-targeting-it-and-cloud-applications</link>
            <guid isPermaLink="false">1add8c76-b6ae-8012-ab5b-f9b8e73c8c1f</guid>
            <pubDate>Wed, 05 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft Threat Intelligence has identified an evolution in the tactics of Silk Typhoon, a Chinese state-sponsored espionage group, now increasingly focusing on compromising IT solutions, remote management tools, and cloud applications to gain initial access. By exploiting un...]]></description>
            <content:encoded><![CDATA[Microsoft Threat Intelligence has identified an evolution in the tactics of Silk Typhoon, a Chinese state-sponsored espionage group, now increasingly focusing on compromising IT solutions, remote management tools, and cloud applications to gain initial access. By exploiting un...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Zapier data breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/zapier-data-breach</link>
            <guid isPermaLink="false">1aad8c76-b6ae-80fd-ad8f-fa6c215096d9</guid>
            <pubDate>Sat, 01 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On February 27, 2025, Zapier detected that an unauthorized user had accessed some of its internal code repositories due to a two-factor authentication (2FA) misconfiguration on an employee’s account. While the breach did not affect production systems, databases, or payment inf...]]></description>
            <content:encoded><![CDATA[On February 27, 2025, Zapier detected that an unauthorized user had accessed some of its internal code repositories due to a two-factor authentication (2FA) misconfiguration on an employee’s account. While the breach did not affect production systems, databases, or payment inf...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[JavaGhost SES abuse (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/javaghost-ses-abuse</link>
            <guid isPermaLink="false">1aad8c76-b6ae-8048-b089-d9e616fea7bc</guid>
            <pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat group JavaGhost has evolved from website defacement to persistent phishing operations targeting cloud environments, particularly AWS. Between 2022 and 2024, JavaGhost leveraged exposed long-term AWS access keys due to customer misconfigurations. These keys allowed t...]]></description>
            <content:encoded><![CDATA[The threat group JavaGhost has evolved from website defacement to persistent phishing operations targeting cloud environments, particularly AWS. Between 2022 and 2024, JavaGhost leveraged exposed long-term AWS access keys due to customer misconfigurations. These keys allowed t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CPU_HU: Malicious Campaign Targeting Misconfigured PostgreSQL Servers for Cryptomining (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cpuhu-malicious-campaign-targeting-misconfigured-postgresql-servers-for-cryptomining</link>
            <guid isPermaLink="false">1a7d8c76-b6ae-8069-994a-cce2c8fc8dd4</guid>
            <pubDate>Thu, 27 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research identified a malicious campaign targeting weakly configured and publicly exposed PostgreSQL servers to deploy a XMRig-C3 cryptominer. In observed attacks, the threat actor exploited exposed PostgreSQL instances, abused the COPY FROM PROGRAM function to exec...]]></description>
            <content:encoded><![CDATA[Wiz Threat Research identified a malicious campaign targeting weakly configured and publicly exposed PostgreSQL servers to deploy a XMRig-C3 cryptominer. In observed attacks, the threat actor exploited exposed PostgreSQL instances, abused the COPY FROM PROGRAM function to exec...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ByBit hack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/bybit-hack</link>
            <guid isPermaLink="false">1aad8c76-b6ae-80aa-a314-d2f6ae14db77</guid>
            <pubDate>Wed, 26 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On February 21, 2025, Safe{Wallet} suffered a state-sponsored attack, attributed to TraderTraitor (UNC4899), a DPRK-affiliated group. The attackers compromised a developer’s laptop, hijacked AWS session tokens, and bypassed MFA to gain unauthorized access to Safe{Wallet} serve...]]></description>
            <content:encoded><![CDATA[On February 21, 2025, Safe{Wallet} suffered a state-sponsored attack, attributed to TraderTraitor (UNC4899), a DPRK-affiliated group. The attackers compromised a developer’s laptop, hijacked AWS session tokens, and bypassed MFA to gain unauthorized access to Safe{Wallet} serve...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Krpano XSS exploitation campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/krpano-xss-exploitation-campaign</link>
            <guid isPermaLink="false">1aad8c76-b6ae-8090-a73c-d52af523a68b</guid>
            <pubDate>Wed, 26 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The "360XSS" campaign is a widespread exploitation of a reflected cross-site scripting (XSS) vulnerability in the popular virtual tour framework Krpano, which allows external XML content to be injected via the xml query parameter. The vulnerability, known as CVE-2020-24901, st...]]></description>
            <content:encoded><![CDATA[The "360XSS" campaign is a widespread exploitation of a reflected cross-site scripting (XSS) vulnerability in the popular virtual tour framework Krpano, which allows external XML content to be injected via the xml query parameter. The vulnerability, known as CVE-2020-24901, st...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Teammate App exposed MongoDB (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/teammate-app-exposed-mongodb</link>
            <guid isPermaLink="false">1aad8c76-b6ae-8073-b080-cb75ed69d8ee</guid>
            <pubDate>Mon, 24 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A researcher discovered that Teammate App had an exposed database containing nearly 3 million records, including user credentials, employee details, and confidential documents, accessible without authentication. The researcher flagged this issue in December 2024 and formally n...]]></description>
            <content:encoded><![CDATA[A researcher discovered that Teammate App had an exposed database containing nearly 3 million records, including user credentials, employee details, and confidential documents, accessible without authentication. The researcher flagged this issue in December 2024 and formally n...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RevivalStone Campaign by Winnti (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/revivalstone-campaign-by-winnti</link>
            <guid isPermaLink="false">19fd8c76-b6ae-80df-b5f8-efbce47d6367</guid>
            <pubDate>Tue, 18 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The China-linked APT group Winnti (APT41) has been linked to a new cyber espionage campaign, RevivalStone, targeting Japanese manufacturing, materials, and energy companies in March 2024. The attack, detailed by LAC, exploited an SQL injection vulnerability in an unspecified E...]]></description>
            <content:encoded><![CDATA[The China-linked APT group Winnti (APT41) has been linked to a new cyber espionage campaign, RevivalStone, targeting Japanese manufacturing, materials, and energy companies in March 2024. The attack, detailed by LAC, exploited an SQL injection vulnerability in an unspecified E...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Earth Preta’s Campaign Abusing MAVInject to Bypass Detection (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/earth-pretas-campaign-abusing-mavinject-to-bypass-detection</link>
            <guid isPermaLink="false">19fd8c76-b6ae-80b7-b731-edf59e3ef0a7</guid>
            <pubDate>Tue, 18 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Earth Preta (Mustang Panda), a known APT group targeting government entities in the Asia-Pacific region, has been observed using a new technique to evade detection and maintain persistence. Researchers from Trend Micro discovered that the group leverages Microsoft Application ...]]></description>
            <content:encoded><![CDATA[Earth Preta (Mustang Panda), a known APT group targeting government entities in the Asia-Pacific region, has been observed using a new technique to evade detection and maintain persistence. Researchers from Trend Micro discovered that the group leverages Microsoft Application ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Seashell Blizzard Subgroup's Campaign Exploiting Vulnerabilities for Data Exfiltration (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/seashell-blizzard-subgroups-campaign-exploiting-vulnerabilities-for-data-exfiltration</link>
            <guid isPermaLink="false">19ed8c76-b6ae-809f-8ba0-e7a8d13e5b38</guid>
            <pubDate>Thu, 13 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The BadPilot campaign operates as a horizontally scalable cyber operation, compromising a wide range of internet-facing systems using publicly available exploits. The subgroup conducts broad scanning for vulnerable systems and leverages commodity exploits to infiltrate network...]]></description>
            <content:encoded><![CDATA[The BadPilot campaign operates as a horizontally scalable cyber operation, compromising a wide range of internet-facing systems using publicly available exploits. The subgroup conducts broad scanning for vulnerable systems and leverages commodity exploits to infiltrate network...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Code Injection Attacks Exploiting Publicly Disclosed ASP.NET Keys (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/code-injection-attacks-exploiting-publicly-disclosed-aspnet-keys</link>
            <guid isPermaLink="false">19ed8c76-b6ae-8056-aba1-eaf512e3ce51</guid>
            <pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft Threat Intelligence identified a threat actor exploiting publicly disclosed ASP.NET machine keys to perform ViewState code injection attacks. This technique enables attackers to inject malicious code into web applications, leading to remote code execution on IIS serv...]]></description>
            <content:encoded><![CDATA[Microsoft Threat Intelligence identified a threat actor exploiting publicly disclosed ASP.NET machine keys to perform ViewState code injection attacks. This technique enables attackers to inject malicious code into web applications, leading to remote code execution on IIS serv...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Black Basta Exploiting Vulnerabilities in Multiple Products (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/black-basta-exploiting-vulnerabilities-in-multiple-products</link>
            <guid isPermaLink="false">1a4d8c76-b6ae-809b-9d64-f9079fe5eda6</guid>
            <pubDate>Tue, 11 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A major leak of Black Basta’s internal chat logs on February 11, 2025, has exposed significant internal conflicts, leadership instability, and financial fraud within the ransomware group. The leak, allegedly triggered by their attacks on Russian banks, has led to a decline in ...]]></description>
            <content:encoded><![CDATA[A major leak of Black Basta’s internal chat logs on February 11, 2025, has exposed significant internal conflicts, leadership instability, and financial fraud within the ransomware group. The leak, allegedly triggered by their attacks on Russian banks, has led to a decline in ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Malicious AI Models Bypass Picklescan Detection (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/malicious-ai-models-bypass-picklescan-detection</link>
            <guid isPermaLink="false">19ed8c76-b6ae-80b1-8c1a-d79e8eb5b57c</guid>
            <pubDate>Sun, 09 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The nullifAI attack exploits Pickle file serialization, an insecure method for storing ML models, to distribute malware-laced PyTorch models on Hugging Face. Instead of using PyTorch’s default ZIP compression, the attackers compressed the models using 7z, preventing automatic ...]]></description>
            <content:encoded><![CDATA[The nullifAI attack exploits Pickle file serialization, an insecure method for storing ML models, to distribute malware-laced PyTorch models on Hugging Face. Instead of using PyTorch’s default ZIP compression, the attackers compressed the models using 7z, preventing automatic ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From social engineering to Lambda modification (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-social-engineering-to-lambda-modification</link>
            <guid isPermaLink="false">195d8c76-b6ae-8005-bb32-c7c22388efc4</guid>
            <pubDate>Mon, 03 Feb 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered a sophisticated attack initiated through social engineering on LinkedIn and WhatsApp, leading to credential theft via seemingly benign code downloads. With stolen session tokens and cloud access keys, the attackers authenticated into Microsoft 365 and AW...]]></description>
            <content:encoded><![CDATA[Researchers discovered a sophisticated attack initiated through social engineering on LinkedIn and WhatsApp, leading to credential theft via seemingly benign code downloads. With stolen session tokens and cloud access keys, the attackers authenticated into Microsoft 365 and AW...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[USAID cryptojacking incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/usaid-cryptojacking-incident</link>
            <guid isPermaLink="false">18ed8c76-b6ae-8007-935b-f78ab71d4e5a</guid>
            <pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The U.S. Agency for International Development (USAID) was hit by a cryptojacking attack. A global administrator account in a test environment within their Azure subscription was compromised as a result of a password spray attack. The attackers then leveraged the compromised ac...]]></description>
            <content:encoded><![CDATA[The U.S. Agency for International Development (USAID) was hit by a cryptojacking attack. A global administrator account in a test environment within their Azure subscription was compromised as a result of a password spray attack. The attackers then leveraged the compromised ac...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DogWifTool supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/dogwiftool-supply-chain-attack</link>
            <guid isPermaLink="false">191d8c76-b6ae-80ff-b972-d7c28ee2b6bf</guid>
            <pubDate>Wed, 29 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Hackers compromised the Windows version of DogWifTools, a platform for promoting meme coins on the Solana blockchain, through a supply-chain attack that led to the theft of users' cryptocurrency wallets.The attack occurred after a threat actor reverse-engineered the software a...]]></description>
            <content:encoded><![CDATA[Hackers compromised the Windows version of DogWifTools, a platform for promoting meme coins on the Solana blockchain, through a supply-chain attack that led to the theft of users' cryptocurrency wallets.The attack occurred after a threat actor reverse-engineered the software a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Operation LongFang (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/operation-longfang</link>
            <guid isPermaLink="false">1b9d8c76-b6ae-80e8-976b-f88c9a3594d4</guid>
            <pubDate>Fri, 24 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Operation LongFang is a cyber-espionage campaign, attributed to a Chinese threat actor, targeting Latin American government entities. First detected in December 2024, it has been active for at least two years. The campaign's initial access was achieved by exploiting vulnerabil...]]></description>
            <content:encoded><![CDATA[Operation LongFang is a cyber-espionage campaign, attributed to a Chinese threat actor, targeting Latin American government entities. First detected in December 2024, it has been active for at least two years. The campaign's initial access was achieved by exploiting vulnerabil...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[MasterCard Fixes Five-Year-Old DNS Typo Misconfiguration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/mastercard-fixes-five-year-old-dns-typo-misconfiguration</link>
            <guid isPermaLink="false">184d8c76-b6ae-80ec-adb8-cdb2070723cb</guid>
            <pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[MasterCard recently corrected a significant DNS misconfiguration that had persisted for nearly five years, potentially allowing cybercriminals to intercept or divert its Internet traffic. While all MasterCard's DNS server names were supposed to end with "akam.net," one contain...]]></description>
            <content:encoded><![CDATA[MasterCard recently corrected a significant DNS misconfiguration that had persisted for nearly five years, potentially allowing cybercriminals to intercept or divert its Internet traffic. While all MasterCard's DNS server names were supposed to end with "akam.net," one contain...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TRIPLESTRENGTH: Cloud Account Hijacking and Cryptocurrency Mining via Stolen Credentials (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/triplestrength-cloud-account-hijacking-and-cryptocurrency-mining-via-stolen-credentials</link>
            <guid isPermaLink="false">184d8c76-b6ae-80ca-9f15-cbddfb620ac4</guid>
            <pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat actor TRIPLESTRENGTH uses stolen credentials and cookies, partially sourced from Racoon infostealer logs, to gain unauthorized access to victim cloud environments. Initially, they exploited legitimate compromised accounts to create compute resources for cryptocurren...]]></description>
            <content:encoded><![CDATA[The threat actor TRIPLESTRENGTH uses stolen credentials and cookies, partially sourced from Racoon infostealer logs, to gain unauthorized access to victim cloud environments. Initially, they exploited legitimate compromised accounts to create compute resources for cryptocurren...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC2165 Targets Hybrid Environments with Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc2165-targets-hybrid-environments-with-ransomware</link>
            <guid isPermaLink="false">184d8c76-b6ae-8020-9c33-ec155ac403d0</guid>
            <pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[In 2024, UNC2165 exploited a victim's environment by a UNC1543 FAKEUPDATES infection to gain initial access. They deployed their Python tunneler, VIPERTUNNEL, for persistent access and used utility scripts for reconnaissance and disabling anti-virus protection. UNC2165 then ac...]]></description>
            <content:encoded><![CDATA[In 2024, UNC2165 exploited a victim's environment by a UNC1543 FAKEUPDATES infection to gain initial access. They deployed their Python tunneler, VIPERTUNNEL, for persistent access and used utility scripts for reconnaissance and disabling anti-virus protection. UNC2165 then ac...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Otelier data breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/otelier-data-breach</link>
            <guid isPermaLink="false">180d8c76-b6ae-80e3-bbfe-ecead3cd422f</guid>
            <pubDate>Fri, 17 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[An Otelier employee's workstation was infected with an infostealer, leading to compromise of their Jira credentials. The threat actor abused these to gain access to the Jira server, which contained additional credentials granting access to S3 buckets, which contained various d...]]></description>
            <content:encoded><![CDATA[An Otelier employee's workstation was infected with an infostealer, leading to compromise of their Jira credentials. The threat actor abused these to gain access to the Jira server, which contained additional credentials granting access to S3 buckets, which contained various d...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Bapak Exploiting Stolen Cloud Access Keys (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/bapak-exploiting-stolen-cloud-access-keys</link>
            <guid isPermaLink="false">188d8c76-b6ae-8039-816a-f280fc087a14</guid>
            <pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research discovered a malicious campaign where attackers are using leaked or stolen cloud access keys to access cloud environments and deploy ECS clusters. The attacker was observed abusing accidentally exposed AWS access keys and trying to gain a permanent foothold...]]></description>
            <content:encoded><![CDATA[Wiz Threat Research discovered a malicious campaign where attackers are using leaked or stolen cloud access keys to access cloud environments and deploy ECS clusters. The attacker was observed abusing accidentally exposed AWS access keys and trying to gain a permanent foothold...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Codefinger Ransomware Campaign Targeting S3 Buckets (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/codefinger-ransomware-campaign-targeting-s3-buckets</link>
            <guid isPermaLink="false">192d8c76-b6ae-8097-b70f-f90f627dfcc0</guid>
            <pubDate>Mon, 13 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered a ransomware campaign leveraging AWS Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data in Amazon S3 buckets. The attack, orchestrated by the threat actor "Codefinger," uses compromised AWS credentials to encrypt files securely. V...]]></description>
            <content:encoded><![CDATA[Researchers discovered a ransomware campaign leveraging AWS Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data in Amazon S3 buckets. The attack, orchestrated by the threat actor "Codefinger," uses compromised AWS credentials to encrypt files securely. V...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exploitation in the Wild of Aviatrix Controller RCE (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/exploitation-in-the-wild-of-aviatrix-controller-rce</link>
            <guid isPermaLink="false">179d8c76-b6ae-8011-9d71-c5b88537fe16</guid>
            <pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[The vulnerability CVE-2024-50603 was disclosed on 2025-01-07, with a detailed blog and proof-of-concept exploit released by researchers soon after. Evidence of exploitation in cloud environments were observed by Wiz Research, targeting publicly exposed, vulnerable machines. At...]]></description>
            <content:encoded><![CDATA[The vulnerability CVE-2024-50603 was disclosed on 2025-01-07, with a detailed blog and proof-of-concept exploit released by researchers soon after. Evidence of exploitation in cloud environments were observed by Wiz Research, targeting publicly exposed, vulnerable machines. At...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/campaign-targeting-publicly-exposed-management-interfaces-on-fortinet-fortigate-firewalls</link>
            <guid isPermaLink="false">179d8c76-b6ae-8008-b6b2-fff2e2877efd</guid>
            <pubDate>Fri, 10 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Threat actors recently targeted Fortinet FortiGate firewall devices with exposed management interfaces in a suspected zero-day campaign. Arctic Wolf observed unauthorized admin logins via the jsconsole interface, new account creation, SSL VPN configurations, and other system c...]]></description>
            <content:encoded><![CDATA[Threat actors recently targeted Fortinet FortiGate firewall devices with exposed management interfaces in a suspected zero-day campaign. Arctic Wolf observed unauthorized admin logins via the jsconsole interface, new account creation, SSL VPN configurations, and other system c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gravy Analytics data breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/gravy-analytics-data-breach</link>
            <guid isPermaLink="false">179d8c76-b6ae-8084-a9ff-d9c4eb276bfa</guid>
            <pubDate>Fri, 10 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2025-01-10, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2025-01-10, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Kong image compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/kong-image-compromise</link>
            <guid isPermaLink="false">17ad8c76-b6ae-8085-aec6-e5379e25a6be</guid>
            <pubDate>Thu, 02 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Kong Ingress Controller is a popular ingress controller for Kubernetes. The Kong Ingress Controller version 3.4 instances  have been experiencing a significant performance regression causing excessive CPU utilization of approximately 4 cores, even with minimal Gateway API reso...]]></description>
            <content:encoded><![CDATA[Kong Ingress Controller is a popular ingress controller for Kubernetes. The Kong Ingress Controller version 3.4 instances  have been experiencing a significant performance regression causing excessive CPU utilization of approximately 4 cores, even with minimal Gateway API reso...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[US Treasury Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/us-treasury-breach</link>
            <guid isPermaLink="false">16dd8c76-b6ae-8034-8f24-d92c00d5e253</guid>
            <pubDate>Tue, 31 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In December 2024, the U.S. Department of the Treasury experienced a cybersecurity breach due to a compromised API key from BeyondTrust’s Remote Support SaaS. A Chinese state-sponsored Advanced Persistent Threat (APT) actor exploited the stolen key to bypass security measures, ...]]></description>
            <content:encoded><![CDATA[In December 2024, the U.S. Department of the Treasury experienced a cybersecurity breach due to a compromised API key from BeyondTrust’s Remote Support SaaS. A Chinese state-sponsored Advanced Persistent Threat (APT) actor exploited the stolen key to bypass security measures, ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Volkswagen massive data leak through Spring Boot Actuator misconfiguration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/volkswagen-massive-data-leak-through-spring-boot-actuator-misconfiguration</link>
            <guid isPermaLink="false">175d8c76-b6ae-8043-99bb-e76c74d21bdc</guid>
            <pubDate>Mon, 30 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers found a data exposure issue within Volkswagen’s environment by leveraging tools such as Subfinder, GoBuster, and Spring. Using these tools, they found a Java Spring application exposing its Heap dump file. Heap dumps, which list various objects within a Java Virtua...]]></description>
            <content:encoded><![CDATA[Researchers found a data exposure issue within Volkswagen’s environment by leveraging tools such as Subfinder, GoBuster, and Spring. Using these tools, they found a Java Spring application exposing its Heap dump file. Heap dumps, which list various objects within a Java Virtua...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[EC2 Grouper Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ec2-grouper-campaign</link>
            <guid isPermaLink="false">173d8c76-b6ae-8032-9cfc-e81d01930ffc</guid>
            <pubDate>Mon, 30 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The "EC2 Grouper" threat actor is a prolific group frequently detected in cloud environments. They are known for using consistent user agents and a specific security group naming convention (e.g., ec2group, ec2group12345) during attacks, making them easier to identify. However...]]></description>
            <content:encoded><![CDATA[The "EC2 Grouper" threat actor is a prolific group frequently detected in cloud environments. They are known for using consistent user agents and a specific security group naming convention (e.g., ec2group, ec2group12345) during attacks, making them easier to identify. However...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ZAGG customer data compromised via hijacked FreshClicks BigCommerce app (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/zagg-customer-data-compromised-via-hijacked-freshclicks-bigcommerce-app</link>
            <guid isPermaLink="false">176d8c76-b6ae-80db-a8b2-cc48c0f05f71</guid>
            <pubDate>Sat, 28 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-12-28, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-12-28, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Phishing campaign leading to Azure account takeover (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/phishing-campaign-leading-to-azure-account-takeover</link>
            <guid isPermaLink="false">175d8c76-b6ae-808e-b587-f8c0cfc8007e</guid>
            <pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In June 2024, Unit 42 researchers identified a phishing campaign targeting approximately 20,000 users in European automotive, chemical, and industrial compound manufacturing sectors, particularly in Germany and the UK. The attackers employed fake forms created with HubSpot's F...]]></description>
            <content:encoded><![CDATA[In June 2024, Unit 42 researchers identified a phishing campaign targeting approximately 20,000 users in European automotive, chemical, and industrial compound manufacturing sectors, particularly in Germany and the UK. The attackers employed fake forms created with HubSpot's F...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Diicot Campaign Targeting Linux Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/diicot-campaign-targeting-linux-environments</link>
            <guid isPermaLink="false">16fd8c76-b6ae-80d3-9120-cfd2056afe28</guid>
            <pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research uncovered a sophisticated malware campaign by the Romanian-speaking Diicot threat group targeting Linux systems, especially in cloud environments. This campaign demonstrates notable advancements over previous iterations, such as corrupted UPX headers, cloud-specif...]]></description>
            <content:encoded><![CDATA[Wiz Research uncovered a sophisticated malware campaign by the Romanian-speaking Diicot threat group targeting Linux systems, especially in cloud environments. This campaign demonstrates notable advancements over previous iterations, such as corrupted UPX headers, cloud-specif...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RCE Vulnerability in Apache Struts Targeted by Attackers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/rce-vulnerability-in-apache-struts-targeted-by-attackers</link>
            <guid isPermaLink="false">167d8c76-b6ae-8099-9d6b-f731d1aacde8</guid>
            <pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[CVE-2024-53677 is a critical vulnerability in Apache Struts 2 with a CVSS score of 9.5. This flaw in the file upload logic allows path traversal and uploading of malicious files, enabling remote code execution (RCE). Exploitation has been observed in the wild using public proo...]]></description>
            <content:encoded><![CDATA[CVE-2024-53677 is a critical vulnerability in Apache Struts 2 with a CVSS score of 9.5. This flaw in the file upload logic allows path traversal and uploading of malicious files, enabling remote code execution (RCE). Exploitation has been observed in the wild using public proo...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PHP Targeted with Glutton backdoor (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/php-targeted-with-glutton-backdoor</link>
            <guid isPermaLink="false">160d8c76-b6ae-80c3-adba-d87a047caeee</guid>
            <pubDate>Mon, 16 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The Glutton backdoor, a modular PHP-based malware framework, has been observed targeting systems in China, the U.S., Cambodia, Pakistan, and South Africa. The malware, linked with moderate confidence to the Chinese nation-state group Winnti, showcases unique behavior by target...]]></description>
            <content:encoded><![CDATA[The Glutton backdoor, a modular PHP-based malware framework, has been observed targeting systems in China, the U.S., Cambodia, Pakistan, and South Africa. The malware, linked with moderate confidence to the Chinese nation-state group Winnti, showcases unique behavior by target...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LLM Hijacking Targeting AWS (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/llm-hijacking-targeting-aws</link>
            <guid isPermaLink="false">160d8c76-b6ae-80d5-b107-d4a6d3ae8fbe</guid>
            <pubDate>Sun, 15 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On November 26, 2024, Wiz Threat Research identified JINX-2401, a threat actor attempting to hijack LLM models in multiple AWS environments using compromised IAM credentials. The attackers leveraged compromised IAM user keys to gain access, perform privilege escalation, and es...]]></description>
            <content:encoded><![CDATA[On November 26, 2024, Wiz Threat Research identified JINX-2401, a threat actor attempting to hijack LLM models in multiple AWS environments using compromised IAM credentials. The attackers leveraged compromised IAM user keys to gain access, perform privilege escalation, and es...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cleo Vulnerabilities Targeted by Cl0p Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cleo-vulnerabilities-targeted-by-cl0p-ransomware</link>
            <guid isPermaLink="false">15ed8c76-b6ae-80fe-acac-de48a2a88770</guid>
            <pubDate>Sun, 15 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Two critical vulnerabilities in Cleo file transfer software—CVE-2024-50623 and CVE-2024-55956—have been actively exploited, leading to unauthorized data access and system compromise. The Clop ransomware gang has claimed responsibility for these attacks, leveraging zero-day exp...]]></description>
            <content:encoded><![CDATA[Two critical vulnerabilities in Cleo file transfer software—CVE-2024-50623 and CVE-2024-55956—have been actively exploited, leading to unauthorized data access and system compromise. The Clop ransomware gang has claimed responsibility for these attacks, leveraging zero-day exp...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Byte Federal Data Breach via Gitlab Vulnerability (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/byte-federal-data-breach-via-gitlab-vulnerability</link>
            <guid isPermaLink="false">15ed8c76-b6ae-804e-a257-d9178ee23d54</guid>
            <pubDate>Thu, 12 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Byte Federal, the largest US Bitcoin ATM operator, experienced a data breach in November 2024, exposing the sensitive data of 58,000 customers. Hackers exploited an unspecified GitLab vulnerability to gain unauthorized access to Byte Federal's servers. The compromised informat...]]></description>
            <content:encoded><![CDATA[Byte Federal, the largest US Bitcoin ATM operator, experienced a data breach in November 2024, exposing the sensitive data of 58,000 customers. Hackers exploited an unspecified GitLab vulnerability to gain unauthorized access to Byte Federal's servers. The compromised informat...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Attacks abusing Amazon SES (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/attacks-abusing-amazon-ses</link>
            <guid isPermaLink="false">15ad8c76-b6ae-80ca-a6fe-cf6ea959cf86</guid>
            <pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Datadog researchers identified an intrusion targeting Amazon Simple Email Service (SES) in an AWS environment, where attackers employed advanced persistence techniques. The attack was notable for leveraging an external AWS account to assume roles within the victim's environmen...]]></description>
            <content:encoded><![CDATA[Datadog researchers identified an intrusion targeting Amazon Simple Email Service (SES) in an AWS environment, where attackers employed advanced persistence techniques. The attack was notable for leveraging an external AWS account to assume roles within the victim's environmen...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[State-Sponsored APT Abuse Visual Studio Code in Attacks (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/state-sponsored-apt-abuse-visual-studio-code-in-attacks</link>
            <guid isPermaLink="false">159d8c76-b6ae-80ab-bc4c-ee2fdf1c78f0</guid>
            <pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Operation Digital Eye, a suspected China-nexus cyberespionage campaign, targeted business-to-business IT service providers in Southern Europe from late June to mid-July 2024. The attacks aimed to establish strategic footholds for further compromise of downstream entities. Thre...]]></description>
            <content:encoded><![CDATA[Operation Digital Eye, a suspected China-nexus cyberespionage campaign, targeted business-to-business IT service providers in Southern Europe from late June to mid-July 2024. The attacks aimed to establish strategic footholds for further compromise of downstream entities. Thre...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Ultralytics compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/ultralytics-compromise</link>
            <guid isPermaLink="false">159d8c76-b6ae-80f8-8143-f7307b8a2bd7</guid>
            <pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for many packages. On December 5, 2024 security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromise...]]></description>
            <content:encoded><![CDATA[Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for many packages. On December 5, 2024 security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromise...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Solana web3.js Supply Chain Attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/solana-web3js-supply-chain-attack</link>
            <guid isPermaLink="false">1fbd8c76-b6ae-8052-85c4-f5782f367004</guid>
            <pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On December 3, 2024, a critical supply chain attack was uncovered targeting versions 1.95.6 and 1.95.7 of the widely-used @solana/web3.js JavaScript library. The attack involved a malicious backdoor injected via a compromised npm publish account. Once deployed, the backdoor ca...]]></description>
            <content:encoded><![CDATA[On December 3, 2024, a critical supply chain attack was uncovered targeting versions 1.95.6 and 1.95.7 of the widely-used @solana/web3.js JavaScript library. The attack involved a malicious backdoor injected via a compromised npm publish account. Once deployed, the backdoor ca...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gafgyt Malware Targeting Misconfigured Docker Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gafgyt-malware-targeting-misconfigured-docker-servers</link>
            <guid isPermaLink="false">159d8c76-b6ae-8075-bf70-dad835239db5</guid>
            <pubDate>Tue, 03 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified threat actors leveraging misconfigured Docker Remote API servers to deploy the Gafgyt malware, traditionally targeting IoT devices, to perform DDoS attacks. Attackers exploit these misconfigurations to create Docker containers, elevate privileges, and ex...]]></description>
            <content:encoded><![CDATA[Researchers identified threat actors leveraging misconfigured Docker Remote API servers to deploy the Gafgyt malware, traditionally targeting IoT devices, to perform DDoS attacks. Attackers exploit these misconfigurations to create Docker containers, elevate privileges, and ex...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mauri Ransomware Exploiting Apache ActiveMQ (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mauri-ransomware-exploiting-apache-activemq</link>
            <guid isPermaLink="false">159d8c76-b6ae-800f-b0ef-c0636d3cb742</guid>
            <pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[CVE-2023-46604 is a critical Remote Code Execution (RCE) vulnerability in Apache ActiveMQ. This vulnerability may allow a remote attacker with network access to a broker to run arbitrary commands due to an insecure deserialization in the OpenWire protocol.The vulnerability is ...]]></description>
            <content:encoded><![CDATA[CVE-2023-46604 is a critical Remote Code Execution (RCE) vulnerability in Apache ActiveMQ. This vulnerability may allow a remote attacker with network access to a broker to run arbitrary commands due to an insecure deserialization in the OpenWire protocol.The vulnerability is ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gelsemium’s Shift to Linux Malware with WolfsBane and FireWood (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gelsemiums-shift-to-linux-malware-with-wolfsbane-and-firewood</link>
            <guid isPermaLink="false">148d8c76-b6ae-80c7-bade-e288b4678078</guid>
            <pubDate>Thu, 21 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[ESET researchers have identified two Linux backdoors, WolfsBane and FireWood, linked to the China-aligned Gelsemium APT group. WolfsBane is the Linux counterpart of Gelsevirine, a Windows backdoor, and is attributed to Gelsemium with high confidence due to shared features like...]]></description>
            <content:encoded><![CDATA[ESET researchers have identified two Linux backdoors, WolfsBane and FireWood, linked to the China-aligned Gelsemium APT group. WolfsBane is the Linux counterpart of Gelsevirine, a Windows backdoor, and is attributed to Gelsemium with high confidence due to shared features like...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Sports Piracy Exploiting Misconfigured Jupyter Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sports-piracy-exploiting-misconfigured-jupyter-servers</link>
            <guid isPermaLink="false">145d8c76-b6ae-80c0-81c8-f2fca52544f5</guid>
            <pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Threat actors have developed an attack leveraging misconfigured JupyterLab and Jupyter Notebook servers to conduct illegal live streaming of sports events. By exploiting unauthenticated access to these environments, attackers deploy the open-source tool ffmpeg to capture and r...]]></description>
            <content:encoded><![CDATA[Threat actors have developed an attack leveraging misconfigured JupyterLab and Jupyter Notebook servers to conduct illegal live streaming of sports events. By exploiting unauthenticated access to these environments, attackers deploy the open-source tool ffmpeg to capture and r...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Earth Kasha’s Campaign Exploiting Fortinet Vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/earth-kashas-campaign-exploiting-fortinet-vulnerability</link>
            <guid isPermaLink="false">143d8c76-b6ae-8053-a330-db5a3cf0f272</guid>
            <pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered a new campaign by Earth Kasha, a threat group targeting Japan, Taiwan, and India since 2019, with connections to the broader APT10 umbrella. This recent campaign, beginning in 2023, employs updated TTPs, including exploiting vulnerabilities like CVE-2023...]]></description>
            <content:encoded><![CDATA[Researchers discovered a new campaign by Earth Kasha, a threat group targeting Japan, Taiwan, and India since 2019, with connections to the broader APT10 umbrella. This recent campaign, beginning in 2023, employs updated TTPs, including exploiting vulnerabilities like CVE-2023...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BrazenBamboo Weaponizes FortiClient Vulnerability to Steal Credentials (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-credentials</link>
            <guid isPermaLink="false">141d8c76-b6ae-80d6-9290-fccfbbaf21e1</guid>
            <pubDate>Fri, 15 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[A zero-day vulnerability in Fortinet's Windows VPN client, FortiClient, was discovered by Volexity, allowing user credentials to remain in process memory after authentication. This vulnerability was exploited by BrazenBamboo, a Chinese state-affiliated threat actor, using a pl...]]></description>
            <content:encoded><![CDATA[A zero-day vulnerability in Fortinet's Windows VPN client, FortiClient, was discovered by Volexity, allowing user credentials to remain in process memory after authentication. This vulnerability was exploited by BrazenBamboo, a Chinese state-affiliated threat actor, using a pl...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RCE Vulnerability in PAN-OS Exploited in-the-Wild (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/rce-vulnerability-in-pan-os-exploited-in-the-wild</link>
            <guid isPermaLink="false">141d8c76-b6ae-8040-9638-cbc22f36ec1e</guid>
            <pubDate>Fri, 08 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Palo Alto Networks has confirmed the active exploitation of a critical remote code execution vulnerability (CVE-2024-0012) in the PAN-OS management interface. This vulnerability allows an unauthenticated attacker with network access to the management interface to bypass authen...]]></description>
            <content:encoded><![CDATA[Palo Alto Networks has confirmed the active exploitation of a critical remote code execution vulnerability (CVE-2024-0012) in the PAN-OS management interface. This vulnerability allows an unauthenticated attacker with network access to the management interface to bypass authen...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Silent Skimmer Attacks Exploiting Telerik UI to Steal Payment Data (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/silent-skimmer-attacks-exploiting-telerik-ui-to-steal-payment-data</link>
            <guid isPermaLink="false">13ed8c76-b6ae-8077-a104-f842cb779900</guid>
            <pubDate>Thu, 07 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In May 2024, researchers observed an attack by the Silent Skimmer threat actor, targeting a multinational organization’s payment infrastructure. This attack exploited known vulnerabilities in Telerik UI to gain unauthorized access and deploy various malicious tools, including ...]]></description>
            <content:encoded><![CDATA[In May 2024, researchers observed an attack by the Silent Skimmer threat actor, targeting a multinational organization’s payment infrastructure. This attack exploited known vulnerabilities in Telerik UI to gain unauthorized access and deploy various malicious tools, including ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mozi Botnet Using AndroxGh0st Toolkit to Target Cloud Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mozi-botnet-using-androxgh0st-toolkit-to-target-cloud-environments</link>
            <guid isPermaLink="false">13dd8c76-b6ae-8008-a948-dd6175418579</guid>
            <pubDate>Wed, 06 Nov 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers at CloudSEK’s Threat Research team identified major developments in the Androxgh0st toolkit, expanding its arsenal of vulnerabilities, and noticed a potential operational integration with the Mozi botnet. First observed in early 2024, Androxgh0st integrates Mozi’s ...]]></description>
            <content:encoded><![CDATA[Researchers at CloudSEK’s Threat Research team identified major developments in the Androxgh0st toolkit, expanding its arsenal of vulnerabilities, and noticed a potential operational integration with the Mozi botnet. First observed in early 2024, Androxgh0st integrates Mozi’s ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Supply Chain Attack on lottie-player (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/supply-chain-attack-on-lottie-player</link>
            <guid isPermaLink="false">133d8c76-b6ae-80d5-9627-d1d2a045dd2a</guid>
            <pubDate>Thu, 31 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On October 30, 2024, a supply chain attack was initiated against the popular JavaScript library lottie-player, injecting malicious code that populates a Web3 wallet connection prompt on legitimate websites using the library, potentially targeting prominent cryptocurrency platf...]]></description>
            <content:encoded><![CDATA[On October 30, 2024, a supply chain attack was initiated against the popular JavaScript library lottie-player, injecting malicious code that populates a Web3 wallet connection prompt on legitimate websites using the library, potentially targeting prominent cryptocurrency platf...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cyberoam breach (2018) (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cyberoam-breach-2018</link>
            <guid isPermaLink="false">131d8c76-b6ae-80d5-9734-dffd691deac6</guid>
            <pubDate>Thu, 31 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-10-31, an incident was reported, involving Volt Typhoon, APT31, APT41, gaining initial access via Unknown, while using SSM misconfiguration abuse, to achieve Data exfiltration. The following tools were observed: CloudSnooper, Onderon, Gh0st RAT.]]></description>
            <content:encoded><![CDATA[On 2024-10-31, an incident was reported, involving Volt Typhoon, APT31, APT41, gaining initial access via Unknown, while using SSM misconfiguration abuse, to achieve Data exfiltration. The following tools were observed: CloudSnooper, Onderon, Gh0st RAT.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SharePoint Vulnerability Exploited in-the-Wild (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sharepoint-vulnerability-exploited-in-the-wild</link>
            <guid isPermaLink="false">13ed8c76-b6ae-802c-8df5-cfc352a32fb4</guid>
            <pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed an attacker exploiting CVE-2024-38094—a vulnerability in Microsoft SharePoint. The attacker gained unauthorized access, escalated privileges, and moved laterally across the network to gain control over the entire domain. Through various techniques, includi...]]></description>
            <content:encoded><![CDATA[Researchers observed an attacker exploiting CVE-2024-38094—a vulnerability in Microsoft SharePoint. The attacker gained unauthorized access, escalated privileges, and moved laterally across the network to gain control over the entire domain. Through various techniques, includi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[EMERALDWHALE Attacks Targeting Exposed Git Config Files (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/emeraldwhale-attacks-targeting-exposed-git-config-files</link>
            <guid isPermaLink="false">133d8c76-b6ae-8088-a93c-c7e366a555ec</guid>
            <pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Research uncovered an operation named EMERALDWHALE that compromised over 15,000 cloud service credentials by exploiting exposed Git configurations and other misconfigured web services. The attack aimed to steal credentials from private Git repositories and cloud environments, ...]]></description>
            <content:encoded><![CDATA[Research uncovered an operation named EMERALDWHALE that compromised over 15,000 cloud service credentials by exploiting exposed Git configurations and other misconfigured web services. The attack aimed to steal credentials from private Git repositories and cloud environments, ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Amazon DB exposed with Prime Video viewing habits (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/amazon-db-exposed-with-prime-video-viewing-habits</link>
            <guid isPermaLink="false">134d8c76-b6ae-80cf-ad48-e63ca258ea03</guid>
            <pubDate>Sun, 27 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Security researcher Anurag Sen discovered an unprotected Amazon Prime database containing pseudonymized viewing data, accessible from the internet without a password. Named "Sauron," the Elasticsearch database held approximately 215 million records, including information on st...]]></description>
            <content:encoded><![CDATA[Security researcher Anurag Sen discovered an unprotected Amazon Prime database containing pseudonymized viewing data, accessible from the internet without a password. Named "Sauron," the Elasticsearch database held approximately 215 million records, including information on st...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TeamTNT’s Docker Gatling Gun Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/teamtnts-docker-gatling-gun-campaign</link>
            <guid isPermaLink="false">12cd8c76-b6ae-8005-b3ea-cca31cf36ece</guid>
            <pubDate>Fri, 25 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed TeamTNT, a threat group known to target cloud environments, in a campaign targeting cloud-native environments by compromising exposed Docker daemons. Using Docker Hub to distribute malware, the group employs cryptominers and the Sliver malware, enhancing t...]]></description>
            <content:encoded><![CDATA[Researchers observed TeamTNT, a threat group known to target cloud environments, in a campaign targeting cloud-native environments by compromising exposed Docker daemons. Using Docker Hub to distribute malware, the group employs cryptominers and the Sliver malware, enhancing t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC5820 exploiting FortiManager flaw (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc5820-exploiting-fortimanager-flaw</link>
            <guid isPermaLink="false">12dd8c76-b6ae-80fc-bd4d-dfa718527dad</guid>
            <pubDate>Thu, 24 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified a zero-day vulnerability, CVE-2024-47575, impacting FortiManager, exploited by the UNC5820 group. This flaw allows unauthorized access, enabling threat actors to exfiltrate critical configuration data. The vulnerability has been actively exploited, with ...]]></description>
            <content:encoded><![CDATA[Researchers identified a zero-day vulnerability, CVE-2024-47575, impacting FortiManager, exploited by the UNC5820 group. This flaw allows unauthorized access, enabling threat actors to exfiltrate critical configuration data. The vulnerability has been actively exploited, with ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Prometei campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/prometei-campaign</link>
            <guid isPermaLink="false">12cd8c76-b6ae-80ea-8154-e94226537416</guid>
            <pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The Prometei botnet attempted to infiltrate a company’s network using a brute-force attack. Researchers from Trend Micro identified and mitigated the threat by tracing Prometei’s stealthy, modular structure. Prometei, primarily aimed at cryptocurrency mining and credential the...]]></description>
            <content:encoded><![CDATA[The Prometei botnet attempted to infiltrate a company’s network using a brute-force attack. Researchers from Trend Micro identified and mitigated the threat by tracing Prometei’s stealthy, modular structure. Prometei, primarily aimed at cryptocurrency mining and credential the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Triad Nexus: Funnull malicious campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/triad-nexus-funnull-malicious-campaign</link>
            <guid isPermaLink="false">12dd8c76-b6ae-803d-ade3-fa7ddc3292f5</guid>
            <pubDate>Tue, 22 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Silent Push’s investigation into FUNNULL, a Chinese CDN, reveals its role in hosting extensive malicious infrastructure dubbed "Triad Nexus." This includes over 200,000 algorithmically generated domains connected to gambling, investment scams, phishing, and a supply chain atta...]]></description>
            <content:encoded><![CDATA[Silent Push’s investigation into FUNNULL, a Chinese CDN, reveals its role in hosting extensive malicious infrastructure dubbed "Triad Nexus." This includes over 200,000 algorithmically generated domains connected to gambling, investment scams, phishing, and a supply chain atta...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[perfctl campaign targeting Docker API (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/perfctl-campaign-targeting-docker-api</link>
            <guid isPermaLink="false">12cd8c76-b6ae-8016-bc46-d46b5be75255</guid>
            <pubDate>Mon, 21 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Attackers are exploiting exposed Docker Remote API servers to deploy a new malware strain named "perfctl." This malware is designed to mine cryptocurrency and can evade detection by disabling security features and establishing persistence on compromised systems. The attackers ...]]></description>
            <content:encoded><![CDATA[Attackers are exploiting exposed Docker Remote API servers to deploy a new malware strain named "perfctl." This malware is designed to mine cryptocurrency and can evade detection by disabling security features and establishing persistence on compromised systems. The attackers ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[EA cross-user access via API (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/ea-cross-user-access-via-api</link>
            <guid isPermaLink="false">175d8c76-b6ae-8048-b136-ec1261532f71</guid>
            <pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-10-18, a research was reported, involving , gaining initial access via API vulnerability, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-10-18, a research was reported, involving , gaining initial access via API vulnerability, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Earth Simnavaz (APT34) Targeting UAE and Gulf Regions (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/earth-simnavaz-apt34-targeting-uae-and-gulf-regions</link>
            <guid isPermaLink="false">11fd8c76-b6ae-8076-b279-ebf1c2b9b498</guid>
            <pubDate>Fri, 11 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers at Trend Micro identified cyberattacks by Earth Simnavaz (also known as APT34 or OilRig), targeting UAE and Gulf region entities. The group exploits vulnerabilities, including CVE-2024-30088, to escalate privileges and deploy backdoors via Microsoft Exchange server...]]></description>
            <content:encoded><![CDATA[Researchers at Trend Micro identified cyberattacks by Earth Simnavaz (also known as APT34 or OilRig), targeting UAE and Gulf region entities. The group exploits vulnerabilities, including CVE-2024-30088, to escalate privileges and deploy backdoors via Microsoft Exchange server...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Game Freak data leak (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/game-freak-data-leak</link>
            <guid isPermaLink="false">1f7d8c76-b6ae-80fe-9a6d-e8aab368a6a9</guid>
            <pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-10-10, an incident was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Exposed git config files abuse, targeting GitLab to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-10-10, an incident was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Exposed git config files abuse, targeting GitLab to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[APT29 Targeting Zimbra and TeamCity Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apt29-targeting-zimbra-and-teamcity-servers</link>
            <guid isPermaLink="false">11fd8c76-b6ae-8027-997a-cd837f87ae24</guid>
            <pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The U.S. and U.K. cyber agencies have issued a joint advisory warning about Russian Foreign Intelligence Service (SVR)-linked attackers, tracked as APT29 (a.k.a Cozy Bear or Midnight Blizzard). These actors are exploiting vulnerabilities in Zimbra and JetBrains TeamCity server...]]></description>
            <content:encoded><![CDATA[The U.S. and U.K. cyber agencies have issued a joint advisory warning about Russian Foreign Intelligence Service (SVR)-linked attackers, tracked as APT29 (a.k.a Cozy Bear or Midnight Blizzard). These actors are exploiting vulnerabilities in Zimbra and JetBrains TeamCity server...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Veeam Vulnerability Exploited by Akira and Fog Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/veeam-vulnerability-exploited-by-akira-and-fog-ransomware</link>
            <guid isPermaLink="false">11fd8c76-b6ae-80b1-bd47-ebc941cd27a8</guid>
            <pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[CVE-2024-40711 arises from the deserialization of untrusted data in the Veeam Backup & Replication software. This vulnerability can be exploited with low-complexity attacks, making it a threat to organizations relying on Veeam’s platform for backup, disaster recovery, and data...]]></description>
            <content:encoded><![CDATA[CVE-2024-40711 arises from the deserialization of untrusted data in the Veeam Backup & Replication software. This vulnerability can be exploited with low-complexity attacks, making it a threat to organizations relying on Veeam’s platform for backup, disaster recovery, and data...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LLMJacking for Roleplaying Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/llmjacking-for-roleplaying-campaign</link>
            <guid isPermaLink="false">2f8d8c76-b6ae-805c-8d94-d060818a9e4a</guid>
            <pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In September 2024, threat actors conducted a campaign exploiting exposed AWS access keys to hijack AWS Bedrock services for operating illicit AI-powered roleplay chatbots. The attackers leverage compromised long-lived credentials (AKIA keys) discovered primarily through GitHub...]]></description>
            <content:encoded><![CDATA[In September 2024, threat actors conducted a campaign exploiting exposed AWS access keys to hijack AWS Bedrock services for operating illicit AI-powered roleplay chatbots. The attackers leverage compromised long-lived credentials (AKIA keys) discovered primarily through GitHub...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[perfctl Malware Targeting Linux (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/perfctl-malware-targeting-linux</link>
            <guid isPermaLink="false">119d8c76-b6ae-80a4-a385-f95c3752ad85</guid>
            <pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers investigated the "perfctl malware," a Linux malware targeting misconfigurations and vulnerabilities on Linux servers. Perfctl employs rootkits, privilege escalation exploits, and cryptomining activities. It also uses tactics such as process masquerading and deletin...]]></description>
            <content:encoded><![CDATA[Researchers investigated the "perfctl malware," a Linux malware targeting misconfigurations and vulnerabilities on Linux servers. Perfctl employs rootkits, privilege escalation exploits, and cryptomining activities. It also uses tactics such as process masquerading and deletin...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Rackspace incident (2024) (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/rackspace-incident-2024</link>
            <guid isPermaLink="false">11ed8c76-b6ae-80da-b257-e5c635079baf</guid>
            <pubDate>Mon, 30 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-09-30, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, targeting ScienceLogic SL1 to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-09-30, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, targeting ScienceLogic SL1 to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[REF6138 campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ref6138-campaign</link>
            <guid isPermaLink="false">112d8c76-b6ae-8017-9ca7-da33a9fa59db</guid>
            <pubDate>Fri, 27 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Elastic Security Labs uncovered a Linux malware campaign that began in March 2024, targeting vulnerable servers via an Apache2 web server exploit. The attackers gained access and deployed a variety of tools and malware families, including KAIJI, known for its DDoS capabilities...]]></description>
            <content:encoded><![CDATA[Elastic Security Labs uncovered a Linux malware campaign that began in March 2024, targeting vulnerable servers via an Apache2 web server exploit. The attackers gained access and deployed a variety of tools and malware families, including KAIJI, known for its DDoS capabilities...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Storm-0501 Targeting Hybrid Environments with Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/storm-0501-targeting-hybrid-environments-with-ransomware</link>
            <guid isPermaLink="false">119d8c76-b6ae-8051-8fec-d60c1c834eec</guid>
            <pubDate>Thu, 26 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Storm-0501 has been observed conducting multi-staged attacks targeting hybrid cloud environments across various U.S. sectors, including government and manufacturing. These attacks involve lateral movement from on-premises environments to the cloud, leading to data exfiltration...]]></description>
            <content:encoded><![CDATA[Storm-0501 has been observed conducting multi-staged attacks targeting hybrid cloud environments across various U.S. sectors, including government and manufacturing. These attacks involve lateral movement from on-premises environments to the cloud, leading to data exfiltration...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Storm-0501 attacking hybrid environments with ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/storm-0501-attacking-hybrid-environments-with-ransomware</link>
            <guid isPermaLink="false">112d8c76-b6ae-8065-afcd-dd830bbd68ad</guid>
            <pubDate>Thu, 26 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft sheds light on the activities of Storm-0501, a threat actor known for deploying ransomware attacks in hybrid cloud environments. The group has expanded its operations to target both on-premises and cloud resources, posing significant risks to organizations utilizing ...]]></description>
            <content:encoded><![CDATA[Microsoft sheds light on the activities of Storm-0501, a threat actor known for deploying ransomware attacks in hybrid cloud environments. The group has expanded its operations to target both on-premises and cloud resources, posing significant risks to organizations utilizing ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Docker Swarm and K8s cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/docker-swarm-and-k8s-cryptojacking-campaign</link>
            <guid isPermaLink="false">112d8c76-b6ae-80ab-b342-e88544c99167</guid>
            <pubDate>Mon, 23 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Datadog Security Research has uncovered a sophisticated cryptojacking campaign targeting microservice technologies, specifically Docker and Kubernetes. The threat actors exploit exposed Docker Engine APIs to gain initial access, deploying cryptocurrency miners on compromised c...]]></description>
            <content:encoded><![CDATA[Datadog Security Research has uncovered a sophisticated cryptojacking campaign targeting microservice technologies, specifically Docker and Kubernetes. The threat actors exploit exposed Docker Engine APIs to gain initial access, deploying cryptocurrency miners on compromised c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC1860 Attacks Targeting the Middle East (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc1860-attacks-targeting-the-middle-east</link>
            <guid isPermaLink="false">10bd8c76-b6ae-8056-b3fe-fc9f2c7c67d3</guid>
            <pubDate>Fri, 20 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[UNC1860 is an Iranian state-sponsored threat actor, likely affiliated with Iran's Ministry of Intelligence and Security (MOIS). This group specializes in gaining persistent access to high-priority networks, especially in the government and telecommunications sectors in the Mid...]]></description>
            <content:encoded><![CDATA[UNC1860 is an Iranian state-sponsored threat actor, likely affiliated with Iran's Ministry of Intelligence and Security (MOIS). This group specializes in gaining persistent access to high-priority networks, especially in the government and telecommunications sectors in the Mid...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scattered Spider targeting GCP environment (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/scattered-spider-targeting-gcp-environment</link>
            <guid isPermaLink="false">111d8c76-b6ae-80cd-91b4-c07554173706</guid>
            <pubDate>Tue, 17 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via Unknown, while using Create or modify firewall or security group rules, OS password reset, Create SSH backdoor, Modify compute startup script, Launch new cloud resources, Delete compute snapshot, to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via Unknown, while using Create or modify firewall or security group rules, OS password reset, Create SSH backdoor, Modify compute startup script, Launch new cloud resources, Delete compute snapshot, to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scattered Spider targeting Azure environment (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/scattered-spider-targeting-azure-environment</link>
            <guid isPermaLink="false">111d8c76-b6ae-80c0-a1a7-f5d6d43bc70a</guid>
            <pubDate>Tue, 17 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Vishing, MFA enrollment, Cloud API e, to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Vishing, MFA enrollment, Cloud API e, to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GitHub PAT leakage leading to RDS Database exfiltration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/github-pat-leakage-leading-to-rds-database-exfiltration</link>
            <guid isPermaLink="false">111d8c76-b6ae-8030-9050-e8a4b9878706</guid>
            <pubDate>Tue, 17 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-09-17, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, targeting GitHub to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-09-17, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, targeting GitHub to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Fortinet Sharepoint data leak (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/fortinet-sharepoint-data-leak</link>
            <guid isPermaLink="false">b9241975-3b5b-45a1-b67a-1655c028cfab</guid>
            <pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Fortinet confirmed a data breach where a threat actor, "Fortibitch," claimed to have stolen 440GB of data from the company's Microsoft Sharepoint server. The threat actor reportedly shared access credentials to an S3 bucket containing the stolen data and attempted to extort Fo...]]></description>
            <content:encoded><![CDATA[Fortinet confirmed a data breach where a threat actor, "Fortibitch," claimed to have stolen 440GB of data from the company's Microsoft Sharepoint server. The threat actor reportedly shared access credentials to an S3 bucket containing the stolen data and attempted to extort Fo...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Campaign targeting Selenium Grid for cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/campaign-targeting-selenium-grid-for-cryptomining</link>
            <guid isPermaLink="false">104d8c76-b6ae-80b0-8d15-fd377c4e0478</guid>
            <pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Cado Security Labs discovered two campaigns exploiting misconfigured Selenium Grid instances to deploy malware, including an exploit kit, cryptominer, and proxyjacker. Selenium Grid is widely used for browser automation and testing, but its default configuration lacks authenti...]]></description>
            <content:encoded><![CDATA[Cado Security Labs discovered two campaigns exploiting misconfigured Selenium Grid instances to deploy malware, including an exploit kit, cryptominer, and proxyjacker. Selenium Grid is widely used for browser automation and testing, but its default configuration lacks authenti...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Hadooken Malware Targeting Weblogic Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/hadooken-malware-targeting-weblogic-servers</link>
            <guid isPermaLink="false">103d8c76-b6ae-8043-ba7e-fd1b722eea5d</guid>
            <pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered a new Linux malware named "Hadooken" that specifically targets Oracle WebLogic servers. The malware exploits weak passwords to gain access and then deploys both Tsunami malware and a cryptominer. The attack flow involves using a combination of shell and ...]]></description>
            <content:encoded><![CDATA[Researchers discovered a new Linux malware named "Hadooken" that specifically targets Oracle WebLogic servers. The malware exploits weak passwords to gain access and then deploys both Tsunami malware and a cryptominer. The attack flow involves using a combination of shell and ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DragonRank Targeting IIS Web Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dragonrank-targeting-iis-web-servers</link>
            <guid isPermaLink="false">e0916fe6-5ec7-4239-880c-14397eff7de9</guid>
            <pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified a "DragonRank" campaign targeting countries in Asia and Europe. This group exploits web application services to deploy web shells and malware like PlugX and BadIIS, primarily for manipulating search engine rankings. The campaign has affected more than 35...]]></description>
            <content:encoded><![CDATA[Researchers identified a "DragonRank" campaign targeting countries in Asia and Europe. This group exploits web application services to deploy web shells and malware like PlugX and BadIIS, primarily for manipulating search engine rankings. The campaign has affected more than 35...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Godzilla Backdoor Exploiting Confluence Vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/godzilla-backdoor-exploiting-confluence-vulnerability</link>
            <guid isPermaLink="false">fa83ff8c-b56c-4d86-b0e2-37b6a898645c</guid>
            <pubDate>Fri, 30 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered a new attack exploiting the CVE-2023-22527. The attack uses an in-memory fileless backdoor, known as the Godzilla webshell. The Godzilla backdoor uses AES encryption for communication and remains in memory, making it difficult to identify. It is recommen...]]></description>
            <content:encoded><![CDATA[Researchers discovered a new attack exploiting the CVE-2023-22527. The attack uses an in-memory fileless backdoor, known as the Godzilla webshell. The Godzilla backdoor uses AES encryption for communication and remains in memory, making it difficult to identify. It is recommen...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Confluence exploited for cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/confluence-exploited-for-cryptojacking</link>
            <guid isPermaLink="false">106d8c76-b6ae-80ba-8e51-e3848c8143fb</guid>
            <pubDate>Wed, 28 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The critical vulnerability CVE-2023-22527 is being actively exploited for cryptojacking activities, turning affected Confluence Data Center and Server instances into cryptomining networks. Attackers exploit this vulnerability through methods like deploying shell scripts and XM...]]></description>
            <content:encoded><![CDATA[The critical vulnerability CVE-2023-22527 is being actively exploited for cryptojacking activities, turning affected Confluence Data Center and Server instances into cryptomining networks. Attackers exploit this vulnerability through methods like deploying shell scripts and XM...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ShinyHunters Ransomware Targeting Cloud Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/shinyhunters-ransomware-targeting-cloud-environments</link>
            <guid isPermaLink="false">bae5334c-c0e7-40b5-9bd9-3c60a8433fec</guid>
            <pubDate>Fri, 23 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat actor group Bling Libra (behind ShinyHunters ransomware) has been observed infiltrating an organization's Amazon Web Services (AWS) environment, focusing on extortion rather than selling stolen data. Using legitimate credentials sourced from public repositories, the...]]></description>
            <content:encoded><![CDATA[The threat actor group Bling Libra (behind ShinyHunters ransomware) has been observed infiltrating an organization's Amazon Web Services (AWS) environment, focusing on extortion rather than selling stolen data. Using legitimate credentials sourced from public repositories, the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PG_MEM Malware Exploiting Misconfigured PostreSQL Instances (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/pgmem-malware-exploiting-misconfigured-postresql-instances</link>
            <guid isPermaLink="false">241ed599-3f41-4cce-aee3-a4d46a0b8e09</guid>
            <pubDate>Mon, 19 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers have discovered a new PostgreSQL malware called PG_MEM, which uses brute force attacks to access databases, hide its operations, and mine cryptocurrency. The attack involves creating a superuser role, delivering two malware payloads, and evading detection while eli...]]></description>
            <content:encoded><![CDATA[Researchers have discovered a new PostgreSQL malware called PG_MEM, which uses brute force attacks to access databases, hide its operations, and mine cryptocurrency. The attack involves creating a superuser role, delivering two malware payloads, and evading detection while eli...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Msupedge Backdoor Targeting Taiwanese University (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/msupedge-backdoor-targeting-taiwanese-university</link>
            <guid isPermaLink="false">f8228cb8-b835-44a9-8bd0-614e44c93e1c</guid>
            <pubDate>Mon, 19 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[A newly discovered backdoor, dubbed Backdoor.Msupedge, was used in an attack on a Taiwanese university, leveraging an unusual communication method through DNS traffic to reach its command-and-control (C&C) server. While DNS-based communication is known among threat actors, its...]]></description>
            <content:encoded><![CDATA[A newly discovered backdoor, dubbed Backdoor.Msupedge, was used in an attack on a Taiwanese university, leveraging an unusual communication method through DNS traffic to reach its command-and-control (C&C) server. While DNS-based communication is known among threat actors, its...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Extortion Campaign Exploiting Exposed Environment Variable (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/extortion-campaign-exploiting-exposed-environment-variable</link>
            <guid isPermaLink="false">d9452e24-3c47-44ef-905f-c0549a1caa79</guid>
            <pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered an extortion campaign that exploited exposed environment variable files (.env) in cloud environments. These files, which contained sensitive credentials, were accessed and leveraged by attackers to ransom data from victim organizations. The attackers used...]]></description>
            <content:encoded><![CDATA[Researchers uncovered an extortion campaign that exploited exposed environment variable files (.env) in cloud environments. These files, which contained sensitive credentials, were accessed and leveraged by attackers to ransom data from victim organizations. The attackers used...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gafgyt Malware Targeting Cloud Environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gafgyt-malware-targeting-cloud-environments</link>
            <guid isPermaLink="false">d65fc526-973e-49fa-ba1f-4f86e4bf1d0d</guid>
            <pubDate>Wed, 14 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified a new variant of the Gafgyt botnet targeting cloud-native environments by exploiting weak SSH passwords. This variant integrates cryptomining with traditional botnet activities, using GPU power to mine cryptocurrency. The attack flow includes brute-forci...]]></description>
            <content:encoded><![CDATA[Researchers identified a new variant of the Gafgyt botnet targeting cloud-native environments by exploiting weak SSH passwords. This variant integrates cryptomining with traditional botnet activities, using GPU power to mine cryptocurrency. The attack flow includes brute-forci...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Horde Panda targeting South Asian telecommunications provider  (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/horde-panda-targeting-south-asian-telecommunications-provider-</link>
            <guid isPermaLink="false">6377424d-8a3a-4f03-a171-0fb0a54c8f58</guid>
            <pubDate>Fri, 09 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Between late June 2023 and early August 2023, CrowdStrike detected suspicious activity at a South Asian telecommunications provider linked to the China-based threat group Horde Panda. The adversary used multiple compromised identities to try to embed themselves deeper into the...]]></description>
            <content:encoded><![CDATA[Between late June 2023 and early August 2023, CrowdStrike detected suspicious activity at a South Asian telecommunications provider linked to the China-based threat group Horde Panda. The adversary used multiple compromised identities to try to embed themselves deeper into the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scattered Spider Abuses Cloud Management Agent (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scattered-spider-abuses-cloud-management-agent</link>
            <guid isPermaLink="false">241e61c7-404d-4447-ab6b-ae00e03266df</guid>
            <pubDate>Fri, 09 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In May 2024, CrowdStrike observed the cyber threat group Scattered Spider establish a foothold on a cloud-hosted virtual machine (VM) using a cloud service VM management agent. The attackers compromised existing credentials through a phishing campaign to authenticate to the cl...]]></description>
            <content:encoded><![CDATA[In May 2024, CrowdStrike observed the cyber threat group Scattered Spider establish a foothold on a cloud-hosted virtual machine (VM) using a cloud service VM management agent. The attackers compromised existing credentials through a phishing campaign to authenticate to the cl...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Earth Baku campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/earth-baku-campaign</link>
            <guid isPermaLink="false">82001eea-36db-4932-95a3-177387279af4</guid>
            <pubDate>Fri, 09 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Earth Baku, a threat actor linked to APT41, has extended its operations beyond the Indo-Pacific, targeting regions across Europe, the Middle East, and Africa, including countries such as Italy, Germany, the UAE, and Qatar, with suspected activities in Georgia and Romania. The ...]]></description>
            <content:encoded><![CDATA[Earth Baku, a threat actor linked to APT41, has extended its operations beyond the Indo-Pacific, targeting regions across Europe, the Middle East, and Africa, including countries such as Italy, Germany, the UAE, and Qatar, with suspected activities in Georgia and Romania. The ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Panamorfi campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/panamorfi-campaign</link>
            <guid isPermaLink="false">760ab810-7a33-4aa6-b651-f2f9534ed7f8</guid>
            <pubDate>Fri, 02 Aug 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-08-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Denial of service. The following tools were observed: Mineping.]]></description>
            <content:encoded><![CDATA[On 2024-08-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Denial of service. The following tools were observed: Mineping.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mirai Botnet Exploiting Apache OFBiz Vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mirai-botnet-exploiting-apache-ofbiz-vulnerability</link>
            <guid isPermaLink="false">3b5b9850-9930-434e-bb1b-c422968d024d</guid>
            <pubDate>Wed, 31 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The Apache Foundation's OFBiz, an open-source Java-based ERP framework, addressed in May 2024 a critical security vulnerability (CVE-2024-32113) involving path traversal that could lead to remote command execution. Despite its lesser prevalence compared to commercial ERP syste...]]></description>
            <content:encoded><![CDATA[The Apache Foundation's OFBiz, an open-source Java-based ERP framework, addressed in May 2024 a critical security vulnerability (CVE-2024-32113) involving path traversal that could lead to remote command execution. Despite its lesser prevalence compared to commercial ERP syste...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Ransomware operators exploit ESXi vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ransomware-operators-exploit-esxi-vulnerability</link>
            <guid isPermaLink="false">f456e63d-a4c7-4851-ae9e-e89e857390de</guid>
            <pubDate>Mon, 29 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft researchers have discovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085. This flaw is being exploited by ransomware operators to gain full administrative access to domain-joined ESXi hypervisors, enabling them to encrypt file systems, access hos...]]></description>
            <content:encoded><![CDATA[Microsoft researchers have discovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085. This flaw is being exploited by ransomware operators to gain full administrative access to domain-joined ESXi hypervisors, enabling them to encrypt file systems, access hos...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BORN Group supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/born-group-supply-chain-attack</link>
            <guid isPermaLink="false">d2fbde71-5fa3-4521-a568-97177bff3d5a</guid>
            <pubDate>Thu, 25 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-07-25, an incident was reported, involving IntelBroker, gaining initial access via 1-day vulnerability, while using Network lateral movement, SSH key compromise, Local privilege escalation via vulnerability exploitation, targeting Jenkins, GitHub to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2024-07-25, an incident was reported, involving IntelBroker, gaining initial access via 1-day vulnerability, while using Network lateral movement, SSH key compromise, Local privilege escalation via vulnerability exploitation, targeting Jenkins, GitHub to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/seleniumgreed-threat-actors-exploit-exposed-selenium-grid-services-for-cryptomining</link>
            <guid isPermaLink="false">48b6ea2a-3a33-4d3a-9ae5-c85f6f4e6bef</guid>
            <pubDate>Thu, 25 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Research has detected an ongoing threat campaign dubbed “SeleniumGreed” that exploits exposed Selenium Grid services to deploy cryptominers. Selenium is a popular open-source suite used for testing web applications, allowing users to write tests that simulate user interact...]]></description>
            <content:encoded><![CDATA[Wiz Research has detected an ongoing threat campaign dubbed “SeleniumGreed” that exploits exposed Selenium Grid services to deploy cryptominers. Selenium is a popular open-source suite used for testing web applications, allowing users to write tests that simulate user interact...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Disney Slack breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/disney-slack-breach</link>
            <guid isPermaLink="false">1ebd8c76-b6ae-8044-9d4a-de2ee55492dd</guid>
            <pubDate>Mon, 15 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-07-15, an incident was reported, involving NullBulge, gaining initial access via End-user compromise, targeting Slack to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-07-15, an incident was reported, involving NullBulge, gaining initial access via End-user compromise, targeting Slack to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[crystalray (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/crystalray</link>
            <guid isPermaLink="false">6dd8f986-3ff3-4b9a-9995-d819ec298a88</guid>
            <pubDate>Thu, 11 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The Sysdig Threat Research Team (TRT) identified a threat actor named CRYSTALRAY, who has significantly expanded its operations since its initial detection in February 2024. CRYSTALRAY exploits multiple vulnerabilities and uses various open source security tools, such as SSH-S...]]></description>
            <content:encoded><![CDATA[The Sysdig Threat Research Team (TRT) identified a threat actor named CRYSTALRAY, who has significantly expanded its operations since its initial detection in February 2024. CRYSTALRAY exploits multiple vulnerabilities and uses various open source security tools, such as SSH-S...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Python infrastructure leaked access token (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/python-infrastructure-leaked-access-token</link>
            <guid isPermaLink="false">3ef45d84-195b-4cfa-a327-9fda8641fe09</guid>
            <pubDate>Mon, 08 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-07-08, a research was reported, involving , gaining initial access via Exposed secret, while using Registry secret scanning, targeting GitHub to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-07-08, a research was reported, involving , gaining initial access via Exposed secret, while using Registry secret scanning, targeting GitHub to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Misconfigured Jenkins Servers Used for Cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/misconfigured-jenkins-servers-used-for-cryptomining</link>
            <guid isPermaLink="false">6ed4679b-88f8-4a70-bdba-cd5e1af6e8c4</guid>
            <pubDate>Fri, 05 Jul 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers discovered attackers targeting misconfigurations in the Jenkins Script Console to execute malicious Groovy scripts, leading to activities such as deploying cryptocurrency miners. By leveraging vulnerabilities and misconfigurations, such as improperly set authentica...]]></description>
            <content:encoded><![CDATA[Researchers discovered attackers targeting misconfigurations in the Jenkins Script Console to execute malicious Groovy scripts, leading to activities such as deploying cryptocurrency miners. By leveraging vulnerabilities and misconfigurations, such as improperly set authentica...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[8220 Gang Exploiting WebLogic Vulnerabilities for Cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/8220-gang-exploiting-weblogic-vulnerabilities-for-cryptojacking</link>
            <guid isPermaLink="false">80b0501d-79b7-413a-b7ae-6b5ce7df6ae4</guid>
            <pubDate>Sun, 30 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Water Sigbin exploits CVE-2017-3506 to gain initial access, deploying a PowerShell script on the compromised machine. This script decodes and executes the first stage payload, named wireguard2-3.exe, in the temporary directory. The malware masquerades as a legitimate VPN appli...]]></description>
            <content:encoded><![CDATA[Water Sigbin exploits CVE-2017-3506 to gain initial access, deploying a PowerShell script on the compromised machine. This script decodes and executes the first stage payload, named wireguard2-3.exe, in the temporary directory. The malware masquerades as a legitimate VPN appli...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Funnull Polyfill supply chain attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/funnull-polyfill-supply-chain-attack</link>
            <guid isPermaLink="false">754df9b9-0a82-48fe-99d2-08c2976227bd</guid>
            <pubDate>Tue, 25 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[A Chinese company named Funnull acquired the Polyfill domain and GitHub repo, and inserted malware into polyfill.js that redirected users to gambling websites. Further pivoting revealed that Funnull had exposed a CloudFlare API key that linked the company to several CDN provid...]]></description>
            <content:encoded><![CDATA[A Chinese company named Funnull acquired the Polyfill domain and GitHub repo, and inserted malware into polyfill.js that redirected users to gambling websites. Further pivoting revealed that Funnull had exposed a CloudFlare API key that linked the company to several CDN provid...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Rabbit AI exposed keys in code (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/rabbit-ai-exposed-keys-in-code</link>
            <guid isPermaLink="false">cad41dd6-9553-457c-ad75-53baa4ca97a2</guid>
            <pubDate>Tue, 25 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Rabbit AI's codebase included several hardcoded API keys for ElevenLabs, Azure, Yelp, Google Maps, and SendGrid. According to the researchers who discovered this, this access would have allowed an attacker to read Rabbit customers' data, make customer devices inoperable, and t...]]></description>
            <content:encoded><![CDATA[Rabbit AI's codebase included several hardcoded API keys for ElevenLabs, Azure, Yelp, Google Maps, and SendGrid. According to the researchers who discovered this, this access would have allowed an attacker to read Rabbit customers' data, make customer devices inoperable, and t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Chinese Threat Actor RedJuliett Exploiting VPN and Firewall Vulnerabilities (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/chinese-threat-actor-redjuliett-exploiting-vpn-and-firewall-vulnerabilities</link>
            <guid isPermaLink="false">4c9c2151-2167-47f0-a3c2-1369d8a7d2a0</guid>
            <pubDate>Mon, 24 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Between November 2023 and April 2024, researchers observed RedJuliett, a likely Chinese state-sponsored cyber-espionage group, targeting entities primarily in Taiwan but also across Asia, Africa, and the US. The focus was on sectors such as government, education, technology, a...]]></description>
            <content:encoded><![CDATA[Between November 2023 and April 2024, researchers observed RedJuliett, a likely Chinese state-sponsored cyber-espionage group, targeting entities primarily in Taiwan but also across Asia, Africa, and the US. The focus was on sectors such as government, education, technology, a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Boolka campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/boolka-campaign</link>
            <guid isPermaLink="false">cb83ea5c-6feb-4839-a003-6a4d6ae73138</guid>
            <pubDate>Fri, 21 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-21, a campaign was reported, involving Boolka, gaining initial access via Web vulnerability, while using SQL injection, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2024-06-21, a campaign was reported, involving Boolka, gaining initial access via Web vulnerability, while using SQL injection, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scattered Spider SaaS targeting (2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scattered-spider-saas-targeting-2024</link>
            <guid isPermaLink="false">1785f203-4514-4d0c-afe8-3609c5739176</guid>
            <pubDate>Fri, 14 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[UNC3944, a financially motivated threat group linked to "0ktapus," "Octo Tempest," "Scatter Swine," and "Scattered Spider," has evolved its tactics to include data theft from SaaS applications, persistence mechanisms in virtualization platforms, and lateral movement via SaaS p...]]></description>
            <content:encoded><![CDATA[UNC3944, a financially motivated threat group linked to "0ktapus," "Octo Tempest," "Scatter Swine," and "Scattered Spider," has evolved its tactics to include data theft from SaaS applications, persistence mechanisms in virtualization platforms, and lateral movement via SaaS p...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[NCS mass server deletion (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/ncs-mass-server-deletion</link>
            <guid isPermaLink="false">05d49414-7160-4471-8337-f2951dff1b1c</guid>
            <pubDate>Thu, 13 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-13, an incident was reported, involving , gaining initial access via Insider threat, to achieve Data destruction.]]></description>
            <content:encoded><![CDATA[On 2024-06-13, an incident was reported, involving , gaining initial access via Insider threat, to achieve Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RCE Vulnerability in PHP CGI Exploited by TellYouThePass (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/rce-vulnerability-in-php-cgi-exploited-by-tellyouthepass</link>
            <guid isPermaLink="false">5684f61b-f8d2-4754-8a80-75469c53785a</guid>
            <pubDate>Mon, 10 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The TellYouThePass ransomware gang has been exploiting the recently patched vulnerability (CVE-2024-4577) in PHP to deploy webshells and execute their encryptor payload on target systems. Attacks started on June 8, just after the release of security updates, using publicly ava...]]></description>
            <content:encoded><![CDATA[The TellYouThePass ransomware gang has been exploiting the recently patched vulnerability (CVE-2024-4577) in PHP to deploy webshells and execute their encryptor payload on target systems. Attacks started on June 8, just after the release of security updates, using publicly ava...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[NYT source code theft (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/nyt-source-code-theft</link>
            <guid isPermaLink="false">ff8b06e1-7afa-475d-8350-0b81a2b238e8</guid>
            <pubDate>Sat, 08 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-06-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DERO cryptojacking campaign (2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dero-cryptojacking-campaign-2024</link>
            <guid isPermaLink="false">5aca975e-b2ad-4d94-a202-d22376ae33c1</guid>
            <pubDate>Fri, 07 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz Threat Research discovered a new variant of a cryptojacking campaign targeting misconfigured Kubernetes clusters in cloud environments. The threat actor abuses cluster anonymous access to deploy malicious container images from Docker Hub that contain a DERO miner. The thre...]]></description>
            <content:encoded><![CDATA[Wiz Threat Research discovered a new variant of a cryptojacking campaign targeting misconfigured Kubernetes clusters in cloud environments. The threat actor abuses cluster anonymous access to deploy malicious container images from Docker Hub that contain a DERO miner. The thre...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scylla LLMJacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scylla-llmjacking-campaign</link>
            <guid isPermaLink="false">f70d7d39-9c3b-4f88-9bfc-d6fcaa136e36</guid>
            <pubDate>Thu, 06 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-06, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using LLMjacking, Cloud key compromise, Cloud API e, targeting Amazon Bedrock to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2024-06-06, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using LLMjacking, Cloud key compromise, Cloud API e, targeting Amazon Bedrock to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gitloker campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gitloker-campaign</link>
            <guid isPermaLink="false">c08f4ded-3458-4a5b-bcf8-0c162e8c0940</guid>
            <pubDate>Wed, 05 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-05, a campaign was reported, involving Gitloker, gaining initial access via End-user compromise, while using Repo encryption for extortion, targeting GitHub to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-06-05, a campaign was reported, involving Gitloker, gaining initial access via End-user compromise, while using Repo encryption for extortion, targeting GitHub to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Club Penguin data theft via Confluence (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/club-penguin-data-theft-via-confluence</link>
            <guid isPermaLink="false">b1d4c90c-43b5-4749-a732-c8b60adefbbf</guid>
            <pubDate>Wed, 05 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Club Penguin fans hacked a Disney Confluence server to obtain information about their favorite game, but ended up with 2.5 GB of internal corporate data. Club Penguin, a popular MMO from 2005 to 2018, continues to exist on private servers run by fans, despite Disney shutting i...]]></description>
            <content:encoded><![CDATA[Club Penguin fans hacked a Disney Confluence server to obtain information about their favorite game, but ended up with 2.5 GB of internal corporate data. Club Penguin, a popular MMO from 2005 to 2018, continues to exist on private servers run by fans, despite Disney shutting i...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Dama webshell deployment via ThinkPHP exploitation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dama-webshell-deployment-via-thinkphp-exploitation</link>
            <guid isPermaLink="false">befe9160-577a-40e9-9f88-642cd1530742</guid>
            <pubDate>Wed, 05 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-05, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ThinkPHP to achieve Resource hijacking. The following tools were observed: Dama.]]></description>
            <content:encoded><![CDATA[On 2024-06-05, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ThinkPHP to achieve Resource hijacking. The following tools were observed: Dama.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Operation Veles (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/operation-veles</link>
            <guid isPermaLink="false">12598dc6-8aa8-45b8-a4d8-fc3795a3dbdd</guid>
            <pubDate>Tue, 04 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-06-04, a campaign was reported, involving UTG-Q-008, gaining initial access via Password attack, while using SSH bruteforcing, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2024-06-04, a campaign was reported, involving UTG-Q-008, gaining initial access via Password attack, while using SSH bruteforcing, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Muhstik (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/muhstik</link>
            <guid isPermaLink="false">176f8441-ce3f-444b-bbea-f33fdbd87d60</guid>
            <pubDate>Tue, 04 Jun 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a new campaign using Muhstik malware to target Apache RocketMQ, a distributed messaging platform, exploiting a remote code execution vulnerability (CVE-2023-33246). Attackers use this vulnerability to download and execute Muhstik malware on compromised in...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a new campaign using Muhstik malware to target Apache RocketMQ, a distributed messaging platform, exploiting a remote code execution vulnerability (CVE-2023-33246). Attackers use this vulnerability to download and execute Muhstik malware on compromised in...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ByteDance Rspack GitHub misconfiguration (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/bytedance-rspack-github-misconfiguration</link>
            <guid isPermaLink="false">2060e772-efe8-4328-bf0f-b920e356c7ab</guid>
            <pubDate>Fri, 31 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-05-31, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-05-31, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RedTail Cryptomining campaign  (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/redtail-cryptomining-campaign-</link>
            <guid isPermaLink="false">583baa6b-ecf9-49f9-8d5c-d05b329e5453</guid>
            <pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The RedTail cryptomining malware has been updated to exploit CVE-2024-3400, a vulnerability in PAN-OS. The attackers are using private cryptomining pools for greater control, and the malware now includes advanced antiresearch techniques. It spreads through multiple web exploit...]]></description>
            <content:encoded><![CDATA[The RedTail cryptomining malware has been updated to exploit CVE-2024-3400, a vulnerability in PAN-OS. The attackers are using private cryptomining pools for greater control, and the malware now includes advanced antiresearch techniques. It spreads through multiple web exploit...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Snowflake compromised creds abuse campaign (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/snowflake-compromised-creds-abuse-campaign</link>
            <guid isPermaLink="false">face0cc2-a9f6-43c0-879c-25014362b41c</guid>
            <pubDate>Wed, 29 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On May 30, 2024, researchers published a report concerning activity by a threat actor dubbed UNC5537, involving abuse of stolen credentials to gain illicit access to Snowflake accounts unprotected by MFA by using a toolkit known as rapeflake.On May 31, 2024, Snowflake publishe...]]></description>
            <content:encoded><![CDATA[On May 30, 2024, researchers published a report concerning activity by a threat actor dubbed UNC5537, involving abuse of stolen credentials to gain illicit access to Snowflake accounts unprotected by MFA by using a toolkit known as rapeflake.On May 31, 2024, Snowflake publishe...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Kinsing targeting cloud servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/kinsing-targeting-cloud-servers</link>
            <guid isPermaLink="false">1dc1e22e-f775-4389-aac7-15c2ad0e277d</guid>
            <pubDate>Thu, 16 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed recent activities surrounding the Kinsing malware, which primarily targets Linux-based cloud infrastructure. Kinsing exploits various vulnerabilities to gain unauthorized access and deploys backdoors and cryptominers. Recent findings show that Kinsing also...]]></description>
            <content:encoded><![CDATA[Researchers observed recent activities surrounding the Kinsing malware, which primarily targets Linux-based cloud infrastructure. Kinsing exploits various vulnerabilities to gain unauthorized access and deploys backdoors and cryptominers. Recent findings show that Kinsing also...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mirai campaign targeting Ivanti products (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mirai-campaign-targeting-ivanti-products</link>
            <guid isPermaLink="false">1b9f95be-d96d-4ce0-9c04-461cde39e4df</guid>
            <pubDate>Tue, 07 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-05-07, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN to achieve Resource hijacking. The following tools were observed: Mirai.]]></description>
            <content:encoded><![CDATA[On 2024-05-07, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN to achieve Resource hijacking. The following tools were observed: Mirai.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Atlas Lion phishing campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/atlas-lion-phishing-campaign</link>
            <guid isPermaLink="false">cd46a909-f388-4044-b09f-9f7445e4c90d</guid>
            <pubDate>Mon, 06 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft has identified a Morocco-based cybercrime group, Storm-0539, known for sophisticated phishing attacks to steal and sell gift cards. Active since 2021, the group targets large retailers by compromising gift card services and bypassing multi-factor authentication. Thei...]]></description>
            <content:encoded><![CDATA[Microsoft has identified a Morocco-based cybercrime group, Storm-0539, known for sophisticated phishing attacks to steal and sell gift cards. Active since 2021, the group targets large retailers by compromising gift card services and bypassing multi-factor authentication. Thei...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LLMjacking via Laravel exploitation (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/llmjacking-via-laravel-exploitation</link>
            <guid isPermaLink="false">5c3f50c3-67a7-4c76-84ae-5acfd3bc21f6</guid>
            <pubDate>Mon, 06 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Threat actors are attempting to monetize their illicit access to LLMs while the cloud account owner bears the costs. The attackers target a variety of LLM services across AWS, Azure, and GCP. In some instances, they employ a script to automate checking the validity of the stol...]]></description>
            <content:encoded><![CDATA[Threat actors are attempting to monetize their illicit access to LLMs while the cloud account owner bears the costs. The attackers target a variety of LLM services across AWS, Azure, and GCP. In some instances, they employ a script to automate checking the validity of the stol...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Utah “Bathroom Bill” open database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/utah-bathroom-bill-open-database</link>
            <guid isPermaLink="false">d6cabbe2-20a4-48e3-a331-6062933eb789</guid>
            <pubDate>Fri, 03 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-05-03, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Google Cloud Storage to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-05-03, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Google Cloud Storage to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TargetCompany Abusing MSSQL Servers for Ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/targetcompany-abusing-mssql-servers-for-ransomware</link>
            <guid isPermaLink="false">c876967a-dbfe-45d8-8d22-20c3e3ef1576</guid>
            <pubDate>Thu, 02 May 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers investigated a series of ransomware attacks targeting poorly managed MS-SQL servers by the TargetCompany ransomware group. This group primarily installs Mallox ransomware, with recent analysis linking these incidents to earlier attacks involving Tor2Mine CoinMiner ...]]></description>
            <content:encoded><![CDATA[Researchers investigated a series of ransomware attacks targeting poorly managed MS-SQL servers by the TargetCompany ransomware group. This group primarily installs Mallox ransomware, with recent analysis linking these incidents to earlier attacks involving Tor2Mine CoinMiner ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ArcaneDoor Campaign Targeting Cisco Adaptive Security Appliance 0day (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/arcanedoor-campaign-targeting-cisco-adaptive-security-appliance-0day</link>
            <guid isPermaLink="false">e4ef3775-4b8c-47a4-bcf6-1b8f57884316</guid>
            <pubDate>Wed, 24 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Cisco reported two zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls that have been exploited by a state-backed hacking group known as UAT4356 or STORM-1849. These vulnerabilities have been under attack since Novembe...]]></description>
            <content:encoded><![CDATA[Cisco reported two zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls that have been exploited by a state-backed hacking group known as UAT4356 or STORM-1849. These vulnerabilities have been under attack since Novembe...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[MITRE breach via Ivanti Connect Secure (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/mitre-breach-via-ivanti-connect-secure</link>
            <guid isPermaLink="false">61aef1bb-dac3-415e-942d-0dc7fec17ed3</guid>
            <pubDate>Fri, 19 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-19, an incident was reported, involving UNC5221, gaining initial access via 1-day vulnerability, while using Session hijacking, Webshell deployment, targeting Ivanti Connect Secure VPN to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-04-19, an incident was reported, involving UNC5221, gaining initial access via 1-day vulnerability, while using Session hijacking, Webshell deployment, targeting Ivanti Connect Secure VPN to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Kubernetes Clusters Targeted in OpenMetadata Exploits (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/kubernetes-clusters-targeted-in-openmetadata-exploits</link>
            <guid isPermaLink="false">b2c525b2-4911-4263-99e1-aba94ef6ec86</guid>
            <pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed attackers exploiting critical vulnerabilities in the OpenMetadata platform to infiltrate Kubernetes environments for cryptomining. OpenMetadata, an open-source platform for managing data source metadata, was found to have several vulnerabilities (CVE-2024-...]]></description>
            <content:encoded><![CDATA[Researchers observed attackers exploiting critical vulnerabilities in the OpenMetadata platform to infiltrate Kubernetes environments for cryptomining. OpenMetadata, an open-source platform for managing data source metadata, was found to have several vulnerabilities (CVE-2024-...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Delinea breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/delinea-breach</link>
            <guid isPermaLink="false">ede37996-268f-479a-8c23-2e28c01d7542</guid>
            <pubDate>Sun, 14 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-14, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, with unknown impact.]]></description>
            <content:encoded><![CDATA[On 2024-04-14, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, with unknown impact.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From password reset to data exfiltration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-password-reset-to-data-exfiltration</link>
            <guid isPermaLink="false">92629b0d-c3b7-446c-be7c-14b55dac9753</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Launch new cloud resources, Create or modify firewall or security group rules, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Launch new cloud resources, Create or modify firewall or security group rules, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Smishing into Entra onto VMWare ransomware (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/smishing-into-entra-onto-vmware-ransomware</link>
            <guid isPermaLink="false">0f02f6f9-323c-4c27-844c-970f0e14a839</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Launch new cloud resources, MFA enrollment, Credential theft, Cloud to on-prem lateral movement, Smishing (SMS phishing), EDR whitelisting, to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Launch new cloud resources, MFA enrollment, Credential theft, Cloud to on-prem lateral movement, Smishing (SMS phishing), EDR whitelisting, to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Third party to cloud compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/third-party-to-cloud-compromise</link>
            <guid isPermaLink="false">48803c11-8b3c-4d7b-8c57-1f29aa4e12e7</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Cloud key compromise, Cloud to on-prem lateral movement, to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Cloud key compromise, Cloud to on-prem lateral movement, to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Personal local drive to AWS ransomware (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/personal-local-drive-to-aws-ransomware</link>
            <guid isPermaLink="false">5b4a1e94-0445-48a3-9eac-c52e723bcc30</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, Phishing, to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, Phishing, to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Abusing management tooling for cloud access (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/abusing-management-tooling-for-cloud-access</link>
            <guid isPermaLink="false">8f72fa1b-a04b-4e99-b71f-fc31cce8c08b</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Sisense breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sisense-breach</link>
            <guid isPermaLink="false">123c8991-29d8-44c6-87d7-2a18434a6b6e</guid>
            <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[An unknown threat actor gained access to a self-hosted Gitlab instance used by Sisense, which stored credentials for an S3 bucket containing customer access tokens, passwords and SSL certificates.]]></description>
            <content:encoded><![CDATA[An unknown threat actor gained access to a self-hosted Gitlab instance used by Sisense, which stored credentials for an S3 bucket containing customer access tokens, passwords and SSL certificates.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RUBYCARP: Botnet Exploiting Vulnerabilities for Crypto (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/rubycarp-botnet-exploiting-vulnerabilities-for-crypto</link>
            <guid isPermaLink="false">be6f1244-7e18-4a03-bb55-0894fd651bd2</guid>
            <pubDate>Tue, 09 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers has uncovered a decade-long botnet operation by a Romanian group dubbed RUBYCARP. This group focuses on financial gain through cryptomining, phishing, and DDoS attacks, utilizing public exploits and brute force for deployment.Pinpointing their exact origin is chall...]]></description>
            <content:encoded><![CDATA[Researchers has uncovered a decade-long botnet operation by a Romanian group dubbed RUBYCARP. This group focuses on financial gain through cryptomining, phishing, and DDoS attacks, utilizing public exploits and brute force for deployment.Pinpointing their exact origin is chall...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Muddled Libra campaigns (2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/muddled-libra-campaigns-2024</link>
            <guid isPermaLink="false">69b8d33d-2e88-46a1-b6b1-a24612ed176f</guid>
            <pubDate>Tue, 09 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-09, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Exfiltration via AWS Transfer, Exfiltration via AWS DataSync, Cloud API e, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-04-09, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Exfiltration via AWS Transfer, Exfiltration via AWS DataSync, Cloud API e, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft exposed storage with credentials (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/microsoft-exposed-storage-with-credentials</link>
            <guid isPermaLink="false">6eda5357-683d-44f5-83aa-63121737e1cd</guid>
            <pubDate>Tue, 09 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-04-09, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Azure Storage to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-04-09, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Azure Storage to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Hugging Face cross-tenant access (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/hugging-face-cross-tenant-access</link>
            <guid isPermaLink="false">962e27f1-5699-49ae-b269-2cb1b1913c1f</guid>
            <pubDate>Thu, 04 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Wiz found two critical security risks that were present in Hugging Face’s environment:Specifically, Wiz Research showed that an attacker targeting Hugging Face could have achieved the following:Wiz Research were able to achieve remote code execution through a specially-crafted...]]></description>
            <content:encoded><![CDATA[Wiz found two critical security risks that were present in Hugging Face’s environment:Specifically, Wiz Research showed that an attacker targeting Hugging Face could have achieved the following:Wiz Research were able to achieve remote code execution through a specially-crafted...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Affirmed Networks breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/affirmed-networks-breach</link>
            <guid isPermaLink="false">771f88a8-46fa-4ae7-b350-7f7059d8566a</guid>
            <pubDate>Tue, 02 Apr 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In April 2020, Microsoft acquired Affirmed Networks. Sometime prior to that, Storm-0558 likely gained access to a device used by one of the company’s engineer, and retained that access following the acquisition, which allowed the threat actor to move laterally into Microsoft’s...]]></description>
            <content:encoded><![CDATA[In April 2020, Microsoft acquired Affirmed Networks. Sometime prior to that, Storm-0558 likely gained access to a device used by one of the company’s engineer, and retained that access following the acquisition, which allowed the threat actor to move laterally into Microsoft’s...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[XZ Utils backdoor incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/xz-utils-backdoor-incident</link>
            <guid isPermaLink="false">f3c196de-2370-4393-ba78-e214cb219a94</guid>
            <pubDate>Fri, 29 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[A backdoor has been identified in versions 5.6.0 and 5.6.1 of XZ Utils (assigned CVE-2024-3094), which under some conditions may allow SSH authentication bypass in specific versions of certain Linux distributions.According to Wiz data, while XZ Utils itself is highly prevalent...]]></description>
            <content:encoded><![CDATA[A backdoor has been identified in versions 5.6.0 and 5.6.1 of XZ Utils (assigned CVE-2024-3094), which under some conditions may allow SSH authentication bypass in specific versions of certain Linux distributions.According to Wiz data, while XZ Utils itself is highly prevalent...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Agenda Ransomware Targets ESXi and vCenter Servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/agenda-ransomware-targets-esxi-and-vcenter-servers</link>
            <guid isPermaLink="false">702d234e-48cc-4a8c-b903-044204a8858d</guid>
            <pubDate>Tue, 26 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed the Agenda Ransomware group, identified as Qilin or Water Galura, has been spreading through VMware vCenter and ESXi servers. The group has been actively evolving and targeting entities globally, particularly in the US, Argentina, Australia, and Thailand, ...]]></description>
            <content:encoded><![CDATA[Researchers observed the Agenda Ransomware group, identified as Qilin or Water Galura, has been spreading through VMware vCenter and ESXi servers. The group has been actively evolving and targeting entities globally, particularly in the US, Argentina, Australia, and Thailand, ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Compromise of Top.gg repo (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/compromise-of-topgg-repo</link>
            <guid isPermaLink="false">e766eead-5a76-46d1-b683-b8224fbc89c2</guid>
            <pubDate>Mon, 25 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-25, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2024-03-25, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC5174 ScreenConnect and F5 BIG-IP exploitation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc5174-screenconnect-and-f5-big-ip-exploitation</link>
            <guid isPermaLink="false">deefac3d-d877-4c34-af06-cdd8708bcb00</guid>
            <pubDate>Fri, 22 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-22, a campaign was reported, involving UNC5174, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ConnectWise ScreenConnect, F5 BIG IP, Confluence Server to achieve Data exfiltration. The following tools were observed: SUPERSHELL, SNOWLIGHT, GOHEAVY.]]></description>
            <content:encoded><![CDATA[On 2024-03-22, a campaign was reported, involving UNC5174, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ConnectWise ScreenConnect, F5 BIG IP, Confluence Server to achieve Data exfiltration. The following tools were observed: SUPERSHELL, SNOWLIGHT, GOHEAVY.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Fujitsu exposed bucket (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/fujitsu-exposed-bucket</link>
            <guid isPermaLink="false">772ef3b0-8b56-45e1-b401-3517c382b4a6</guid>
            <pubDate>Thu, 21 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-21, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-03-21, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[teamcity-exploitation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/teamcity-exploitation</link>
            <guid isPermaLink="false">a220af2a-da64-4a61-a774-7b86f4e651e1</guid>
            <pubDate>Tue, 19 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-19, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using LOLBin abuse, targeting TeamCity to achieve Resource hijacking, RansomOp. The following tools were observed: Jasmin, XMRig, Cobalt Strike, SparkRAT.]]></description>
            <content:encoded><![CDATA[On 2024-03-19, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using LOLBin abuse, targeting TeamCity to achieve Resource hijacking, RansomOp. The following tools were observed: Jasmin, XMRig, Cobalt Strike, SparkRAT.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[vulnerability-in-aiohttp-targeted-by-shadowsyndicate (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/vulnerability-in-aiohttp-targeted-by-shadowsyndicate</link>
            <guid isPermaLink="false">6a3eace9-f160-4427-bd84-8ab98ec8ef54</guid>
            <pubDate>Fri, 15 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Aiohttp is a widely used open-source library for handling concurrent HTTP requests in Python applications. The ransomware group ShadowSyndicate, has been scanning for servers vulnerable to CVE-2024-23334. The flaw means that improperly configuring static resource resolution in...]]></description>
            <content:encoded><![CDATA[Aiohttp is a widely used open-source library for handling concurrent HTTP requests in Python applications. The ransomware group ShadowSyndicate, has been scanning for servers vulnerable to CVE-2024-23334. The flaw means that improperly configuring static resource resolution in...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Meson Network cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/meson-network-cryptojacking-campaign</link>
            <guid isPermaLink="false">32e22070-724b-4d78-b0b2-33ec955f5dbb</guid>
            <pubDate>Mon, 11 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a malicious campaign targeting the Meson Network, a decentralized content delivery network (CDN) that leverages blockchain for bandwidth marketplace operations. This campaign aimed to exploit the crypto token unlock event around March 15th, attempting to ...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a malicious campaign targeting the Meson Network, a decentralized content delivery network (CDN) that leverages blockchain for bandwidth marketplace operations. This campaign aimed to exploit the crypto token unlock event around March 15th, attempting to ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From writable bucket to credential theft (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-writable-bucket-to-credential-theft</link>
            <guid isPermaLink="false">f23d2251-37dd-4f87-bb28-06630e2c061e</guid>
            <pubDate>Fri, 08 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-08, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-03-08, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Magnet Goblin campaign (2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/magnet-goblin-campaign-2024</link>
            <guid isPermaLink="false">13aabfa5-5311-4ebe-a7ce-b101d2992cae</guid>
            <pubDate>Fri, 08 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-08, a campaign was reported, involving Magnet Goblin, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN, Apache ActiveMQ, Magento, Qlink Sense with unknown impact. The following tools were observed: NerbianRAT, AnyDesk, WARPWIRE, MiniNerbian, ScreenConnect, Ligolo.]]></description>
            <content:encoded><![CDATA[On 2024-03-08, a campaign was reported, involving Magnet Goblin, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN, Apache ActiveMQ, Magento, Qlink Sense with unknown impact. The following tools were observed: NerbianRAT, AnyDesk, WARPWIRE, MiniNerbian, ScreenConnect, Ligolo.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[malware-campaign-targeting-misconfigured-servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/malware-campaign-targeting-misconfigured-servers</link>
            <guid isPermaLink="false">4ccd0e95-5bb0-4345-995b-c5e74e73717d</guid>
            <pubDate>Wed, 06 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed threat actors exploiting misconfiguration in servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware, which uses worm-like behavior to automate host discovery and compromise. After gaining access to misconfigured serv...]]></description>
            <content:encoded><![CDATA[Researchers observed threat actors exploiting misconfiguration in servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware, which uses worm-like behavior to automate host discovery and compromise. After gaining access to misconfigured serv...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[z0Miner targeting WebLogic servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/z0miner-targeting-weblogic-servers</link>
            <guid isPermaLink="false">b6f376d0-643c-4566-9413-58157c5604f1</guid>
            <pubDate>Wed, 06 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers observed threat actor z0Miner targeting Korean WebLogic servers as download servers for distributing malware, including miners and network tools. It is recommended to look for indicators of compromise in your environment, and if any are identified, remove the files...]]></description>
            <content:encoded><![CDATA[Researchers observed threat actor z0Miner targeting Korean WebLogic servers as download servers for distributing malware, including miners and network tools. It is recommended to look for indicators of compromise in your environment, and if any are identified, remove the files...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From social engineering to cryptocurrency theft  (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-social-engineering-to-cryptocurrency-theft</link>
            <guid isPermaLink="false">df39eb65-14e8-405c-9489-d6fa19b266d9</guid>
            <pubDate>Wed, 06 Mar 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-03-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-03-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cutout.Pro Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cutoutpro-breach</link>
            <guid isPermaLink="false">17bd8c76-b6ae-80c7-97a1-e159c6fdab96</guid>
            <pubDate>Wed, 28 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[The Singapore-based company, which provides AI-powered tools for designing image and video content, has suffered a massive data breach that compromised the personal information of nearly 20 million users.Unauthorized access to Cutout.Pro’s user data-base was disclosed on the a...]]></description>
            <content:encoded><![CDATA[The Singapore-based company, which provides AI-powered tools for designing image and video content, has suffered a massive data breach that compromised the personal information of nearly 20 million users.Unauthorized access to Cutout.Pro’s user data-base was disclosed on the a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Pure Incubation (DemandScience) Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/pure-incubation-demandscience-breach</link>
            <guid isPermaLink="false">17bd8c76-b6ae-803d-9164-e7cb5ef3a715</guid>
            <pubDate>Wed, 28 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Pure Incubation was founded in 2012, and the company later rebranded to DemandScience.Back in March 2024, an actor named KryptonZambie posted a thread on Breach Forums selling a database belonging to Pure Incubation.Furthermore, within their group of businesses, they reportedl...]]></description>
            <content:encoded><![CDATA[Pure Incubation was founded in 2012, and the company later rebranded to DemandScience.Back in March 2024, an actor named KryptonZambie posted a thread on Breach Forums selling a database belonging to Pure Incubation.Furthermore, within their group of businesses, they reportedl...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From refresh token theft to global admin (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-refresh-token-theft-to-global-admin</link>
            <guid isPermaLink="false">e74b0b42-331a-4564-8275-428ae8632bc6</guid>
            <pubDate>Fri, 23 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-23, a research was reported, involving , gaining initial access via Unknown, while using Refresh token compromise, Attach administrative role to account, Create or modify cloud key, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-23, a research was reported, involving , gaining initial access via Unknown, while using Refresh token compromise, Attach administrative role to account, Create or modify cloud key, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[lucifer-botnet-targeting-apache-hadoop (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/lucifer-botnet-targeting-apache-hadoop</link>
            <guid isPermaLink="false">22c3bd9e-97a5-48ee-b163-6c0c1841781c</guid>
            <pubDate>Thu, 22 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified a malicious campaign focusing on Apache big-data solutions, particularly Apache Hadoop and Apache Druid. This campaign leverages the Lucifer DDoS botnet, infecting Linux machines to mine the Monero cryptocurrency.The attackers target misconfigurations an...]]></description>
            <content:encoded><![CDATA[Researchers identified a malicious campaign focusing on Apache big-data solutions, particularly Apache Hadoop and Apache Druid. This campaign leverages the Lucifer DDoS botnet, infecting Linux machines to mine the Monero cryptocurrency.The attackers target misconfigurations an...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[US DOI PII exfiltration pentest (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/us-doi-pii-exfiltration-pentest</link>
            <guid isPermaLink="false">47aa9f7c-2f63-455e-a48d-b83ea277e867</guid>
            <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-21, a research was reported, involving , gaining initial access via Insider threat, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-21, a research was reported, involving , gaining initial access via Insider threat, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[S3 ransomware scam (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/s3-ransomware-scam</link>
            <guid isPermaLink="false">0bbc0e8a-e5a0-4c66-8118-2fd11fc90944</guid>
            <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, while using Data exfiltration from cloud storage, targeting S3 Bucket to achieve Data exfiltration, Data destruction.]]></description>
            <content:encoded><![CDATA[On 2024-02-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, while using Data exfiltration from cloud storage, targeting S3 Bucket to achieve Data exfiltration, Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Migo cryptominer targeting Redis (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/migo-cryptominer-targeting-redis</link>
            <guid isPermaLink="false">2b1d6299-1565-4ce1-9f6a-96eaaf70ebd5</guid>
            <pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[A new campaign named Migo targeting Redis servers running on Linux hosts to mine cryptocurrency. The campaign was identified following suspicious activities on a Redis honeypot, where a malicious node disabled several Redis configuration options to weaken security and facilita...]]></description>
            <content:encoded><![CDATA[A new campaign named Migo targeting Redis servers running on Linux hosts to mine cryptocurrency. The campaign was identified following suspicious activities on a Redis honeypot, where a malicious node disabled several Redis configuration options to weaken security and facilita...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SSH-Snake Confluence targeting campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ssh-snake-confluence-targeting-campaign</link>
            <guid isPermaLink="false">4796339d-9052-4283-87a5-0c571a81a792</guid>
            <pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-20, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using SSH propagation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: SSH-Snake.]]></description>
            <content:encoded><![CDATA[On 2024-02-20, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using SSH propagation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: SSH-Snake.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[WinStar exposed app database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/winstar-exposed-app-database</link>
            <guid isPermaLink="false">e726f246-1491-4ed8-bda0-c4e8ffd4b7cd</guid>
            <pubDate>Sun, 18 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Sliver deployment via Confluence
  vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sliver-deployment-via-confluence--vulnerability</link>
            <guid isPermaLink="false">19394c7d-9005-449e-8da3-0cbfb62d304a</guid>
            <pubDate>Thu, 15 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-15, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: XMRig, Sliver.]]></description>
            <content:encoded><![CDATA[On 2024-02-15, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: XMRig, Sliver.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BMW exposed cloud storage (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/bmw-exposed-cloud-storage</link>
            <guid isPermaLink="false">72672875-9b69-40da-9bfa-a116f6961e79</guid>
            <pubDate>Wed, 14 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-14, a research was reported, involving , gaining initial access via Cloud native misconfig, while using Cloud key compromise, targeting Azure Storage to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-14, a research was reported, involving , gaining initial access via Cloud native misconfig, while using Cloud key compromise, targeting Azure Storage to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[U.S. Internet exposed email server (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/us-internet-exposed-email-server</link>
            <guid isPermaLink="false">305a851d-7200-4a35-a2ae-69d448eccc90</guid>
            <pubDate>Wed, 14 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-14, a research was reported, involving , gaining initial access via Software misconfig, targeting Ansible, NGINX to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-14, a research was reported, involving , gaining initial access via Software misconfig, targeting Ansible, NGINX to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft Smartscreen Vulnerability Exploited by Water Hydra (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/microsoft-smartscreen-vulnerability-exploited-by-water-hydra</link>
            <guid isPermaLink="false">39b5238f-996c-463c-bbd3-07f8e74bb3bd</guid>
            <pubDate>Tue, 13 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Water Hydra group (AKA DarkCasino), whose activity was first detected in 2021, is known for their cyberattacks targeting the financial industry globally, including banks, cryptocurrency platforms, and gambling sites. Initially confused with the Evilnum APT group, Water Hydra w...]]></description>
            <content:encoded><![CDATA[Water Hydra group (AKA DarkCasino), whose activity was first detected in 2021, is known for their cyberattacks targeting the financial industry globally, including banks, cryptocurrency platforms, and gambling sites. Initially confused with the Evilnum APT group, Water Hydra w...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CGI Federal incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cgi-federal-incident</link>
            <guid isPermaLink="false">c5bd7761-6917-4d9d-8f4e-1f7c7593b95b</guid>
            <pubDate>Tue, 13 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-13, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-02-13, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Zenlayer exposed database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/zenlayer-exposed-database</link>
            <guid isPermaLink="false">bee85479-cbe5-494a-ae03-23dab998647c</guid>
            <pubDate>Tue, 13 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-13, a research was reported, involving , gaining initial access via Software misconfig, while using Cloud key compromise, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-13, a research was reported, involving , gaining initial access via Software misconfig, while using Cloud key compromise, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[wrk-exposed-database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/wrk-exposed-database</link>
            <guid isPermaLink="false">45cb4818-1017-49e3-9465-85747e570425</guid>
            <pubDate>Fri, 09 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting MongoDB to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting MongoDB to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Juniper support portal exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/juniper-support-portal-exposure</link>
            <guid isPermaLink="false">aa2bb354-57b7-449e-9187-914a9bede04c</guid>
            <pubDate>Fri, 09 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting Salesforce to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting Salesforce to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Almerys incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/almerys-incident</link>
            <guid isPermaLink="false">25762901-d54b-4d6e-99fc-529f2b4184c4</guid>
            <pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Viamedis incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/viamedis-incident</link>
            <guid isPermaLink="false">bc354c38-e496-41a3-ac55-e32c5adc9b22</guid>
            <pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[C3Pool mining via Confluence vulnerability (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/c3pool-mining-via-confluence-vulnerability</link>
            <guid isPermaLink="false">d75fb94b-eec7-4523-a4c2-613568a828f4</guid>
            <pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-08, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: C3Pool.]]></description>
            <content:encoded><![CDATA[On 2024-02-08, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: C3Pool.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cryptojacking via Azure Batch (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cryptojacking-via-azure-batch</link>
            <guid isPermaLink="false">034b9fcc-f201-426c-91fe-fe97c2c3e560</guid>
            <pubDate>Tue, 06 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Azure Batch abuse, targeting Azure Batch to achieve Resource hijacking. The following tools were observed: XMRig.]]></description>
            <content:encoded><![CDATA[On 2024-02-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Azure Batch abuse, targeting Azure Batch to achieve Resource hijacking. The following tools were observed: XMRig.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Windows SmartScreen vulnerability exploited by Mispadu trojan (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/windows-smartscreen-vulnerability-exploited-by-mispadu-trojan</link>
            <guid isPermaLink="false">a1315ad3-c45b-43cd-b7f7-df85d7e37994</guid>
            <pubDate>Fri, 02 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Mispadu Stealer, a banking Trojan first reported in November 2019, has been observed exploiting the Windows SmartScreen bypass vulnerability, CVE-2023-36025. This variant of Mispadu spreads through phishing emails and primarily affects victims in Latin America. The malware is ...]]></description>
            <content:encoded><![CDATA[Mispadu Stealer, a banking Trojan first reported in November 2019, has been observed exploiting the Windows SmartScreen bypass vulnerability, CVE-2023-36025. This variant of Mispadu spreads through phishing emails and primarily affects victims in Latin America. The malware is ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Football Australia exposed cloud key (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/football-australia-exposed-cloud-key</link>
            <guid isPermaLink="false">3c8da787-51f2-487c-b190-7df574d887e6</guid>
            <pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-02-01, a research was reported, involving , gaining initial access via Exposed secret, Cloud native misconfig, while using Cloud key compromise, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-02-01, a research was reported, involving , gaining initial access via Exposed secret, Cloud native misconfig, while using Cloud key compromise, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cloudflare incident following Okta breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cloudflare-incident-following-okta-breach</link>
            <guid isPermaLink="false">d2ec2aff-35b8-480a-8542-45efeb9101be</guid>
            <pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On November 23, 2023, Cloudflare detected activity in their network related to the Okta support system supply chain attack.]]></description>
            <content:encoded><![CDATA[On November 23, 2023, Cloudflare detected activity in their network related to the Okta support system supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Commando Cat campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/commando-cat-campaign</link>
            <guid isPermaLink="false">98f26ba8-8613-4287-8af8-138ddc4da51e</guid>
            <pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[This campaign, active since the beginning of 2024, deploys a benign container through the Commando project, escaping it to run multiple payloads on the Docker host. Docker is used as an initial access vector to deliver payloads that register persistence, create backdoors, exfi...]]></description>
            <content:encoded><![CDATA[This campaign, active since the beginning of 2024, deploys a benign container through the Commando project, escaping it to run multiple payloads on the Docker host. Docker is used as an initial access vector to deliver payloads that register persistence, create backdoors, exfi...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[New Relic incident (November 2023) (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/new-relic-incident-november-2023</link>
            <guid isPermaLink="false">46283688-c31d-4f97-92f1-4b6b684e9546</guid>
            <pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Credential stuffing, VPN anonymization, Email C2, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Credential stuffing, VPN anonymization, Email C2, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DangerDev SES abuse incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/dangerdev-ses-abuse-incident</link>
            <guid isPermaLink="false">1fa32f56-66ee-419f-9b13-f6b82d7ccfc6</guid>
            <pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, Create or modify firewall or security group rules, Launch new cloud resources, Evasive username patterns, Domain registration abuse, SES abuse for spam or phishing, Attach administrative role to account, Share compromised resources to an external account, Policy simulation, Modify existing IAM user or role, Cloud compute cryptojacking, targeting Amazon SES to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, Create or modify firewall or security group rules, Launch new cloud resources, Evasive username patterns, Domain registration abuse, SES abuse for spam or phishing, Attach administrative role to account, Share compromised resources to an external account, Policy simulation, Modify existing IAM user or role, Cloud compute cryptojacking, targeting Amazon SES to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[trigona-ransomware-infecting-misconfigured-mssql-servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/trigona-ransomware-infecting-misconfigured-mssql-servers</link>
            <guid isPermaLink="false">edb0d19b-c0fa-4692-b906-863a86aaf494</guid>
            <pubDate>Sun, 28 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Trigona ransomware has been active since at least June 2022, targeting MSSQL servers. Mimic ransomware was first identified in June 2022, with a January 2024 attack by a Turkish-speaking threat actor on poorly managed MSSQL servers. Researchers believe the same Trigona threat ...]]></description>
            <content:encoded><![CDATA[Trigona ransomware has been active since at least June 2022, targeting MSSQL servers. Mimic ransomware was first identified in June 2022, with a January 2024 attack by a Turkish-speaking threat actor on poorly managed MSSQL servers. Researchers believe the same Trigona threat ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mercedes-Benz source code exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/mercedes-benz-source-code-exposure</link>
            <guid isPermaLink="false">f181246e-7069-4989-9d32-a907bb817de2</guid>
            <pubDate>Fri, 26 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[In January 2024, researchers at RedHunt Labs discovered that Mercedes-Benz accidentally included an access token in a one of their public GitHub repositories that granted access to an internal GitHub Enterprise server. This server contained intellectual property as well as cre...]]></description>
            <content:encoded><![CDATA[In January 2024, researchers at RedHunt Labs discovered that Mercedes-Benz accidentally included an access token in a one of their public GitHub repositories that granted access to an internal GitHub Enterprise server. This server contained intellectual property as well as cre...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ECS Fargate cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ecs-fargate-cryptojacking</link>
            <guid isPermaLink="false">79fdf673-248f-4362-b2a6-0240716a6226</guid>
            <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they immediately began spinning up hundreds of ECS Fargate clusters, within which they created ECS task definitions to launch containers based...]]></description>
            <content:encoded><![CDATA[Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they immediately began spinning up hundreds of ECS Fargate clusters, within which they created ECS task definitions to launch containers based...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[S3 data exfiltration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/s3-data-exfiltration</link>
            <guid isPermaLink="false">02877f4b-4f79-4686-8ceb-8503e3a27335</guid>
            <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they checked SES quotes and enumerated cloud identities. The threat actor proceeded to create a new admin user. The above was quick and theref...]]></description>
            <content:encoded><![CDATA[Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they checked SES quotes and enumerated cloud identities. The threat actor proceeded to create a new admin user. The above was quick and theref...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft email exfiltration by Nobelium (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/microsoft-email-exfiltration-by-nobelium</link>
            <guid isPermaLink="false">26e5b7ec-ee4e-48a2-a753-57e46b149e35</guid>
            <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On January 19, 2023, Microsoft disclosed that email accounts of multiple employees had been compromised by Nobelium (which overlaps with APT29).According to Microsoft, beginning in late November 2023, Nobelium used a Password spraying attack to compromise a "legacy non-product...]]></description>
            <content:encoded><![CDATA[On January 19, 2023, Microsoft disclosed that email accounts of multiple employees had been compromised by Nobelium (which overlaps with APT29).According to Microsoft, beginning in late November 2023, Nobelium used a Password spraying attack to compromise a "legacy non-product...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From ActiveMQ to Godzilla webshell (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-activemq-to-godzilla-webshell</link>
            <guid isPermaLink="false">6f6a2218-b38b-45f2-b37e-6a5910181820</guid>
            <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Apache ActiveMQ to achieve Resource hijacking. The following tools were observed: Godzilla.]]></description>
            <content:encoded><![CDATA[On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Apache ActiveMQ to achieve Resource hijacking. The following tools were observed: Godzilla.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mimo cryptomining campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mimo-cryptomining-campaign</link>
            <guid isPermaLink="false">e6874a6a-b975-4b80-aa59-b28cca960c5c</guid>
            <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-18, a campaign was reported, involving Mimo operator, gaining initial access via 1-day vulnerability, targeting VMware Horizon, Confluence Server, WSO2, Apache ActiveMQ, PaperCut to achieve Resource hijacking, RansomOp. The following tools were observed: Mimo, NHAS reverse_ssh, XMRig, Mimus, Peer2Profit.]]></description>
            <content:encoded><![CDATA[On 2024-01-18, a campaign was reported, involving Mimo operator, gaining initial access via 1-day vulnerability, targeting VMware Horizon, Confluence Server, WSO2, Apache ActiveMQ, PaperCut to achieve Resource hijacking, RansomOp. The following tools were observed: Mimo, NHAS reverse_ssh, XMRig, Mimus, Peer2Profit.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[9hits Docker campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/9hits-docker-campaign</link>
            <guid isPermaLink="false">29a28dc5-ea2d-43b4-848c-7feda3af0710</guid>
            <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Proxyjacking, targeting Docker to achieve Resource hijacking. The following tools were observed: 9hits, XMRig.]]></description>
            <content:encoded><![CDATA[On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Proxyjacking, targeting Docker to achieve Resource hijacking. The following tools were observed: 9hits, XMRig.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AndroxGh0st usage (2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/androxgh0st-usage-2024</link>
            <guid isPermaLink="false">e9d5c8b0-9baf-482b-ac6f-fc19bae29fa4</guid>
            <pubDate>Tue, 16 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-16, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, while using Exposed environment config abuse, targeting PHP, Apache HTTP Server, Laravel to achieve Resource hijacking. The following tools were observed: AndroxGh0st.]]></description>
            <content:encoded><![CDATA[On 2024-01-16, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, while using Exposed environment config abuse, targeting PHP, Apache HTTP Server, Laravel to achieve Resource hijacking. The following tools were observed: AndroxGh0st.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TensorFlow GitHub misconfiguration (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/tensorflow-github-misconfiguration</link>
            <guid isPermaLink="false">5c0b4f2e-1cd9-4904-88b1-3cc1437409f9</guid>
            <pubDate>Mon, 15 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-15, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-01-15, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PyTorch GitHub misconfiguration (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/pytorch-github-misconfiguration</link>
            <guid isPermaLink="false">3f0d8d49-6510-4eef-8a89-3fccb25b82a7</guid>
            <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-11, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2024-01-11, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[S3 RansomOp following long-term key exposure (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/s3-ransomop-following-long-term-key-exposure</link>
            <guid isPermaLink="false">538905fd-d9ca-44e7-8779-e99d44b2634e</guid>
            <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-11, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, targeting S3 Bucket to achieve RansomOp, Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2024-01-11, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, targeting S3 Bucket to achieve RansomOp, Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Dreambus campaign (2023) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dreambus-campaign-2023</link>
            <guid isPermaLink="false">cbff15d4-605b-4a57-9e22-28045ed1f148</guid>
            <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-11, a campaign was reported, involving Dreambus operator, gaining initial access via Software misconfig, 1-day vulnerability, targeting Apache RocketMQ, Metabase to achieve Resource hijacking. The following tools were observed: XMRig.]]></description>
            <content:encoded><![CDATA[On 2024-01-11, a campaign was reported, involving Dreambus operator, gaining initial access via Software misconfig, 1-day vulnerability, targeting Apache RocketMQ, Metabase to achieve Resource hijacking. The following tools were observed: XMRig.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[FBot toolkit targets cloud environments (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/fbot-toolkit-targets-cloud-environments</link>
            <guid isPermaLink="false">9a51add8-022b-41ad-97ca-b8e1d5912149</guid>
            <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[FBot is a Python-based hacking toolkit, targeting web servers, cloud services, and SaaS platforms like AWS, Office365, PayPal, Sendgrid, and Twilio. FBot's primary purpose is to enable actors to hijack cloud, SaaS, and web services, with a secondary focus on acquiring accounts...]]></description>
            <content:encoded><![CDATA[FBot is a Python-based hacking toolkit, targeting web servers, cloud services, and SaaS platforms like AWS, Office365, PayPal, Sendgrid, and Twilio. FBot's primary purpose is to enable actors to hijack cloud, SaaS, and web services, with a secondary focus on acquiring accounts...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Ivanti Connect Secure targeting campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ivanti-connect-secure-targeting-campaign</link>
            <guid isPermaLink="false">7d536dc5-ff21-4191-8923-7ef7d22679db</guid>
            <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-10, a campaign was reported, involving UNC5221, gaining initial access via 0-day vulnerability, targeting Ivanti Connect Secure VPN with unknown impact. The following tools were observed: PySoxy, LIGHTWIRE, THINSPOOL, WARPWIRE, WIREFIRE, enum4Linux, ZIPLINE, BUSHWALK, CHAINLINE, FRAMESTING, Impacket, CrackMapExec, iodine, DSLog.]]></description>
            <content:encoded><![CDATA[On 2024-01-10, a campaign was reported, involving UNC5221, gaining initial access via 0-day vulnerability, targeting Ivanti Connect Secure VPN with unknown impact. The following tools were observed: PySoxy, LIGHTWIRE, THINSPOOL, WARPWIRE, WIREFIRE, enum4Linux, ZIPLINE, BUSHWALK, CHAINLINE, FRAMESTING, Impacket, CrackMapExec, iodine, DSLog.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[returgence-campaign-targeting-mssql-servers-with-ransomware (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/returgence-campaign-targeting-mssql-servers-with-ransomware</link>
            <guid isPermaLink="false">8ae25eb1-b693-4283-b33c-0c1ee9ce22a5</guid>
            <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers identified attacks targeting Microsoft SQL (MSSQL) servers to encrypt the victims' files with Mimic (N3ww4v3) ransomware. The attacks are tracked as RE#TURGENCE and have been observed targeting Europe, the United States, and Latin America.Threat actors targeted pub...]]></description>
            <content:encoded><![CDATA[Researchers identified attacks targeting Microsoft SQL (MSSQL) servers to encrypt the victims' files with Mimic (N3ww4v3) ransomware. The attacks are tracked as RE#TURGENCE and have been observed targeting Europe, the United States, and Latin America.Threat actors targeted pub...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Apache app cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apache-app-cryptojacking-campaign</link>
            <guid isPermaLink="false">e753d911-6271-4907-a65b-545f52fd367f</guid>
            <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2024-01-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, targeting Apache Flink, Apache Hadoop, Spring Framework, Redis to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2024-01-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, targeting Apache Flink, Apache Hadoop, Spring Framework, Redis to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cyber Toufan Linux destruction (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cyber-toufan-linux-destruction</link>
            <guid isPermaLink="false">69647bba-d876-4c40-aba3-0975c461e475</guid>
            <pubDate>Thu, 28 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-28, a campaign was reported, involving Cyber Toufan, gaining initial access via Supply chain vector, while using TOR anonymization, Email server hijacking, to achieve Data exfiltration, Data destruction.]]></description>
            <content:encoded><![CDATA[On 2023-12-28, a campaign was reported, involving Cyber Toufan, gaining initial access via Supply chain vector, while using TOR anonymization, Email server hijacking, to achieve Data exfiltration, Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cloud lateral movement via Citrix cookie (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cloud-lateral-movement-via-citrix-cookie</link>
            <guid isPermaLink="false">82db4877-af03-4838-a8c7-e651a2fb2277</guid>
            <pubDate>Fri, 15 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-15, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Erase logs, Disable logging, Reverse shell, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-12-15, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Erase logs, Disable logging, Reverse shell, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GambleForce SQL injection campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gambleforce-sql-injection-campaign</link>
            <guid isPermaLink="false">777f0eac-5d2f-4015-ad88-b66365c56cfb</guid>
            <pubDate>Thu, 14 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-14, a campaign was reported, involving GambleForce, gaining initial access via Web vulnerability, 1-day vulnerability, while using SQL injection, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-12-14, a campaign was reported, involving GambleForce, gaining initial access via Web vulnerability, 1-day vulnerability, while using SQL injection, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[APT29 TeamCity campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apt29-teamcity-campaign</link>
            <guid isPermaLink="false">8bb920d7-955b-4f0e-a41c-ac24406e4de2</guid>
            <pubDate>Wed, 13 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-13, a campaign was reported, involving APT29, gaining initial access via 1-day vulnerability, targeting TeamCity to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-12-13, a campaign was reported, involving APT29, gaining initial access via 1-day vulnerability, targeting TeamCity to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[OAuth applications to deploy VMs for cryptomining (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/oauth-applications-to-deploy-vms-for-cryptomining</link>
            <guid isPermaLink="false">f566bbe2-0e21-4fef-9647-63ac74b4513b</guid>
            <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-12, a campaign was reported, involving Storm-1283, gaining initial access via End-user compromise, while using OAuth app creation, OAuth app hijack, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2023-12-12, a campaign was reported, involving Storm-1283, gaining initial access via End-user compromise, while using OAuth app creation, OAuth app hijack, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[First Republic Bank incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/first-republic-bank-incident</link>
            <guid isPermaLink="false">ea259958-5789-45c9-9439-46f08d4d6b2c</guid>
            <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-12, an incident was reported, involving an unknown actor, gaining initial access via Insider threat, to achieve Data destruction.]]></description>
            <content:encoded><![CDATA[On 2023-12-12, an incident was reported, involving an unknown actor, gaining initial access via Insider threat, to achieve Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Krasue Thailand campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/krasue-thailand-campaign</link>
            <guid isPermaLink="false">25265c3e-074f-4343-994e-c8d490247ed0</guid>
            <pubDate>Thu, 07 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-07, a campaign was reported, involving Krasue operator, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: Krasue.]]></description>
            <content:encoded><![CDATA[On 2023-12-07, a campaign was reported, involving Krasue operator, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: Krasue.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Package hijacking redteam op (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/package-hijacking-redteam-op</link>
            <guid isPermaLink="false">82d8c1e9-4236-41ad-bc54-c9c7bf96956a</guid>
            <pubDate>Wed, 06 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-12-06, a research was reported, involving , gaining initial access via End-user compromise, while using Package hijacking, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2023-12-06, a research was reported, involving , gaining initial access via End-user compromise, while using Package hijacking, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GoTitan ActiveMQ campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gotitan-activemq-campaign</link>
            <guid isPermaLink="false">0dabf01e-1004-42f8-a753-58d6071535e8</guid>
            <pubDate>Tue, 28 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Fortiguard Labs detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware. Their analysis unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote contr...]]></description>
            <content:encoded><![CDATA[Fortiguard Labs detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware. Their analysis unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote contr...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LINE and NAVER Cloud incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/line-and-naver-cloud-incident</link>
            <guid isPermaLink="false">f892fc96-ccd8-49c4-b09d-a7d10f504d84</guid>
            <pubDate>Mon, 27 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-11-27, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-11-27, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Andariel exploiting Apache ActiveMQ (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/andariel-exploiting-apache-activemq</link>
            <guid isPermaLink="false">80020b0e-3699-4e75-8cc9-d9ebae59210f</guid>
            <pubDate>Mon, 27 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-11-27, a campaign was reported, involving Andariel, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Apache ActiveMQ with unknown impact. The following tools were observed: NukeSped, Metasploit.]]></description>
            <content:encoded><![CDATA[On 2023-11-27, a campaign was reported, involving Andariel, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Apache ActiveMQ with unknown impact. The following tools were observed: NukeSped, Metasploit.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[cryptojacking-against-apache-servers-with-cobalt-strike (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cryptojacking-against-apache-servers-with-cobalt-strike</link>
            <guid isPermaLink="false">a242c389-20f1-4a16-bf16-01a9b0c686cd</guid>
            <pubDate>Mon, 20 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers detected a cyber attack campaign that installs the XMRig CoinMiner on Windows web servers operating Apache. The threat actor employed Cobalt Strike to manage the compromised system. Cobalt Strike, a commercial penetration testing tool, has recently become a common ...]]></description>
            <content:encoded><![CDATA[Researchers detected a cyber attack campaign that installs the XMRig CoinMiner on Windows web servers operating Apache. The threat actor employed Cobalt Strike to manage the compromised system. Cobalt Strike, a commercial penetration testing tool, has recently become a common ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Confluence targeting by C3RB3R (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/confluence-targeting-by-c3rb3r</link>
            <guid isPermaLink="false">b08652e8-b353-49d4-9130-a8a506adfdb6</guid>
            <pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-11-14, a campaign was reported, involving C3RB3R operator, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve RansomOp. The following tools were observed: C3RB3R Ransomware.]]></description>
            <content:encoded><![CDATA[On 2023-11-14, a campaign was reported, involving C3RB3R operator, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve RansomOp. The following tools were observed: C3RB3R Ransomware.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[OracleIV campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/oracleiv-campaign</link>
            <guid isPermaLink="false">c1c018ec-a406-421b-a36e-7bdea5dd79b0</guid>
            <pubDate>Mon, 13 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-11-13, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Abusing exposed Docker socket, targeting Docker to achieve Resource hijacking. The following tools were observed: OracleIV.]]></description>
            <content:encoded><![CDATA[On 2023-11-13, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Abusing exposed Docker socket, targeting Docker to achieve Resource hijacking. The following tools were observed: OracleIV.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[sumologic-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sumologic-breach</link>
            <guid isPermaLink="false">5fc2e76f-ed39-4400-9865-b2fc1ed919cc</guid>
            <pubDate>Tue, 07 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-11-07, an incident was reported, involving an unknown actor, gaining initial access via Unknown, with unknown impact.]]></description>
            <content:encoded><![CDATA[On 2023-11-07, an incident was reported, involving an unknown actor, gaining initial access via Unknown, with unknown impact.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[EleKtra-Leak (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/elektra-leak</link>
            <guid isPermaLink="false">691be387-45e1-476c-988f-b245b1548cc6</guid>
            <pubDate>Mon, 30 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Unit 42 researchers identified a campaign dubbed EleKtra-Leak, which performs automated targeting of exposed identity and access management (IAM) credentials within public GitHub repositories.]]></description>
            <content:encoded><![CDATA[Unit 42 researchers identified a campaign dubbed EleKtra-Leak, which performs automated targeting of exposed identity and access management (IAM) credentials within public GitHub repositories.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Okta support system supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/okta-support-system-supply-chain-attack</link>
            <guid isPermaLink="false">0c763dc4-08fd-4dd5-abde-eabff6215358</guid>
            <pubDate>Fri, 20 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat actor gained access to Okta’s environment, and figured out that Okta was storing unsanitized HAR files (recordings of browser activity) that customers were sharing with the Okta support team to help with troubleshooting. These HAR files sometimes contained customer ...]]></description>
            <content:encoded><![CDATA[The threat actor gained access to Okta’s environment, and figured out that Okta was storing unsanitized HAR files (recordings of browser activity) that customers were sharing with the Okta support team to help with troubleshooting. These HAR files sometimes contained customer ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Qubitstrike Crypto Mining and Rootkit Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/qubitstrike-crypto-mining-and-rootkit-campaign</link>
            <guid isPermaLink="false">964d5e08-1734-44d1-8ad7-f18eef167135</guid>
            <pubDate>Wed, 18 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Qubitstrike is a cryptojacking campaing targeting exposed Jupyter Notebooks, as they may allow to execute commands remotely. After obtaining a shell on the remote host, the shell script executes a cryptocurrency miner and establishes persistence using a cron job that inserts a...]]></description>
            <content:encoded><![CDATA[Qubitstrike is a cryptojacking campaing targeting exposed Jupyter Notebooks, as they may allow to execute commands remotely. After obtaining a shell on the remote host, the shell script executes a cryptocurrency miner and establishes persistence using a cron job that inserts a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cloud tools imitation campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cloud-tools-imitation-campaign</link>
            <guid isPermaLink="false">d1c48aa9-d6ff-40b6-965b-d7449c1c1535</guid>
            <pubDate>Tue, 10 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-10-10, a campaign was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package typosquatting, Package Starjacking, with unknown impact.]]></description>
            <content:encoded><![CDATA[On 2023-10-10, a campaign was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package typosquatting, Package Starjacking, with unknown impact.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SQL Server to cloud lateral movement (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sql-server-to-cloud-lateral-movement</link>
            <guid isPermaLink="false">26f0e873-161a-4cbc-8490-1876bd4c139b</guid>
            <pubDate>Tue, 03 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-10-03, a campaign was reported, involving an unknown actor, gaining initial access via Web vulnerability, while using SQL injection, Use DNS for exfiltration, IMDS abuse, SQL commands, targeting Microsoft SQL Server to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-10-03, a campaign was reported, involving an unknown actor, gaining initial access via Web vulnerability, while using SQL injection, Use DNS for exfiltration, IMDS abuse, SQL commands, targeting Microsoft SQL Server to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Darkbeam data exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/darkbeam-data-exposure</link>
            <guid isPermaLink="false">94514084-df16-4c0e-96d5-fc9c138ae774</guid>
            <pubDate>Mon, 02 Oct 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Cyber risk management company DarkBeam has leaked more than 3.8 billion records after it left an Elasticsearch server unprotected on the internet. The database contained information from older breaches that DarkBeam was using to send alerts to customers. While the leaked data ...]]></description>
            <content:encoded><![CDATA[Cyber risk management company DarkBeam has leaked more than 3.8 billion records after it left an Elasticsearch server unprotected on the internet. The database contained information from older breaches that DarkBeam was using to send alerts to customers. While the leaked data ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Scattered Spider SaaS targeting (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scattered-spider-saas-targeting</link>
            <guid isPermaLink="false">022c69d9-9c76-4cab-aa61-9cc9aefab5e1</guid>
            <pubDate>Wed, 20 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-09-20, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Smishing (SMS phishing), Serial port abuse, MFA enrollment, Create new cloud user, SIM swap scam, Phishing, to achieve Data exfiltration, RansomOp.]]></description>
            <content:encoded><![CDATA[On 2023-09-20, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Smishing (SMS phishing), Serial port abuse, MFA enrollment, Create new cloud user, SIM swap scam, Phishing, to achieve Data exfiltration, RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Prophet Spider campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/prophet-spider-campaign</link>
            <guid isPermaLink="false">0df3f852-a340-4bcd-9d1e-8c1218a7943d</guid>
            <pubDate>Wed, 20 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-09-20, a campaign was reported, involving Prophet Spider, gaining initial access via , while using Vulnerability exploitation,.]]></description>
            <content:encoded><![CDATA[On 2023-09-20, a campaign was reported, involving Prophet Spider, gaining initial access via , while using Vulnerability exploitation,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft AI data exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/microsoft-ai-data-exposure</link>
            <guid isPermaLink="false">f73d3d0c-b794-4556-bb37-3437fe970839</guid>
            <pubDate>Mon, 18 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-09-18, a research was reported, involving , gaining initial access via Software misconfig, targeting Azure Storage to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2023-09-18, a research was reported, involving , gaining initial access via Software misconfig, targeting Azure Storage to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AmberSquid campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ambersquid-campaign</link>
            <guid isPermaLink="false">2bcc7a35-203d-45eb-99ea-5fcda157d080</guid>
            <pubDate>Mon, 18 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Researchers uncovered a cryptojacking operation targeting AWS services such as AWS Amplify, AWS Fargate, and Amazon SageMaker to mine cryptocurrency. The timeline of this operation spans from May 2022 to March 2023. Initially, the attackers used Docker Hub accounts to distribu...]]></description>
            <content:encoded><![CDATA[Researchers uncovered a cryptojacking operation targeting AWS services such as AWS Amplify, AWS Fargate, and Amazon SageMaker to mine cryptocurrency. The timeline of this operation spans from May 2022 to March 2023. Initially, the attackers used Docker Hub accounts to distribu...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[peach-sandstorm-cloud-activity (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/peach-sandstorm-cloud-activity</link>
            <guid isPermaLink="false">da67563c-ddf3-447f-bf04-c1f83217b4b5</guid>
            <pubDate>Thu, 14 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to Microsoft Threat Research, during a campaign by Iranian state-sponsored actor Peach Sandstorm, they were observed utilizing password spray attacks to gain unauthorized access to target environments. Active since February 2023, the campaign successfully targeted sa...]]></description>
            <content:encoded><![CDATA[According to Microsoft Threat Research, during a campaign by Iranian state-sponsored actor Peach Sandstorm, they were observed utilizing password spray attacks to gain unauthorized access to target environments. Active since February 2023, the campaign successfully targeted sa...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Rollbar hack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/rollbar-hack</link>
            <guid isPermaLink="false">d032ce8a-7bce-40b9-a58a-f3963517636b</guid>
            <pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.Once inside Rollbar's systems, the threat actors searched the company's data for cloud cr...]]></description>
            <content:encoded><![CDATA[The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.Once inside Rollbar's systems, the threat actors searched the company's data for cloud cr...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BlackCat Azure Storage Account RansomOp (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/blackcat-azure-storage-account-ransomop</link>
            <guid isPermaLink="false">c9250dfb-4335-4e49-937e-e83e583b1258</guid>
            <pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The threat actors gained access to the customer's Azure portal, where they obtained the Azure key required to access the storage account programmatically. The adversary encoded the keys using base-64 and inserted them into the ransomware binary with execution command lines bel...]]></description>
            <content:encoded><![CDATA[The threat actors gained access to the customer's Azure portal, where they obtained the Azure key required to access the storage account programmatically. The adversary encoded the keys using base-64 and inserted them into the ransomware binary with execution command lines bel...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From SSH bruteforce to cryptojacking (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-ssh-bruteforce-to-cryptojacking</link>
            <guid isPermaLink="false">dbb0be2e-dad2-4df7-a65a-564d56f2826e</guid>
            <pubDate>Fri, 08 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The researchers observed a malicious IP address, previously flagged for conducting SSH brute force attempts, communicating with a malicious shell script named hoze. This script downloads xrx.tar, an archive that contains more scripts that uninstall security software and enable...]]></description>
            <content:encoded><![CDATA[The researchers observed a malicious IP address, previously flagged for conducting SSH brute force attempts, communicating with a malicious shell script named hoze. This script downloads xrx.tar, an archive that contains more scripts that uninstall security software and enable...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Evil_MinIO campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/evilminio-campaign</link>
            <guid isPermaLink="false">0133e9dd-88fd-4c3e-8405-57d048c20416</guid>
            <pubDate>Mon, 04 Sep 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-09-04, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting MinIO with unknown impact.]]></description>
            <content:encoded><![CDATA[On 2023-09-04, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting MinIO with unknown impact.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Kinsing campaigns (2023-2024) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/kinsing-campaigns-2023-2024</link>
            <guid isPermaLink="false">01a629a6-3332-4aba-90e0-04a1eac70dbb</guid>
            <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-29, a campaign was reported, involving Kinsing operator, gaining initial access via 1-day vulnerability, Software misconfig, while using Misconfigured PostgreSQL abuse, targeting Openfire, PostgreSQL, WebLogic, WordPress, Liferay, PHPUnit, Apache RocketMQ to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2023-08-29, a campaign was reported, involving Kinsing operator, gaining initial access via 1-day vulnerability, Software misconfig, while using Misconfigured PostgreSQL abuse, targeting Openfire, PostgreSQL, WebLogic, WordPress, Liferay, PHPUnit, Apache RocketMQ to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC4841 Barracuda ESG Campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc4841-barracuda-esg-campaign</link>
            <guid isPermaLink="false">ae6fc098-a0f4-4eb6-877a-db497aef16f7</guid>
            <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-29, a campaign was reported, involving UNC4841, gaining initial access via 0-day vulnerability, targeting Barracuda ESG to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-08-29, a campaign was reported, involving UNC4841, gaining initial access via 0-day vulnerability, targeting Barracuda ESG to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Retool hack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/retool-hack</link>
            <guid isPermaLink="false">ac0aa38a-9d2d-441f-96af-688d5a09b675</guid>
            <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-29, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Spearphishing, to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2023-08-29, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Spearphishing, to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Fatal Model exposed database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/fatal-model-exposed-database</link>
            <guid isPermaLink="false">99a78b63-3dda-4ec1-8bd5-370a062eab94</guid>
            <pubDate>Fri, 25 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[A security researcher discovered an exposed cloud database that contained sensitive log records with references to Fatal Model, an escort service in Brazil. Additionally, the database contained access keys for an AWS storage account associated with Fatal Model, which wasn't pa...]]></description>
            <content:encoded><![CDATA[A security researcher discovered an exposed cloud database that contained sensitive log records with references to Fatal Model, an escort service in Brazil. Additionally, the database contained access keys for an AWS storage account associated with Fatal Model, which wasn't pa...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Labrat GitLab campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/labrat-gitlab-campaign</link>
            <guid isPermaLink="false">8b8ec207-56fd-4be1-85dd-de709351071b</guid>
            <pubDate>Thu, 17 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-17, a campaign was reported, involving Labrat operator, gaining initial access via 1-day vulnerability, while using Proxyjacking, Cloud compute cryptojacking, targeting GitLab to achieve Resource hijacking. The following tools were observed: Gsocket, ProxyLite, IPRoyal.]]></description>
            <content:encoded><![CDATA[On 2023-08-17, a campaign was reported, involving Labrat operator, gaining initial access via 1-day vulnerability, while using Proxyjacking, Cloud compute cryptojacking, targeting GitLab to achieve Resource hijacking. The following tools were observed: Gsocket, ProxyLite, IPRoyal.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From PHP exploitation to AWS lateral movement (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-php-exploitation-to-aws-lateral-movement</link>
            <guid isPermaLink="false">760db61a-6dc7-4bdd-891e-991029c74d84</guid>
            <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, while using SSM orchestration abuse, Cron persistence, IMDS abuse, targeting PHP with unknown impact. The following tools were observed: Sliver.]]></description>
            <content:encoded><![CDATA[On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, while using SSM orchestration abuse, Cron persistence, IMDS abuse, targeting PHP with unknown impact. The following tools were observed: Sliver.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[use-of-azure-run-commands (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/use-of-azure-run-commands</link>
            <guid isPermaLink="false">4f74ccfb-99bd-4a2c-ba65-c05916650d9c</guid>
            <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-15, a campaign was reported, involving 0ktapus, gaining initial access via Unknown, while using Azure Run Commands abuse, with unknown impact.]]></description>
            <content:encoded><![CDATA[On 2023-08-15, a campaign was reported, involving 0ktapus, gaining initial access via Unknown, while using Azure Run Commands abuse, with unknown impact.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Use of linPEAS for cloud enumeration (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/use-of-linpeas-for-cloud-enumeration</link>
            <guid isPermaLink="false">4d3f9509-16ee-4ab3-bde8-9fe6324740d3</guid>
            <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via ,. The following tools were observed: linPEAS.]]></description>
            <content:encoded><![CDATA[On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via ,. The following tools were observed: linPEAS.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SugarCRM as initial access to AWS envs (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/sugarcrm-as-initial-access-to-aws-envs</link>
            <guid isPermaLink="false">c7f3434f-ea3f-4ea3-a98d-426d627b4b58</guid>
            <pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-08-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting SugarCRM. The following tools were observed: Pacu, ScoutSuite.]]></description>
            <content:encoded><![CDATA[On 2023-08-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting SugarCRM. The following tools were observed: Pacu, ScoutSuite.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[P2PInfect campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/p2pinfect-campaign</link>
            <guid isPermaLink="false">99ed8960-c9dc-4c7e-902e-ffabd15f5303</guid>
            <pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[A campaign targeting misconfigured Redis servers with a peer-to-peer self-replicating worm named P2Pinfect. The campaign exploits a critical vulnerability and makes use of the SLAVEOF feature to install malware that acts as a botnet agent. P2Pinfect is written in Rust and empl...]]></description>
            <content:encoded><![CDATA[A campaign targeting misconfigured Redis servers with a peer-to-peer self-replicating worm named P2Pinfect. The campaign exploits a critical vulnerability and makes use of the SLAVEOF feature to install malware that acts as a botnet agent. P2Pinfect is written in Rust and empl...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Meow Jupyter Notebook campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/meow-jupyter-notebook-campaign</link>
            <guid isPermaLink="false">e28aa01d-2c49-4265-a511-858eb395efcc</guid>
            <pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-07-31, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Data destruction.]]></description>
            <content:encoded><![CDATA[On 2023-07-31, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SkidMap targeting Redis (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/skidmap-targeting-redis</link>
            <guid isPermaLink="false">2e626b1b-a325-4b41-bf85-5ab85e3697f3</guid>
            <pubDate>Sun, 30 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-07-30, a campaign was reported, involving SkidMap operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis with unknown impact. The following tools were observed: SkidMap.]]></description>
            <content:encoded><![CDATA[On 2023-07-30, a campaign was reported, involving SkidMap operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis with unknown impact. The following tools were observed: SkidMap.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[DepositFiles exposed config file (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/depositfiles-exposed-config-file</link>
            <guid isPermaLink="false">9fd0e4e0-ebb1-4b2b-90fd-ebc7b3773585</guid>
            <pubDate>Thu, 27 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The Cybernews research team discovered DepositFiles’ publicly hosted environment configuration (config) file, which exposed:]]></description>
            <content:encoded><![CDATA[The Cybernews research team discovered DepositFiles’ publicly hosted environment configuration (config) file, which exposed:]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[JumpCloud supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/jumpcloud-supply-chain-attack</link>
            <guid isPermaLink="false">c1bf8ade-ad9a-4731-86e5-1f941edf48a9</guid>
            <pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-07-14, an incident was reported, involving TraderTraitor, gaining initial access via End-user compromise, to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2023-07-14, an incident was reported, involving TraderTraitor, gaining initial access via End-user compromise, to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SilentBob cryptomining campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/silentbob-cryptomining-campaign</link>
            <guid isPermaLink="false">90b13112-893d-4a6d-9565-cf39fa0d46c9</guid>
            <pubDate>Thu, 13 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[A cloud attack campaign possibly orchestrated by the threat actor known as TeamTNT. The campaign primarily involves an aggressive cloud worm that targets JupyterLab and Docker APIs to deploy Tsunami malware, hijack cloud credentials, and execute resource hijacking.On July 13, ...]]></description>
            <content:encoded><![CDATA[A cloud attack campaign possibly orchestrated by the threat actor known as TeamTNT. The campaign primarily involves an aggressive cloud worm that targets JupyterLab and Docker APIs to deploy Tsunami malware, hijack cloud credentials, and execute resource hijacking.On July 13, ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Storm-0558 phishing campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/storm-0558-phishing-campaigns</link>
            <guid isPermaLink="false">ae182054-5d75-4ec0-a238-5d5628f9c78e</guid>
            <pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-07-11, a campaign was reported, involving Storm-0558, gaining initial access via End-user compromise, while using Phishing, LSASS dumping, with unknown impact. The following tools were observed: Cigril, China Chopper.]]></description>
            <content:encoded><![CDATA[On 2023-07-11, a campaign was reported, involving Storm-0558, gaining initial access via End-user compromise, while using Phishing, LSASS dumping, with unknown impact. The following tools were observed: Cigril, China Chopper.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PyLoose campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/pyloose-campaign</link>
            <guid isPermaLink="false">63b82525-85a0-4eb6-bb1c-ffdd3c750c79</guid>
            <pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In mid-2023, an unknown financially-motivated threat actor began targeting publicly exposed Jupyter Notebook instances to hijack them for running cryptomining operations. The threat actor deployed a fileless Python tool (dubbed “PyLoose”) that loaded an XMRig miner directly in...]]></description>
            <content:encoded><![CDATA[In mid-2023, an unknown financially-motivated threat actor began targeting publicly exposed Jupyter Notebook instances to hijack them for running cryptomining operations. The threat actor deployed a fileless Python tool (dubbed “PyLoose”) that loaded an XMRig miner directly in...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[APT31 Rekoobe campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apt31-rekoobe-campaign</link>
            <guid isPermaLink="false">fdc520cb-1d52-471f-b4ba-fae5038f2c6e</guid>
            <pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-07-11, a campaign was reported, involving APT31, gaining initial access via ,. The following tools were observed: Rekoobe.]]></description>
            <content:encoded><![CDATA[On 2023-07-11, a campaign was reported, involving APT31, gaining initial access via ,. The following tools were observed: Rekoobe.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[storm-0558-signing-key-compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/storm-0558-signing-key-compromise</link>
            <guid isPermaLink="false">56504ef8-bddd-4cbc-b20f-87e0e43208dd</guid>
            <pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In July 2023, Microsoft disclosed that Storm-0558, a threat actor attributed to China, managed to acquire a signing key that allowed them to gain illicit access to Exchange and Outlook accounts. The threat actor utilized this key in order to exfiltrate emails from multiple org...]]></description>
            <content:encoded><![CDATA[In July 2023, Microsoft disclosed that Storm-0558, a threat actor attributed to China, managed to acquire a signing key that allowed them to gain illicit access to Exchange and Outlook accounts. The threat actor utilized this key in order to exfiltrate emails from multiple org...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[scarleteel20 (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scarleteel20</link>
            <guid isPermaLink="false">b57241c4-81b8-431a-8236-6351bd16c775</guid>
            <pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In July 2023, details of recent activities related to ScarletEel were published, showing the advancement of the attacker over time. The threat actors expanded their arsenal to include new tools and a C2 infrastructure, making it more difficult to detect their activity. They ty...]]></description>
            <content:encoded><![CDATA[In July 2023, details of recent activities related to ScarletEel were published, showing the advancement of the attacker over time. The threat actors expanded their arsenal to include new tools and a C2 infrastructure, making it more difficult to detect their activity. They ty...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[RomCom exploiting Word vulnerability in campaign targeting government entities (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/romcom-exploiting-word-vulnerability-in-campaign-targeting-government-entities</link>
            <guid isPermaLink="false">9fe17fbc-62cb-4029-a51c-f794b602d1e2</guid>
            <pubDate>Mon, 03 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In June 2023, Storm-0978 launched a campaign exploiting the CVE-2023-36884 vulnerability, a remote code execution flaw in Microsoft Word documents. This campaign targeted defense and government entities in Europe and North America, using phishing emails with lures related to t...]]></description>
            <content:encoded><![CDATA[In June 2023, Storm-0978 launched a campaign exploiting the CVE-2023-36884 vulnerability, a remote code execution flaw in Microsoft Word documents. This campaign targeted defense and government entities in Europe and North America, using phishing emails with lures related to t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Diicot Campaign Targeting Exposed SSH (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/diicot-campaign-targeting-exposed-ssh</link>
            <guid isPermaLink="false">15fd8c76-b6ae-8026-b4b0-f3d161048d74</guid>
            <pubDate>Thu, 15 Jun 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-06-15, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, UPX packing, Cron persistence, to achieve Resource hijacking. The following tools were observed: XMRig, zmap.]]></description>
            <content:encoded><![CDATA[On 2023-06-15, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, UPX packing, Cron persistence, to achieve Resource hijacking. The following tools were observed: XMRig, zmap.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From WSO2 RCE to SSH lateral movement (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-wso2-rce-to-ssh-lateral-movement</link>
            <guid isPermaLink="false">c8f5fe4e-8778-42cc-8699-658d635d392f</guid>
            <pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a WSO2 RCE vulnerability (CVE-2022-29464) affecting Linux machines. The actor downloaded several tools including cryptominers and websh...]]></description>
            <content:encoded><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a WSO2 RCE vulnerability (CVE-2022-29464) affecting Linux machines. The actor downloaded several tools including cryptominers and websh...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[from-wso2-rce-to-ssh-lateral-movement (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-wso2-rce-to-ssh-lateral-movement</link>
            <guid isPermaLink="false">05424201-a794-4663-ba2f-032facfdec44</guid>
            <pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a vulnerability affecting an Internet-facing web app and gaining command shell access. The actor used Chisel for C2 purposes (specifica...]]></description>
            <content:encoded><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a vulnerability affecting an Internet-facing web app and gaining command shell access. The actor used Chisel for C2 purposes (specifica...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[from-php-vuln-to-silver-execution-via-cron (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-php-vuln-to-silver-execution-via-cron</link>
            <guid isPermaLink="false">571554f9-ec63-49e9-b87d-67864da7664a</guid>
            <pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment using an RCE vulnerability affecting PHP applications on multiple Linux machines. The actor enumerated the environment and attempted to query the IMD...]]></description>
            <content:encoded><![CDATA[According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment using an RCE vulnerability affecting PHP applications on multiple Linux machines. The actor enumerated the environment and attempted to query the IMD...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cosmic Wolf cloud activity (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/cosmic-wolf-cloud-activity</link>
            <guid isPermaLink="false">2d49fc7d-9d9a-451d-9a5e-128b0a47a737</guid>
            <pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to CrowdStrike research, in a certain incident Cosmic Wolf compromised a target organization’s cloud environment using a stolen credential. They used this to authenticate using a CLI and modified security group settings to allow shell access to machines in the enviro...]]></description>
            <content:encoded><![CDATA[According to CrowdStrike research, in a certain incident Cosmic Wolf compromised a target organization’s cloud environment using a stolen credential. They used this to authenticate using a CLI and modified security group settings to allow shell access to machines in the enviro...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Poisoned image to K8s to cloud (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/poisoned-image-to-k8s-to-cloud</link>
            <guid isPermaLink="false">edcb9f61-2b69-44cd-8b45-cd92c2dd235a</guid>
            <pubDate>Thu, 25 May 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[[…] a real example of an AWS Kubernetes cluster infection through a software development supply chain compromise. The attackers were able to get AWS credentials from a DevOps workstation and use them to introduce a poisoned docker image into a Kubernetes cluster. It allowed th...]]></description>
            <content:encoded><![CDATA[[…] a real example of an AWS Kubernetes cluster infection through a software development supply chain compromise. The attackers were able to get AWS credentials from a DevOps workstation and use them to introduce a poisoned docker image into a Kubernetes cluster. It allowed th...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[8820-gang-targeting-oracle-weblogic (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/8820-gang-targeting-oracle-weblogic</link>
            <guid isPermaLink="false">9c07a8fc-4826-47ec-ad8b-4e8def41cb2b</guid>
            <pubDate>Tue, 16 May 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[8220 Gang, a financially-motivated Chinese threat actor known for their cryptojacking activity, has been observed by researchers to be exploiting CVE-2020-14883, a remote code execution (RCE) vulnerability in Oracle WebLogic Server. The attackers seem to be exploiting the vuln...]]></description>
            <content:encoded><![CDATA[8220 Gang, a financially-motivated Chinese threat actor known for their cryptojacking activity, has been observed by researchers to be exploiting CVE-2020-14883, a remote code execution (RCE) vulnerability in Oracle WebLogic Server. The attackers seem to be exploiting the vuln...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SIM swapping to serial port abuse (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sim-swapping-to-serial-port-abuse</link>
            <guid isPermaLink="false">243c0f34-21ed-4bcb-bb59-89411206706a</guid>
            <pubDate>Tue, 16 May 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In 2022, Mandiant identified attacker activity centered in Microsoft Azure that Mandiant attributed to UNC3944. Mandiant’s investigation revealed that the attacker employed malicious use of the Serial Console on Azure Virtual Machines (VM) to install third-party remote managem...]]></description>
            <content:encoded><![CDATA[In 2022, Mandiant identified attacker activity centered in Microsoft Azure that Mandiant attributed to UNC3944. Mandiant’s investigation revealed that the attacker employed malicious use of the Serial Console on Azure Virtual Machines (VM) to install third-party remote managem...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Optimeyes data leak (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/optimeyes-data-leak</link>
            <guid isPermaLink="false">58ead380-eb8e-4650-9c9e-6b27b028dd06</guid>
            <pubDate>Tue, 09 May 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Optimeyes's Jenkins instance was publicly exposed, albeit with few viewable workspaces and locked down admin permissions. However, the build information for each past build contained a link to the corrosponding git repository, including the bitbucket credentials in the url. Th...]]></description>
            <content:encoded><![CDATA[Optimeyes's Jenkins instance was publicly exposed, albeit with few viewable workspaces and locked down admin permissions. However, the build information for each past build contained a link to the corrosponding git repository, including the bitbucket credentials in the url. Th...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Capita data leak (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/capita-data-leak</link>
            <guid isPermaLink="false">03f86e96-2200-432d-ae6c-25131978d2b4</guid>
            <pubDate>Fri, 05 May 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[UK outsourcing company Capita exposed sensitive data in a public S3 bucket with no password protection for seven years (since 2016). The bucket contained approximately 3,000 files totaling 655GB - including documents, software, cleartext secrets, server images and more - and w...]]></description>
            <content:encoded><![CDATA[UK outsourcing company Capita exposed sensitive data in a public S3 bucket with no password protection for seven years (since 2016). The bucket contained approximately 3,000 files totaling 655GB - including documents, software, cleartext secrets, server images and more - and w...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[fsevents supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/fsevents-supply-chain-attack</link>
            <guid isPermaLink="false">91caaa46-4019-488a-9337-68cf28107134</guid>
            <pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[The fsevents npm package previously pulled certain remote binaries from a public S3 bucket (fsevents-binaries.s3-us-west-2.amazonaws.com). At some point the bucket expired and the domain became dangling, and in April 2023 it was hijacked by an unknown actor (reportedly a secur...]]></description>
            <content:encoded><![CDATA[The fsevents npm package previously pulled certain remote binaries from a public S3 bucket (fsevents-binaries.s3-us-west-2.amazonaws.com). At some point the bucket expired and the domain became dangling, and in April 2023 it was hijacked by an unknown actor (reportedly a secur...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[8220 Gang exploiting Log4Shell8220 Gang targeting Confluence (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/8220-gang-exploiting-log4shell8220-gang-targeting-confluence</link>
            <guid isPermaLink="false">0d8ef5a7-c12e-42df-b601-07b00a112cbb</guid>
            <pubDate>Fri, 21 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-04-21, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2023-04-21, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[misconfigured-fw-to-cryptojacking-botnet (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/misconfigured-fw-to-cryptojacking-botnet</link>
            <guid isPermaLink="false">d95337c3-f830-4ca6-a4ed-efc64406873b</guid>
            <pubDate>Tue, 18 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to Unit42, a medium-sized e-commerce company was attacked by a threat actor with cryptojacking attack which performed large-scale crypto-mining and botnet operations in the company’s cloud environment. The attacked discovered by the cloud provider which alerted the c...]]></description>
            <content:encoded><![CDATA[According to Unit42, a medium-sized e-commerce company was attacked by a threat actor with cryptojacking attack which performed large-scale crypto-mining and botnet operations in the company’s cloud environment. The attacked discovered by the cloud provider which alerted the c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[SIM-Swap to Data Leak on Dark Web (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/sim-swap-to-data-leak-on-dark-web</link>
            <guid isPermaLink="false">4e96654c-86c7-4fed-be55-a0e18f802aa4</guid>
            <pubDate>Tue, 18 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[According to Unit42, a financial firm was attacked by an adversary that manipulated, and compromised it’s cloud workloads. The threat actor was able to drop storage components such as buckets and tables, threatened the firm to leak data if ransom will not paid and eventually t...]]></description>
            <content:encoded><![CDATA[According to Unit42, a financial firm was attacked by an adversary that manipulated, and compromised it’s cloud workloads. The threat actor was able to drop storage components such as buckets and tables, threatened the firm to leak data if ransom will not paid and eventually t...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Trigona targeting MSSQL servers (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/trigona-targeting-mssql-servers</link>
            <guid isPermaLink="false">3a750245-3d99-4aea-8516-e7979f5f33e6</guid>
            <pubDate>Mon, 17 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft SQL servers were observed being attacked through brute-force or dictionary attacks that exploit weak account credentials. The servers were then used as entry points to deploy Trigona ransomware and encrypt all filesOnce the attackers gain access to a server, they dep...]]></description>
            <content:encoded><![CDATA[Microsoft SQL servers were observed being attacked through brute-force or dictionary attacks that exploit weak account credentials. The servers were then used as entry points to deploy Trigona ransomware and encrypt all filesOnce the attackers gain access to a server, they dep...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Mexals cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/mexals-cryptojacking-campaign</link>
            <guid isPermaLink="false">d4e3f32b-19c8-44b8-ab53-97241ab1c9ad</guid>
            <pubDate>Wed, 12 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-04-12, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, Cron persistence, UPX packing, to achieve Resource hijacking. The following tools were observed: XMRig.]]></description>
            <content:encoded><![CDATA[On 2023-04-12, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, Cron persistence, UPX packing, to achieve Resource hijacking. The following tools were observed: XMRig.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[MuddyWater cloud destruction operation (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/muddywater-cloud-destruction-operation</link>
            <guid isPermaLink="false">cbed3c09-05c9-4c62-ba57-1ef585e6dcb4</guid>
            <pubDate>Fri, 07 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Microsoft identified a destructive operation executed by MuddyWater (also known as MERCURY or Mango Sandstorm), a threat actor attributed to the Iranian government, in partnership with “DarkBit” (who gained notoriety for attacking the Technion, an Israeli university, in Februa...]]></description>
            <content:encoded><![CDATA[Microsoft identified a destructive operation executed by MuddyWater (also known as MERCURY or Mango Sandstorm), a threat actor attributed to the Iranian government, in partnership with “DarkBit” (who gained notoriety for attacking the Technion, an Israeli university, in Februa...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[AlienFox campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/alienfox-campaign</link>
            <guid isPermaLink="false">2282da58-92d7-40dc-8585-839327cb013f</guid>
            <pubDate>Thu, 30 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-30, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: AlienFox.]]></description>
            <content:encoded><![CDATA[On 2023-03-30, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: AlienFox.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[3CX and Trading Technologies supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/3cx-and-trading-technologies-supply-chain-attack</link>
            <guid isPermaLink="false">70417214-a12a-4be6-81bf-bcd919b1b796</guid>
            <pubDate>Wed, 29 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In March 2023, a North Korean threat actor (dubbed “SmoothOperator”) gained access to 3CX (VoIP vendor) and inserted a backdoor into their desktop product, which was used for targeting some of their customers - primarily crypto companies. Researchers later discovered 3CX thems...]]></description>
            <content:encoded><![CDATA[In March 2023, a North Korean threat actor (dubbed “SmoothOperator”) gained access to 3CX (VoIP vendor) and inserted a backdoor into their desktop product, which was used for targeting some of their customers - primarily crypto companies. Researchers later discovered 3CX thems...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ChinaZ campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/chinaz-campaigns</link>
            <guid isPermaLink="false">17d0ba67-7aed-4488-b3c0-34b597951cfa</guid>
            <pubDate>Fri, 24 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-24, a campaign was reported, involving ChinaZ, gaining initial access via , while using Misconfigured SSH abuse,.]]></description>
            <content:encoded><![CDATA[On 2023-03-24, a campaign was reported, involving ChinaZ, gaining initial access via , while using Misconfigured SSH abuse,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[JavaScript injection via vulnerable CMS (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/javascript-injection-via-vulnerable-cms</link>
            <guid isPermaLink="false">650ff3b6-1454-4115-ac76-c441e85be3e4</guid>
            <pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-23, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2023-03-23, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC3886 campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc3886-campaigns</link>
            <guid isPermaLink="false">6cb13035-05f4-4437-a281-3c7f109c1838</guid>
            <pubDate>Thu, 16 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-16, a campaign was reported, involving UNC3886, gaining initial access via 1-day vulnerability, targeting ESXi Server, Fortinet Fortigate to achieve Data exfiltration. The following tools were observed: Reptile.]]></description>
            <content:encoded><![CDATA[On 2023-03-16, a campaign was reported, involving UNC3886, gaining initial access via 1-day vulnerability, targeting ESXi Server, Fortinet Fortigate to achieve Data exfiltration. The following tools were observed: Reptile.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Dero cryptojacking targeting K8s (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dero-cryptojacking-targeting-k8s</link>
            <guid isPermaLink="false">ea9c4a21-38dd-40f1-9238-71188cc746a1</guid>
            <pubDate>Wed, 15 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-15, a campaign was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Cloud compute cryptojacking, K8s anonymous auth abuse, targeting Kubernetes to achieve Resource hijacking. The following tools were observed: DERO miner.]]></description>
            <content:encoded><![CDATA[On 2023-03-15, a campaign was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Cloud compute cryptojacking, K8s anonymous auth abuse, targeting Kubernetes to achieve Resource hijacking. The following tools were observed: DERO miner.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GoBruteforcer campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gobruteforcer-campaign</link>
            <guid isPermaLink="false">1164a85a-65e8-477e-9b79-a58d16858386</guid>
            <pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[GoBruteforcer is a new kind of botnet malware that is written in Golang, and targets web servers, specifically those running phpMyAdmin, MySQL, FTP and Postgres services. The following information is based on samples discovered by researchers in March 2023.The GoBruteforcer ma...]]></description>
            <content:encoded><![CDATA[GoBruteforcer is a new kind of botnet malware that is written in Golang, and targets web servers, specifically those running phpMyAdmin, MySQL, FTP and Postgres services. The following information is based on samples discovered by researchers in March 2023.The GoBruteforcer ma...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[IceFire Aspera Faspex campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/icefire-aspera-faspex-campaign</link>
            <guid isPermaLink="false">082e73ef-06df-4491-9004-a158e6e93c18</guid>
            <pubDate>Thu, 09 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-09, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Aspera Faspex to achieve RansomOp. The following tools were observed: IceFire.]]></description>
            <content:encoded><![CDATA[On 2023-03-09, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Aspera Faspex to achieve RansomOp. The following tools were observed: IceFire.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Stealing the LIGHTSHOW (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/stealing-the-lightshow</link>
            <guid isPermaLink="false">9fa84546-578e-4fd5-9baf-46f89fee258c</guid>
            <pubDate>Thu, 09 Mar 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-03-09, a campaign was reported, involving UNC2970, gaining initial access via , while using Azure AD abuse, Intune abuse,.]]></description>
            <content:encoded><![CDATA[On 2023-03-09, a campaign was reported, involving UNC2970, gaining initial access via , while using Azure AD abuse, Intune abuse,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[scarleteel (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/scarleteel</link>
            <guid isPermaLink="false">17f45ab4-0e42-447c-a51c-b7f53174c36f</guid>
            <pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[In early 2023, Sysdig researchers discovered a cyber operation targeting public-facing containerized web apps running in a self-hosted K8s cluster, in order to mine for cryptocurrency and infiltrate the larger cloud environment. The operation, dubbed "SCARLETEEL", involved ret...]]></description>
            <content:encoded><![CDATA[In early 2023, Sysdig researchers discovered a cyber operation targeting public-facing containerized web apps running in a self-hosted K8s cluster, in order to mine for cryptocurrency and infiltrate the larger cloud environment. The operation, dubbed "SCARLETEEL", involved ret...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Fayvo exposed database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/fayvo-exposed-database</link>
            <guid isPermaLink="false">47a78e09-abc7-422c-9f8d-11cabc3afb97</guid>
            <pubDate>Thu, 23 Feb 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Security researchers discovered a database containing sensitive data operated by Fayvo, a Saudi Arabia-based social media app. The server hosting the database also leaked its staging environment file, which led to another unprotected environment file with MySQL credentials, AW...]]></description>
            <content:encoded><![CDATA[Security researchers discovered a database containing sensitive data operated by Fayvo, a Saudi Arabia-based social media app. The server hosting the database also leaked its staging environment file, which led to another unprotected environment file with MySQL credentials, AW...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[US military email server exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/us-military-email-server-exposure</link>
            <guid isPermaLink="false">0ce12a63-559e-4c66-9ea5-41f2c518df4a</guid>
            <pubDate>Sat, 18 Feb 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2023-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[esxiargs-attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/esxiargs-attack</link>
            <guid isPermaLink="false">f6173ce1-a633-4825-8448-23b9bf0a7129</guid>
            <pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-02-03, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve RansomOp. The following tools were observed: Babuk.]]></description>
            <content:encoded><![CDATA[On 2023-02-03, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve RansomOp. The following tools were observed: Babuk.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[HeadCrab campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/headcrab-campaign</link>
            <guid isPermaLink="false">9f0dbc56-3e13-42c2-b760-8b4e0584b460</guid>
            <pubDate>Wed, 01 Feb 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-02-01, a campaign was reported, involving HeadCrab operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis to achieve Resource hijacking. The following tools were observed: HeadCrab.]]></description>
            <content:encoded><![CDATA[On 2023-02-01, a campaign was reported, involving HeadCrab operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis to achieve Resource hijacking. The following tools were observed: HeadCrab.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[GitHub certificate theft incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/github-certificate-theft-incident</link>
            <guid isPermaLink="false">613941aa-2f58-44bd-99fb-5ec87ffb0a39</guid>
            <pubDate>Mon, 30 Jan 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-01-30, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Phishing, targeting GitHub to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2023-01-30, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Phishing, targeting GitHub to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CommuteAir exposed Jenkins (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/commuteair-exposed-jenkins</link>
            <guid isPermaLink="false">00396437-cfc7-456c-9ff6-f81d9c82eb56</guid>
            <pubDate>Thu, 19 Jan 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2023-01-19, a research was reported, involving , gaining initial access via Software misconfig, targeting Jenkins to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2023-01-19, a research was reported, involving , gaining initial access via Software misconfig, targeting Jenkins to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[circleci-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/circleci-breach</link>
            <guid isPermaLink="false">4593cd99-6193-41bd-b8c7-b76b8db53049</guid>
            <pubDate>Wed, 04 Jan 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[On December 29, 2022, CircleCI's security team were alerted to suspicious activity on one of their customer's GitHub OAuth tokens. The team then rotated all GitHub OAuth tokens on December 31, 2022 as a precautionary measure. By January 4, 2023, CircleCI's internal investigati...]]></description>
            <content:encoded><![CDATA[On December 29, 2022, CircleCI's security team were alerted to suspicious activity on one of their customer's GitHub OAuth tokens. The team then rotated all GitHub OAuth tokens on December 31, 2022 as a precautionary measure. By January 4, 2023, CircleCI's internal investigati...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PyTorch-nightly torchtriton dependency compromise (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/pytorch-nightly-torchtriton-dependency-compromise</link>
            <guid isPermaLink="false">286d8c76-b6ae-80a9-923a-d0a153f51a36</guid>
            <pubDate>Sat, 31 Dec 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[PyTorch-nightly Linux packages installed via pip between December 25th and December 30th, 2022 ran a malicious binary. The malicious binary was introduced by a dependency, torchtriton, that was vulnerable to dependency confusion. The malicious payload gathered system informati...]]></description>
            <content:encoded><![CDATA[PyTorch-nightly Linux packages installed via pip between December 25th and December 30th, 2022 ran a malicious binary. The malicious binary was introduced by a dependency, torchtriton, that was vulnerable to dependency confusion. The malicious payload gathered system informati...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Jupyter Notebook cred harvesting campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/jupyter-notebook-cred-harvesting-campaign</link>
            <guid isPermaLink="false">aaba646d-8a68-47e5-869a-b83d5422eadd</guid>
            <pubDate>Wed, 28 Dec 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Permiso identified a credential harvesting campaign targeting cloud infrastructure for the purpose of harvesting credentials. The majority of the victim system were running public facing Juptyer Notebooks. At the time of writing there were about 50 compromised systems. The ini...]]></description>
            <content:encoded><![CDATA[Permiso identified a credential harvesting campaign targeting cloud infrastructure for the purpose of harvesting credentials. The majority of the victim system were running public facing Juptyer Notebooks. At the time of writing there were about 50 compromised systems. The ini...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Okta source code theft (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/okta-source-code-theft</link>
            <guid isPermaLink="false">104b2670-bb4c-4326-a214-666b05965aae</guid>
            <pubDate>Wed, 21 Dec 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-12-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, targeting GitHub to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2022-12-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, targeting GitHub to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Redigo campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/redigo-campaign</link>
            <guid isPermaLink="false">98933ea2-16e2-4d02-9f49-0300f97b3513</guid>
            <pubDate>Thu, 01 Dec 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-12-01, a campaign was reported, involving Redigo operator, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Redis with unknown impact. The following tools were observed: Redigo.]]></description>
            <content:encoded><![CDATA[On 2022-12-01, a campaign was reported, involving Redigo operator, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Redis with unknown impact. The following tools were observed: Redigo.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[lastpass-goto-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/lastpass-goto-breach</link>
            <guid isPermaLink="false">c2052838-17e9-4746-a2e9-b656fe03b3aa</guid>
            <pubDate>Wed, 30 Nov 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[In November 2022, GoTo (formerly LogMeIn) disclosed a security breach of their development environment and a cloud storage service used by them and LastPass (their affiliate).The investigation determined that the threat actor gained access to the development environment using ...]]></description>
            <content:encoded><![CDATA[In November 2022, GoTo (formerly LogMeIn) disclosed a security breach of their development environment and a cloud storage service used by them and LastPass (their affiliate).The investigation determined that the threat actor gained access to the development environment using ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[WatchDog East-Asian CSP campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/watchdog-east-asian-csp-campaign</link>
            <guid isPermaLink="false">4aeddf6c-b5fb-4a7d-b4af-6fb3fb0767f7</guid>
            <pubDate>Wed, 16 Nov 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-11-16, a campaign was reported, involving WatchDog, gaining initial access via ,.]]></description>
            <content:encoded><![CDATA[On 2022-11-16, a campaign was reported, involving WatchDog, gaining initial access via ,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Dropbox Github breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/dropbox-github-breach</link>
            <guid isPermaLink="false">13ad8c76-b6ae-8032-9b14-d933d3b9dcda</guid>
            <pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Dropbox disclosed a security breach where attackers stole 130 code repositories from one of its GitHub accounts by using credentials obtained from phishing Dropbox employees. The breach was discovered on October 14, following a GitHub alert. Attackers impersonated CircleCI in ...]]></description>
            <content:encoded><![CDATA[Dropbox disclosed a security breach where attackers stole 130 code repositories from one of its GitHub accounts by using credentials obtained from phishing Dropbox employees. The breach was discovered on October 14, following a GitHub alert. Attackers impersonated CircleCI in ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Dropbox breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/dropbox-breach</link>
            <guid isPermaLink="false">3320131e-413c-42cb-92ba-2c26d7e082cf</guid>
            <pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-11-01, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2022-11-01, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Backdooring self-hosted GitHub Runner (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/backdooring-self-hosted-github-runner</link>
            <guid isPermaLink="false">a9aec8d7-732a-44c4-aa71-f74d609fec86</guid>
            <pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Misconfigured GitHub Runner abuse, targeting GitHub to achieve None.]]></description>
            <content:encoded><![CDATA[On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Misconfigured GitHub Runner abuse, targeting GitHub to achieve None.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[reuters-leaky-elasticsearch-dbs (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/reuters-leaky-elasticsearch-dbs</link>
            <guid isPermaLink="false">875add9d-7ed9-4cbc-aeda-f27d225d8e63</guid>
            <pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Public exposure abuse, targeting Elasticsearch to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Public exposure abuse, targeting Elasticsearch to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Leaked long-lived AWS creds (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/leaked-long-lived-aws-creds</link>
            <guid isPermaLink="false">5183d3f3-da31-4c2d-a31c-04a567df8593</guid>
            <pubDate>Fri, 07 Oct 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Impacted organization discovered that long-lived AWS creds had leaked. Initially alerted to the following suspicious activity:Follow-up investigation into CloudTrail logs showed compromise of multiple IAM accounts and evidence of leakage of long-lived access keys.]]></description>
            <content:encoded><![CDATA[Impacted organization discovered that long-lived AWS creds had leaked. Initially alerted to the following suspicious activity:Follow-up investigation into CloudTrail logs showed compromise of multiple IAM accounts and evidence of leakage of long-lived access keys.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Auth0 source code theft (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/auth0-source-code-theft</link>
            <guid isPermaLink="false">3d507cb3-8221-4c10-a4f5-d751cef279d5</guid>
            <pubDate>Mon, 26 Sep 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-09-26, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2022-09-26, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[fast-company-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/fast-company-breach</link>
            <guid isPermaLink="false">502fd131-36e8-44fa-9d6b-902bb532a45a</guid>
            <pubDate>Sun, 25 Sep 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Fast Company took its website offline after its content management system (CMS) was hacked to display stories and push out Apple News notifications containing obscene and racist comments.A “Breached” hacking forum member named 'Thrax' published a database dump with 6,737 emplo...]]></description>
            <content:encoded><![CDATA[Fast Company took its website offline after its content management system (CMS) was hacked to display stories and push out Apple News notifications containing obscene and racist comments.A “Breached” hacking forum member named 'Thrax' published a database dump with 6,737 emplo...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[optus-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/optus-breach</link>
            <guid isPermaLink="false">3ec7e9dc-6c35-413c-871d-2c08280ad528</guid>
            <pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[A hacker reportedly stole ~11mil records of customer PII (dated 2017) from Optus, an Australian telco company. The data was disclosed and put on sale in late September 22’. According to information obtained by a reporter who claimed to be in contact with the hacker, the root c...]]></description>
            <content:encoded><![CDATA[A hacker reportedly stole ~11mil records of customer PII (dated 2017) from Optus, an Australian telco company. The data was disclosed and put on sale in late September 22’. According to information obtained by a reporter who claimed to be in contact with the hacker, the root c...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Redirection Roulette (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/redirection-roulette</link>
            <guid isPermaLink="false">e8c342ab-6024-42f6-8211-eaca979f3014</guid>
            <pubDate>Thu, 01 Sep 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Beginning in early September 2022, an unknown threat actor successfully compromised tens of thousands of websites mainly aimed at East Asian audiences, redirecting hundreds of thousands of their users to adult-themed content. In several cases, the threat actor connected to the...]]></description>
            <content:encoded><![CDATA[Beginning in early September 2022, an unknown threat actor successfully compromised tens of thousands of websites mainly aimed at East Asian audiences, redirecting hundreds of thousands of their users to adult-themed content. In several cases, the threat actor connected to the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Kiss-A-Dog campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/kiss-a-dog-campaign</link>
            <guid isPermaLink="false">dcb94760-a6f8-44f5-a7f8-17f6ee8dfa30</guid>
            <pubDate>Thu, 01 Sep 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[CrowdStrike uncovered a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure using an obscure domain from the payload, container escape attempt and anonymized “dog”-themed mining pool domains.Nicknamed “Kiss-a-dog,” the campaign used multiple comman...]]></description>
            <content:encoded><![CDATA[CrowdStrike uncovered a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure using an obscure domain from the payload, container escape attempt and anonymized “dog”-themed mining pool domains.Nicknamed “Kiss-a-dog,” the campaign used multiple comman...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[APT29 targeting Microsoft 365 (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/apt29-targeting-microsoft-365</link>
            <guid isPermaLink="false">a4018894-b867-478f-a2f4-d05fad7c24d3</guid>
            <pubDate>Mon, 22 Aug 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-08-22, a campaign was reported, involving APT29, gaining initial access via , while using Add attacker-controlled IdP via ADFS access, Disable logging, MFA enrollment, Auth token signing via Golden SAML, Auth token signing via ADFS access,.]]></description>
            <content:encoded><![CDATA[On 2022-08-22, a campaign was reported, involving APT29, gaining initial access via , while using Add attacker-controlled IdP via ADFS access, Disable logging, MFA enrollment, Auth token signing via Golden SAML, Auth token signing via ADFS access,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Microsoft credential exposure on GitHub (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/microsoft-credential-exposure-on-github</link>
            <guid isPermaLink="false">4d6c43eb-cf09-4433-a0e3-2165dc04bd3c</guid>
            <pubDate>Tue, 16 Aug 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-08-16, a research was reported, involving , gaining initial access via Exposed secret, targeting GitHub to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2022-08-16, a research was reported, involving , gaining initial access via Exposed secret, targeting GitHub to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[twilio-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/twilio-breach</link>
            <guid isPermaLink="false">3906362c-5eb7-457b-af15-c5ad18a2caf7</guid>
            <pubDate>Mon, 08 Aug 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[A threat actor dubbed “Oktapus” / “ScatterSwine” conducted a widespread SMishing campaign against 136 organizations, and in some cases (Such as MailChimp, DoorDash and Digital Ocean) was successful in gaining initial access to their systems and exfiltrating customer data. One ...]]></description>
            <content:encoded><![CDATA[A threat actor dubbed “Oktapus” / “ScatterSwine” conducted a widespread SMishing campaign against 136 organizations, and in some cases (Such as MailChimp, DoorDash and Digital Ocean) was successful in gaining initial access to their systems and exfiltrating customer data. One ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[PREMINT hack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/premint-hack</link>
            <guid isPermaLink="false">1aad8c76-b6ae-80e2-80be-f317ec2e2fde</guid>
            <pubDate>Mon, 18 Jul 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-07-18, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, to achieve Supply chain attack, Denial of wallet.]]></description>
            <content:encoded><![CDATA[On 2022-07-18, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, to achieve Supply chain attack, Denial of wallet.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Bondnet campaign (2022) (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/bondnet-campaign-2022</link>
            <guid isPermaLink="false">3c6fc185-3759-4ec8-ba2e-754df0566269</guid>
            <pubDate>Mon, 11 Jul 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-07-11, a campaign was reported, involving Bondnet, gaining initial access via Password attack, targeting Microsoft SQL Server to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2022-07-11, a campaign was reported, involving Bondnet, gaining initial access via Password attack, targeting Microsoft SQL Server to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[8220 Gang targeting Confluence (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/8220-gang-targeting-confluence</link>
            <guid isPermaLink="false">7724a7be-9389-486e-9bab-20c62b2efb84</guid>
            <pubDate>Thu, 07 Jul 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-07-07, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2022-07-07, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[darkradiation-container-ransomwarewiper (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/darkradiation-container-ransomwarewiper</link>
            <guid isPermaLink="false">a08b1539-fb18-40c1-b1a1-de14fbffa615</guid>
            <pubDate>Tue, 21 Jun 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-06-21, a campaign was reported, involving DarkRadiation operator, gaining initial access via Unknown, while using Database ransomware, Disk Wipe, Remotely execute commands or scripts on a VM , Rootkit - LD_PRELOAD, targeting Docker to achieve RansomOp.]]></description>
            <content:encoded><![CDATA[On 2022-06-21, a campaign was reported, involving DarkRadiation operator, gaining initial access via Unknown, while using Database ransomware, Disk Wipe, Remotely execute commands or scripts on a VM , Rootkit - LD_PRELOAD, targeting Docker to achieve RansomOp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[incident-report-spotting-an-attacker-in-gcp (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/incident-report-spotting-an-attacker-in-gcp</link>
            <guid isPermaLink="false">af11d40a-e228-41de-af0e-718eb8d45d10</guid>
            <pubDate>Thu, 09 Jun 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[https://expel.com/blog/incident-report-spotting-an-attacker-in-gcp/]]></description>
            <content:encoded><![CDATA[https://expel.com/blog/incident-report-spotting-an-attacker-in-gcp/]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[JavaScript injection via WordPress exploitation (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/javascript-injection-via-wordpress-exploitation</link>
            <guid isPermaLink="false">69ecd12e-8ee3-419d-919e-851202da4c31</guid>
            <pubDate>Wed, 11 May 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-05-11, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting WordPress to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2022-05-11, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting WordPress to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC2903 campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc2903-campaigns</link>
            <guid isPermaLink="false">0e0ac67b-eab7-4abe-a279-c9637a3d250f</guid>
            <pubDate>Wed, 04 May 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-05-04, a campaign was reported, involving UNC2903, gaining initial access via , while using IMDS abuse, SSRF,.]]></description>
            <content:encoded><![CDATA[On 2022-05-04, a campaign was reported, involving UNC2903, gaining initial access via , while using IMDS abuse, SSRF,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LemonDuck Docker campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/lemonduck-docker-campaign</link>
            <guid isPermaLink="false">837e7c36-4579-4a14-b724-8623ebbaed64</guid>
            <pubDate>Thu, 21 Apr 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-04-21, a campaign was reported, involving LemonDuck, gaining initial access via ,.]]></description>
            <content:encoded><![CDATA[On 2022-04-21, a campaign was reported, involving LemonDuck, gaining initial access via ,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[github-npm-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/github-npm-breach</link>
            <guid isPermaLink="false">6de423b4-d8d6-40e1-8793-7fc0829f8e01</guid>
            <pubDate>Fri, 15 Apr 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On April 12, 2022, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm.According to GitHu...]]></description>
            <content:encoded><![CDATA[On April 12, 2022, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm.According to GitHu...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Denonia campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/denonia-campaign</link>
            <guid isPermaLink="false">b3b95e9d-2656-4737-9573-fef857cd8f42</guid>
            <pubDate>Wed, 06 Apr 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Denonia is a newly discovered type of malware targeting AWS Lambda environments. It was recently exposed by Cado Security, who named it after the domain it communicates with. Once the malware is executed on the victim's host, it launches XMRig cryptominer.Denonia's delivery an...]]></description>
            <content:encoded><![CDATA[Denonia is a newly discovered type of malware targeting AWS Lambda environments. It was recently exposed by Cado Security, who named it after the domain it communicates with. Once the malware is executed on the victim's host, it launches XMRig cryptominer.Denonia's delivery an...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[incident-report-from-cli-to-console-chasing-an-attacker-in-aws (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/incident-report-from-cli-to-console-chasing-an-attacker-in-aws</link>
            <guid isPermaLink="false">24b99db6-6d3e-43fa-802e-4b374574fc56</guid>
            <pubDate>Tue, 05 Apr 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[Expel’s SOC detected unauthorized access into one of their customer’s Amazon Web Services (AWS) environments. The attacker used a long-term access key to gain initial access. Once they got in, they were able to abuse the AWS Identity and Access Management (IAM) service to esca...]]></description>
            <content:encoded><![CDATA[Expel’s SOC detected unauthorized access into one of their customer’s Amazon Web Services (AWS) environments. The attacker used a long-term access key to gain initial access. Once they got in, they were able to abuse the AWS Identity and Access Management (IAM) service to esca...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Muhstick Redis campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/muhstick-redis-campaign</link>
            <guid isPermaLink="false">4266b401-d74c-4e57-82a2-48f187d4a49d</guid>
            <pubDate>Mon, 28 Mar 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-03-28, a campaign was reported, involving Muhstik operator, gaining initial access via ,.]]></description>
            <content:encoded><![CDATA[On 2022-03-28, a campaign was reported, involving Muhstik operator, gaining initial access via ,.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[LAPSUS$ campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/lapsus-campaigns</link>
            <guid isPermaLink="false">497915aa-a11d-4ceb-a062-4c52d6211b65</guid>
            <pubDate>Tue, 22 Mar 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[According to Microsoft Threat Research, as part of LAPSUS$’s large-scale social engineering and extortion campaigns, they also gained access to several of their targets’ cloud environments.LAPSUS$ initially targeted organizations in the UK and South America, and then expanded ...]]></description>
            <content:encoded><![CDATA[According to Microsoft Threat Research, as part of LAPSUS$’s large-scale social engineering and extortion campaigns, they also gained access to several of their targets’ cloud environments.LAPSUS$ initially targeted organizations in the UK and South America, and then expanded ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[CoinStomp campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/coinstomp-campaign</link>
            <guid isPermaLink="false">bf884076-67e2-4195-ad87-1e1d31658163</guid>
            <pubDate>Wed, 02 Feb 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2022-02-02, a campaign was reported, involving CoinStomp operator, gaining initial access via , while using Timestomping, Reverse shell, Cron persistence,. The following tools were observed: CoinStomp.]]></description>
            <content:encoded><![CDATA[On 2022-02-02, a campaign was reported, involving CoinStomp operator, gaining initial access via , while using Timestomping, Reverse shell, Cron persistence,. The following tools were observed: CoinStomp.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From code commit to production takeover (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-code-commit-to-production-takeover</link>
            <guid isPermaLink="false">ec5e8e4d-70be-4375-8672-cc5afe993322</guid>
            <pubDate>Thu, 13 Jan 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[NCC Group performed a pentest in which they had (notionally) compromised a developer's laptop who could commit code to a certain Java library. The researchers set a pre-requirement file to one that provided a Meterpreter shell from within the target build environment. They fou...]]></description>
            <content:encoded><![CDATA[NCC Group performed a pentest in which they had (notionally) compromised a developer's laptop who could commit code to a certain Java library. The researchers set a pre-requirement file to one that provided a Meterpreter shell from within the target build environment. They fou...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[From S3 bucket to Jenkins credential dump (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/from-s3-bucket-to-jenkins-credential-dump</link>
            <guid isPermaLink="false">6788c313-311a-4ec1-9359-c7ff0167101b</guid>
            <pubDate>Thu, 13 Jan 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[NCC Group performed a pentest against a web application, in which they leveraged anonymous access to discover a sitemap folder that turned out to be an S3 bucket with directory listing enabled. NCC identified a bash script containing a hardcoded Git credential, which granted a...]]></description>
            <content:encoded><![CDATA[NCC Group performed a pentest against a web application, in which they leveraged anonymous access to discover a sitemap folder that turned out to be an S3 bucket with directory listing enabled. NCC identified a bash script containing a hardcoded Git credential, which granted a...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[UNC3379 npm supply chain attacks (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/unc3379-npm-supply-chain-attacks</link>
            <guid isPermaLink="false">286d8c76-b6ae-8092-a2fc-c1bef03c0f9e</guid>
            <pubDate>Wed, 15 Dec 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[Mandiant has attributed supply chain attacks which compromised ua-parser-js , coa, and rc to UNC3379. The malicious packages would download and execute both a Monero cryptocurrency miner, and the DANABOT banking trojan, depending on the OS. ]]></description>
            <content:encoded><![CDATA[Mandiant has attributed supply chain attacks which compromised ua-parser-js , coa, and rc to UNC3379. The malicious packages would download and execute both a Monero cryptocurrency miner, and the DANABOT banking trojan, depending on the OS. ]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ivanti-supply-chain (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/ivanti-supply-chain</link>
            <guid isPermaLink="false">1aad8c76-b6ae-8063-86a4-ebe45459823c</guid>
            <pubDate>Thu, 02 Dec 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-12-02, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2021-12-02, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Tsunami targeting Jenkins and Weblogic (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/tsunami-targeting-jenkins-and-weblogic</link>
            <guid isPermaLink="false">0df126f2-74eb-4123-9429-8b78fa444115</guid>
            <pubDate>Tue, 26 Oct 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-10-26, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, 1-day vulnerability, targeting Jenkins, WebLogic to achieve Resource hijacking. The following tools were observed: Tsunami.]]></description>
            <content:encoded><![CDATA[On 2021-10-26, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, 1-day vulnerability, targeting Jenkins, WebLogic to achieve Resource hijacking. The following tools were observed: Tsunami.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Abcbot Huawei Cloud targeting campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/abcbot-huawei-cloud-targeting-campaign</link>
            <guid isPermaLink="false">25890a30-70fc-4d92-a944-e83112167eb1</guid>
            <pubDate>Fri, 08 Oct 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-10-08, a campaign was reported, involving Abcbot operator, gaining initial access via Cloud native misconfig, to achieve Resource hijacking. The following tools were observed: Kunpeng.]]></description>
            <content:encoded><![CDATA[On 2021-10-08, a campaign was reported, involving Abcbot operator, gaining initial access via Cloud native misconfig, to achieve Resource hijacking. The following tools were observed: Kunpeng.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Siloscape campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/siloscape-campaign</link>
            <guid isPermaLink="false">1ee66e53-4770-4300-bd87-f42d0fb38734</guid>
            <pubDate>Mon, 07 Jun 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-06-07, a campaign was reported, involving Siloscape operator, gaining initial access via 1-day vulnerability, Web vulnerability, while using TOR anonymization, Thread impersonation to escape to host, targeting Kubernetes with unknown impact. The following tools were observed: Siloscape.]]></description>
            <content:encoded><![CDATA[On 2021-06-07, a campaign was reported, involving Siloscape operator, gaining initial access via 1-day vulnerability, Web vulnerability, while using TOR anonymization, Thread impersonation to escape to host, targeting Kubernetes with unknown impact. The following tools were observed: Siloscape.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Codecov incident (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/codecov-incident</link>
            <guid isPermaLink="false">a9035eab-dbee-4df9-98a5-c4b19c809a9b</guid>
            <pubDate>Thu, 15 Apr 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On April 2021, Codecov was compromised by an unknown threat actor who abused their access to the company's cloud environment to conduct a supply chain attack. The threat actor gained initial access to Codecov's GCP environment by extracting an HMAC key for a service account fr...]]></description>
            <content:encoded><![CDATA[On April 2021, Codecov was compromised by an unknown threat actor who abused their access to the company's cloud environment to conduct a supply chain attack. The threat actor gained initial access to Codecov's GCP environment by extracting an HMAC key for a service account fr...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Multiple organizations vulnerable to dependency confusion (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/multiple-organizations-vulnerable-to-dependency-confusion</link>
            <guid isPermaLink="false">54a0557e-ae76-49fb-a660-f1da1ac6f4c1</guid>
            <pubDate>Tue, 09 Feb 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-02-09, a research was reported, involving , gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve None.]]></description>
            <content:encoded><![CDATA[On 2021-02-09, a research was reported, involving , gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve None.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Gin Docker cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/gin-docker-cryptojacking-campaign</link>
            <guid isPermaLink="false">3ee26498-33c9-48d3-b9d8-9d174757d883</guid>
            <pubDate>Tue, 09 Feb 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-02-09, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Escape to host via cgroups release_agent, targeting Docker to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2021-02-09, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Escape to host via cgroups release_agent, targeting Docker to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[TeamTNT campaigns (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/teamtnt-campaigns</link>
            <guid isPermaLink="false">d16ea821-c009-4cd4-87d5-4a1c65dd168c</guid>
            <pubDate>Wed, 03 Feb 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2021-02-03, a campaign was reported, involving TeamTNT, gaining initial access via ,. The following tools were observed: Peirates, Hildegard.]]></description>
            <content:encoded><![CDATA[On 2021-02-03, a campaign was reported, involving TeamTNT, gaining initial access via ,. The following tools were observed: Peirates, Hildegard.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[dreambus-campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/dreambus-campaign</link>
            <guid isPermaLink="false">08db964d-bb69-4400-86dc-b41ee3ed07fe</guid>
            <pubDate>Fri, 22 Jan 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[See Dreambus operator for more information.]]></description>
            <content:encoded><![CDATA[See Dreambus operator for more information.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[solarwinds-supply-chain-attack (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/solarwinds-supply-chain-attack</link>
            <guid isPermaLink="false">7eddffc5-f02f-470b-a936-fe7dad2d30a8</guid>
            <pubDate>Sun, 13 Dec 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[What seemed to be at first a targeted attack against FireEye, turned out to be a much worse espionage campaign associated with APT29 that the United State has suffered from.The SolarWinds attackers, linked to a Mimecast attack on Jan 13th, executed a sophisticated supply chain...]]></description>
            <content:encoded><![CDATA[What seemed to be at first a targeted attack against FireEye, turned out to be a much worse espionage campaign associated with APT29 that the United State has suffered from.The SolarWinds attackers, linked to a Mimecast attack on Jan 13th, executed a sophisticated supply chain...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Loggerminer campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/loggerminer-campaign</link>
            <guid isPermaLink="false">dabbd8d2-a04f-434e-9722-ece0f7993981</guid>
            <pubDate>Mon, 16 Nov 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-11-16, a campaign was reported, involving Abcbot operator, gaining initial access via , to achieve Resource hijacking. The following tools were observed: Loggerminer.]]></description>
            <content:encoded><![CDATA[On 2020-11-16, a campaign was reported, involving Abcbot operator, gaining initial access via , to achieve Resource hijacking. The following tools were observed: Loggerminer.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Apple cloud key exposure (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/apple-cloud-key-exposure</link>
            <guid isPermaLink="false">9dce1178-73fb-4ff1-9006-f040b810a096</guid>
            <pubDate>Wed, 07 Oct 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[Between July and October 2020, researchers discovered multiple web vulnerabilities affecting Apple’s network, some of which could have allowed exfiltration of AWS access keys.]]></description>
            <content:encoded><![CDATA[Between July and October 2020, researchers discovered multiple web vulnerabilities affecting Apple’s network, some of which could have allowed exfiltration of AWS access keys.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cetus campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cetus-campaign</link>
            <guid isPermaLink="false">de5be62f-b208-4515-8bea-c9e8bbbe52e4</guid>
            <pubDate>Thu, 27 Aug 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-08-27, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Cetus.]]></description>
            <content:encoded><![CDATA[On 2020-08-27, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Cetus.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Drizly data breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/drizly-data-breach</link>
            <guid isPermaLink="false">136d8c76-b6ae-80e8-8c0c-e1776f15d2c8</guid>
            <pubDate>Tue, 28 Jul 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[Drizly, an online alcohol delivery service, recently notified customers of a data breach in which a hacker accessed customer information. This breach reportedly affected up to 2.5 million accounts, exposing email addresses, dates of birth, and bcrypt-hashed passwords. In some ...]]></description>
            <content:encoded><![CDATA[Drizly, an online alcohol delivery service, recently notified customers of a data breach in which a hacker accessed customer information. This breach reportedly affected up to 2.5 million accounts, exposing email addresses, dates of birth, and bcrypt-hashed passwords. In some ...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Doki cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/doki-cryptojacking-campaign</link>
            <guid isPermaLink="false">b7b74427-041a-4648-8e7a-dba2d3e33b1c</guid>
            <pubDate>Tue, 28 Jul 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-07-28, a campaign was reported, involving Doki operator, gaining initial access via Software misconfig, while using Exploiting host mount to escape to host, targeting Docker to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2020-07-28, a campaign was reported, involving Doki operator, gaining initial access via Software misconfig, while using Exploiting host mount to escape to host, targeting Docker to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Behind the scenes in the Expel SOC: Alert-to-fix in AWS (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/behind-the-scenes-in-the-expel-soc-alert-to-fix-in-aws</link>
            <guid isPermaLink="false">9afa7383-c1f8-46d1-afda-b2ac3cd561a9</guid>
            <pubDate>Tue, 28 Jul 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[Over the July 4th holiday weekend Expel’s SOC spotted a coin-mining attack in a customer’s Amazon Web Services (AWS) environment. The attacker compromised the root IAM user access key and used it to enumerate the environment and spin up ten (10) c5.4xlarge EC2s to mine Monero....]]></description>
            <content:encoded><![CDATA[Over the July 4th holiday weekend Expel’s SOC spotted a coin-mining attack in a customer’s Amazon Web Services (AWS) environment. The attacker compromised the root IAM user access key and used it to enumerate the environment and spin up ten (10) c5.4xlarge EC2s to mine Monero....]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Meow database server campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/meow-database-server-campaign</link>
            <guid isPermaLink="false">ace65934-96a4-49a0-8e38-e8125403c92e</guid>
            <pubDate>Sat, 25 Jul 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-07-25, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using FTP access, Misconfigured DB abuse, targeting MongoDB, Elasticsearch, Apache Cassandra, Apache CouchDB, Jenkins, Apache Hadoop to achieve Data destruction.]]></description>
            <content:encoded><![CDATA[On 2020-07-25, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using FTP access, Misconfigured DB abuse, targeting MongoDB, Elasticsearch, Apache Cassandra, Apache CouchDB, Jenkins, Apache Hadoop to achieve Data destruction.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BlueKai exposed database (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/bluekai-exposed-database</link>
            <guid isPermaLink="false">08786e19-19da-4fb6-9c73-81f72a0418d7</guid>
            <pubDate>Fri, 19 Jun 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-06-19, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2020-06-19, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Exim exploitation by Sandworm (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/exim-exploitation-by-sandworm</link>
            <guid isPermaLink="false">d6814bbc-f7a4-4d15-be9a-08673a5138ff</guid>
            <pubDate>Thu, 28 May 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On May 28, 2020, the NSA released a cybersecurity advisory on Russian APT group Sandworm exploiting CVE-2019-10149, a vulnerability in Exim Mail Transfer Agent (MTA) software. An unauthenticated remote attacker can use this vulnerability to send a specially crafted email to ex...]]></description>
            <content:encoded><![CDATA[On May 28, 2020, the NSA released a cybersecurity advisory on Russian APT group Sandworm exploiting CVE-2019-10149, a vulnerability in Exim Mail Transfer Agent (MTA) software. An unauthenticated remote attacker can use this vulnerability to send a specially crafted email to ex...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Large-scale cryptomining attack against K8s clusters detected by Azure (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/large-scale-cryptomining-attack-against-k8s-clusters-detected-by-azure</link>
            <guid isPermaLink="false">1f45ecc9-1883-4906-b3e2-20a1d38e7fc4</guid>
            <pubDate>Wed, 08 Apr 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-04-08, a campaign was reported, involving an unknown actor, gaining initial access via , targeting Kubernetes to achieve Resource hijacking.]]></description>
            <content:encoded><![CDATA[On 2020-04-08, a campaign was reported, involving an unknown actor, gaining initial access via , targeting Kubernetes to achieve Resource hijacking.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[kinsing-campaign-2020 (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/kinsing-campaign-2020</link>
            <guid isPermaLink="false">c1aa2b92-9512-4b60-8461-4e0e3be68fa0</guid>
            <pubDate>Thu, 16 Jan 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2020-01-16, a campaign was reported, involving Kinsing operator, gaining initial access via Software misconfig, 1-day vulnerability, while using Vulnerability exploitation, Misconfigured Docker abuse, targeting Redis, Confluence Server, Docker, Apache Hadoop, Solr, ThinkPHP to achieve Resource hijacking. The following tools were observed: Kinsing.]]></description>
            <content:encoded><![CDATA[On 2020-01-16, a campaign was reported, involving Kinsing operator, gaining initial access via Software misconfig, 1-day vulnerability, while using Vulnerability exploitation, Misconfigured Docker abuse, targeting Redis, Confluence Server, Docker, Apache Hadoop, Solr, ThinkPHP to achieve Resource hijacking. The following tools were observed: Kinsing.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ubiquiti-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/ubiquiti-breach</link>
            <guid isPermaLink="false">db73badb-4924-48c3-aad8-18da12fb7c32</guid>
            <pubDate>Wed, 01 Jan 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[In 2020, Ubiquiti, a company that manufactures and sells wireless data communication and wired products, suffered a data breach and an extortion attempt of nearly $2 million at the hands of a senior developer working for the company. The attacker set a 1-day retention policy o...]]></description>
            <content:encoded><![CDATA[In 2020, Ubiquiti, a company that manufactures and sells wireless data communication and wired products, suffered a data breach and an extortion attempt of nearly $2 million at the hands of a senior developer working for the company. The attacker set a 1-day retention policy o...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Graboid campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/graboid-campaign</link>
            <guid isPermaLink="false">f9fac720-47cb-4912-8061-6ef431779dd0</guid>
            <pubDate>Wed, 16 Oct 2019 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2019-10-16, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Graboid.]]></description>
            <content:encoded><![CDATA[On 2019-10-16, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Graboid.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[imperva-data-leak (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/imperva-data-leak</link>
            <guid isPermaLink="false">8b7b4646-f1b6-49c9-880a-25550e88a57a</guid>
            <pubDate>Thu, 10 Oct 2019 00:00:00 GMT</pubDate>
            <description><![CDATA[Imperva identified an unknown threat actor using an administrative AWS API key in one of their production AWS accounts, which led to the exposure of an RDS database snapshot from September 2017 containing email addresses of Imperva Cloud WAF customers, hashed & salted password...]]></description>
            <content:encoded><![CDATA[Imperva identified an unknown threat actor using an administrative AWS API key in one of their production AWS accounts, which led to the exposure of an RDS database snapshot from September 2017 containing email addresses of Imperva Cloud WAF customers, hashed & salted password...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Webmin supply chain attack (2018) (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/webmin-supply-chain-attack-2018</link>
            <guid isPermaLink="false">5a5c8094-c1b4-4674-bfeb-71b62c11f677</guid>
            <pubDate>Thu, 15 Aug 2019 00:00:00 GMT</pubDate>
            <description><![CDATA[An unknown threat actor compromised the Webmin build server, and inserted a backdoor RCE vulnerability into the Webmin source code that anyone could exploit if they were aware of its existence. This backdoor persisted for over 15 months, likely being exploited as a 0day by the...]]></description>
            <content:encoded><![CDATA[An unknown threat actor compromised the Webmin build server, and inserted a backdoor RCE vulnerability into the Webmin source code that anyone could exploit if they were aware of its existence. This backdoor persisted for over 15 months, likely being exploited as a 0day by the...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[capital-one-breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/capital-one-breach</link>
            <guid isPermaLink="false">9a4a8982-f237-42ba-98c8-7f91a3047989</guid>
            <pubDate>Fri, 19 Jul 2019 00:00:00 GMT</pubDate>
            <description><![CDATA[In 2019, Capital One had over 100 million consumer credit applications exfiltrated from their AWS environment. The root cause was a combination of two main factors: first, a Server Side Request Forgery (SSRF) vulnerability in a Web Application Firewall (WAF) named “ModSecurity...]]></description>
            <content:encoded><![CDATA[In 2019, Capital One had over 100 million consumer credit applications exfiltrated from their AWS environment. The root cause was a combination of two main factors: first, a Server Side Request Forgery (SSRF) vulnerability in a Web Application Firewall (WAF) named “ModSecurity...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[ngrok cryptojacking campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/ngrok-cryptojacking-campaign</link>
            <guid isPermaLink="false">9c8aabdd-2839-4963-a481-3d1e633872b1</guid>
            <pubDate>Wed, 12 Sep 2018 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2018-09-12, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Redis, Apache CouchDB, Docker, Jenkins, Drupal, MODX to achieve Resource hijacking. The following tools were observed: ngrok.]]></description>
            <content:encoded><![CDATA[On 2018-09-12, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Redis, Apache CouchDB, Docker, Jenkins, Drupal, MODX to achieve Resource hijacking. The following tools were observed: ngrok.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[US DoD NIPRNet access via Atlassian SSRF (Research)]]></title>
            <link>https://threats.wiz.io/all-incidents/us-dod-niprnet-access-via-atlassian-ssrf</link>
            <guid isPermaLink="false">82845c7c-bda6-4352-b129-406a3953f09c</guid>
            <pubDate>Mon, 09 Apr 2018 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2018-04-09, a research was reported, involving , gaining initial access via 1-day vulnerability, while using SSRF, IMDS abuse, targeting Confluence Server, Jira Server to achieve Resp. disclosure.]]></description>
            <content:encoded><![CDATA[On 2018-04-09, a research was reported, involving , gaining initial access via 1-day vulnerability, while using SSRF, IMDS abuse, targeting Confluence Server, Jira Server to achieve Resp. disclosure.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[The Los Angeles Times Cryptomining Attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/the-los-angeles-times-cryptomining-attack</link>
            <guid isPermaLink="false">136d8c76-b6ae-801d-8dba-cf75dfd102b4</guid>
            <pubDate>Thu, 22 Feb 2018 00:00:00 GMT</pubDate>
            <description><![CDATA[The Los Angeles Times website was covertly mining cryptocurrency on visitors' devices after hackers injected CoinHive's Monero-mining code. This happened due to an unprotected Amazon S3 storage bucket, which allowed unrestricted public access, letting hackers modify site files...]]></description>
            <content:encoded><![CDATA[The Los Angeles Times website was covertly mining cryptocurrency on visitors' devices after hackers injected CoinHive's Monero-mining code. This happened due to an unprotected Amazon S3 storage bucket, which allowed unrestricted public access, letting hackers modify site files...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[BrowserStack Data Breach (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/browserstack-data-breach</link>
            <guid isPermaLink="false">134d8c76-b6ae-8067-9774-c62b2220311b</guid>
            <pubDate>Sun, 09 Nov 2014 00:00:00 GMT</pubDate>
            <description><![CDATA[On November 9, 2014, BrowserStack suffered a breach when a hacker accessed an old, unpatched prototype server via the shellshock vulnerability. The server contained AWS credentials, allowing the attacker to create an instance, access a backup, and partially copy user data (ema...]]></description>
            <content:encoded><![CDATA[On November 9, 2014, BrowserStack suffered a breach when a hacker accessed an old, unpatched prototype server via the shellshock vulnerability. The server contained AWS credentials, allowing the attacker to create an instance, access a backup, and partially copy user data (ema...]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Operation Windigo (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/operation-windigo</link>
            <guid isPermaLink="false">133d8c76-b6ae-802e-8225-c478ca30c108</guid>
            <pubDate>Tue, 18 Mar 2014 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2014-03-18, a campaign was reported, involving Windigo operator, gaining initial access via Supply chain vector, while using Create SSH backdoor, to achieve Resource hijacking. The following tools were observed: Ebury.]]></description>
            <content:encoded><![CDATA[On 2014-03-18, a campaign was reported, involving Windigo operator, gaining initial access via Supply chain vector, while using Create SSH backdoor, to achieve Resource hijacking. The following tools were observed: Ebury.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Cdorked campaign (Campaign)]]></title>
            <link>https://threats.wiz.io/all-incidents/cdorked-campaign</link>
            <guid isPermaLink="false">133d8c76-b6ae-80ac-a5a3-f5f11918ba48</guid>
            <pubDate>Tue, 07 May 2013 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2013-05-07, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, targeting Apache HTTP Server, NGINX, Lighttpd to achieve Resource hijacking. The following tools were observed: Cdorked.]]></description>
            <content:encoded><![CDATA[On 2013-05-07, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, targeting Apache HTTP Server, NGINX, Lighttpd to achieve Resource hijacking. The following tools were observed: Cdorked.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[kernel.org supply chain attack (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/kernelorg-supply-chain-attack</link>
            <guid isPermaLink="false">133d8c76-b6ae-80f5-95bb-fea703a5ff2b</guid>
            <pubDate>Wed, 31 Aug 2011 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2011-08-31, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Supply chain attack.]]></description>
            <content:encoded><![CDATA[On 2011-08-31, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Supply chain attack.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Operation Aurora (Incident)]]></title>
            <link>https://threats.wiz.io/all-incidents/operation-aurora</link>
            <guid isPermaLink="false">0cd8f9b7-743f-43ad-af3f-a9c767a35f4f</guid>
            <pubDate>Tue, 12 Jan 2010 00:00:00 GMT</pubDate>
            <description><![CDATA[On 2010-01-12, an incident was reported, involving Storm-0558, gaining initial access via Unknown, to achieve Data exfiltration.]]></description>
            <content:encoded><![CDATA[On 2010-01-12, an incident was reported, involving Storm-0558, gaining initial access via Unknown, to achieve Data exfiltration.]]></content:encoded>
            <author>threat.hunters@wiz.io (Wiz Threat Research)</author>
            <enclosure url="https://www.wiz.io/rss_feed_logo.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>