Product
Infostealer Incursion Targeting Cloud and AI Credentials
3 TTPsProlific infostealer families like Lumma, RedLine, and Vidar are leveraging industrialized malware-as-a-service to exfiltrate session tokens and API keys, enabling bypass of MFA and unauthorized access to cloud, code, and AI environments.
Version Control Systems DFIR and Incident Readiness
3 TTPsThreat actors are increasingly exploiting Version Control Systems for supply chain compromise, necessitating proactive audit log streaming and metadata configuration to overcome significant platform-specific visibility gaps.
Multiple Vulnerabilities in GitLab
2 TTPsGitLab is affected by multiple vulnerabilities that allow remote code execution, denial of service, data manipulation, and security control bypass.
AWS Bedrock Model Prompt or Completion Containing Credentials
1 rule 1 TTPA detection rule identifies AWS access key IDs, Amazon Bedrock API keys, PEM private-key blocks, and GitHub/GitLab tokens within Amazon Bedrock model prompts or completions, indicating a critical credential exposure event through misconfiguration, data leakage, or prompt injection that necessitates immediate secret rotation and investigation.
Shai-Hulud Campaign Activity
20 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
GitLab: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in GitLab allow a remote, authenticated attacker to execute arbitrary code, perform Cross-Site Scripting (XSS), manipulate data, or disclose sensitive information.
Compromised node-ipc npm Package Steals Credentials
2 rules 3 TTPs 2 IOCsHackers injected credential-stealing malware into newly published versions of the node-ipc npm package in a supply chain attack, collecting cloud credentials, SSH keys, CI/CD secrets, and other sensitive data, exfiltrating it through DNS TXT queries.