Attackers Link Tiny Flaws Into Lethal Chains Spanning Code and Cloud

A new webinar from Wiz explains how attackers chain together small coding bugs and cloud misconfigurations to access sensitive data, and how teams can break that path.

The Latest

Breaking News and Alerts

Attacker Steals Private Source Code from Grafana Labs After Exploiting CI Pipeline Flaw

The attacker exploited a misconfigured GitHub Action called a Pwn Request vulnerability to steal privileged tokens and download the source code from multiple private repositories.

Spotlight

Cybersecurity Profiles and Stories

Claw Chain Attack Exploits OpenClaw Flaws for Data Theft and Persistence

Cyera researchers discovered four OpenClaw vulnerabilities that form an attack chain allowing data theft, privilege escalation, and persistent backdoor access.

JavaScript IPC Library Node ipc Used in Fresh Supply Chain Attack

Three newly published versions of the node-ipc npm package contain obfuscated malware that steals cloud credentials and exfiltrates data through DNS queries.

Vercel Patches Dozen Flaws in Next.js and React Server Components

Vercel's security update for Next.js and React Server Components addresses over a dozen vulnerabilities, including denial of service, middleware bypass, and server side request forgery flaws.

PHP Image Functions Expose Servers to Memory Leaks via Crafted JPEGs

Attackers can leak heap memory or crash PHP servers by uploading specially crafted JPEG images to web applications that parse image metadata.

Features

Research and Thought Leadership