Get a Demo
Under Attack?

threat response

Shai-Hulud Strikes Again: intercom-client@7.0.4
Shai-Hulud Strikes Again: [email protected]

[email protected] Supply Chain Attack Enables Credential Theft: Shai-Hulud Strikes Again

Executive Summary [email protected] is a compromised npm package used in a supply chain attack to steal GitHub, npm, and multi-cloud credentials. The malicious version introduces a preinstall hook that executes an obfuscated payload, harvesting secrets and exfiltrating them via GitHub APIs. This activity is part of the Shai-Hulud worm campaign targeting CI/CD pipelines. Detection Summary…
CrackArmor: AppArmor Flaws Enable Local Privilege Escalation to Root
CrackArmor: AppArmor Flaws Enable Local Privilege Escalation to Root

CrackArmor: AppArmor Flaws Enable Local Privilege Escalation to Root

Executive Summary CrackArmor is a group of vulnerabilities affecting the Linux kernel AppArmor security module that allow local attackers to interfere with how AppArmor security profiles are managed and enforced. By abusing weaknesses in policy management and kernel profile parsing logic, an attacker with limited system access may weaken AppArmor protections or escalate privileges to…
hackerbot-claw Operation Review: Pull Requests as an Attack Vector in GitHub Actions
hackerbot-claw Operation Review: Pull Requests as an Attack Vector in GitHub Actions

hackerbot-claw Operation Review: Pull Requests as an Attack Vector in GitHub Actions

Executive Summary In February 2026, an autonomous bot named hackerbot-claw exploited insecure GitHub Actions configurations across multiple high-profile repositories. The campaign abused unsafe pull_request_target triggers, unsanitized inputs, dynamic shell execution, and overprivileged GITHUB_TOKEN permissions to achieve remote code execution (RCE) in GitHub-hosted runners. Across at least six repositories, the bot successfully executed arbitrary commands, and…
CVE-2025-14847: MongoDB zlib Compression Memory Disclosure
CVE-2025-14847: MongoDB zlib Compression Memory Disclosure

CVE-2025-14847: MongoDB zlib Compression Memory Disclosure

Executive Summary A critical unauthenticated vulnerability (CVE-2025-14847) has been identified in MongoDB Server, affecting how the database processes zlib-compressed network traffic. Under specific conditions, a remote attacker can trigger MongoDB to return uninitialized heap memory as part of a server response. Because this data originates from process memory, it may contain fragments of previously handled…
A diagram features a central purple circle with six arrows pointing outward to red circles containing icons: a lock, computer screen, fishing hook, smartphone, Bitcoin symbol, and stacked rectangles. The word upwind is at the top left.

Detect & Respond to Advanced Cloud Threats with Upwind

Upwind’s next-generation cloud security platform not only provides real-time risk analysis and threat detection, it also gives you the ability to respond to threats in real time.  In this article, we will dive deep into how Upwind detects threats in real time, our advanced methods of  activity-based threat detection, and ways you can stop or…
Screenshot of the Upwind platform showing response details in a table against a gradient background. The table includes timestamps, response statuses, and various metrics. Success status is highlighted in green.

Automate Threat Detection & Response for Kubernetes Workloads

Upwind’s real-time threat detection capabilities have helped our customers identify threats and bad actors the moment they enter their cloud environment. This real-time, runtime-powered capability is the definition of shift-right security, and we have now taken it one step further by providing the ability to respond to threats as soon as they are detected. With…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS