#MongoBleed
December 27, 2025 at 3:35 AM
The MongoBleed Vulnerability Is Absolutely Insane #Linux #YouTube youtu.be/hOUwH5A2oQs
The MongoBleed Vulnerability Is Absolutely Insane
YouTube video by Brodie Robertson
youtu.be
December 30, 2025 at 11:00 PM
A high-severity flaw known as MongoBleed (CVE-2025-14847) is currently being exploited in the wild. Wiz researchers have confirmed active exploitation.

Read More: www.security.land/mongobleed-a...

#SecurityLand #CyberSecurity #InfoSec #MongoDB #MongoBleed #DatabaseSecurity #Wiz #Shodan
MongoBleed CVE-2025-14847: Is Your MongoDB Exposed?
Dubbed "MongoBleed," CVE-2025-14847 allows unauthenticated attackers to exfiltrate sensitive data from MongoDB heap memory. With 87,000 instances exposed, active exploitation is now confirmed.
www.security.land
December 28, 2025 at 12:55 PM
87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released
87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online - PoC Exploit Released
cybersecuritynews.com
December 28, 2025 at 4:04 AM
How much longer are we going to give *end users* direct control over memory buffer sizes?

www.abstract.security/blog/critica...
Critical MongoDB Vulnerability: CVE-2025-14847 (MongoBleed)
CVE-2025-14847 (MongoBleed) is a critical MongoDB vulnerability enabling unauthenticated memory disclosure. Learn impact, affected versions, and detection steps.
www.abstract.security
December 28, 2025 at 11:27 PM
Obligatory blog post describing the detection methodology I used.

blog.ecapuano.com/p/hunting-mo...
Hunting MongoBleed (CVE-2025-14847)
Detecting CVE-2025-14847 Exploitation with Velociraptor
blog.ecapuano.com
December 27, 2025 at 3:42 AM
Ubisoft was a victim of MongoBleed.

An unknown Threat Actor(s) have exfiltrated the source code to basically every single Ubisoft product dating back to the 90's. This includes their Software Development Kits, Middleware, uPlay, RDV, etc.

No customer data was stolen
December 27, 2025 at 7:04 PM
Gucci Mane had his music leaked because of the Mongobleed vulnerability
December 28, 2025 at 5:43 PM
12 hours of working on MongoBleed, yippee

More MongoBleed work tomorrow 🍄🥹👍
January 8, 2026 at 3:35 AM
mongobleed *takes a long drag from a cig*
December 29, 2025 at 8:15 PM
New Podcast Episode:
Security Now: MongoBleed
Code Signing Under Siege
with Steve Gibson, @leolaporte.me
Security Now: MongoBleed | TWiT.TV
Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the “cabal” rewriting the rules for everyone who
twit.tv
January 7, 2026 at 5:05 AM
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.
www.bleepingcomputer.com
December 28, 2025 at 8:38 PM
New year, new this.weekinsecurity.com newsletter, with all the cyber news you need to know. Includes: MongoBleed under global exploitation; Condé Nast data breach; Kimwolf's growing botnet; U.S. lifts sanctions on spyware executives, EU hackers call for digital independence from U.S. tech, and more.
this week in security — january 4 2026 edition
MongoBleed bug exploited globally, U.S. lifts sanctions on spyware executives, calls for digital independence from Silicon Valley, Kimwolf's huge botnet, and more.
this.weekinsecurity.com
January 4, 2026 at 4:36 PM
I hate that all of my energy is going into resolving this security vulnerability (MongoBleed), rather than being able to sit & process my emotions 😢🍄
January 9, 2026 at 12:10 AM
Meus sentimentos pra quem vai passar esses dias de recesso atualizando versão do mongodb #hugops

www.tenable.com/blog/cve-202...
MongoBleed CVE-2025-14847 exploited in the wild
MongoBleed CVE-2025-14847 exploited in the wild
www.tenable.com
December 29, 2025 at 8:42 PM
CISA ordered U.S. federal agencies to patch an actively exploited MongoDB vulnerability (MongoBleed) that can be exploited to steal credentials, API keys, and other sensitive data.
CISA orders feds to patch MongoBleed flaw exploited in attacks
CISA ordered U.S. federal agencies to patch an actively exploited MongoDB vulnerability (MongoBleed) that can be exploited to steal credentials, API keys, and other sensitive data.
www.bleepingcomputer.com
December 30, 2025 at 2:40 PM
IT-Sicherheitsforscher haben die Verbreitung von für MongoBleed anfällige Instanzen untersucht. In Deutschland stehen über 11.500. #Security
MongoBleed: Mehr als 11.500 verwundbare MongoDB-Instanzen in Deutschland
IT-Sicherheitsforscher haben die Verbreitung von für MongoBleed anfällige Instanzen untersucht. In Deutschland stehen über 11.500.
www.heise.de
December 31, 2025 at 12:51 PM
I have PR'd a new @velocidex.com Artifact to the Exchange to hunt for exploitation of #CVE-2025–14847.

As far as I know, this is the only defensive signature for this CVE that exists currently.

github.com/Velocidex/ve...
Create Linux.Detection.CVE202514847.MongoBleed.yaml by ecapuano · Pull Request #1161 · Velocidex/velociraptor-docs
Add Linux.Detection.CVE202514847.MongoBleed Artifact Summary This artifact detects evidence of CVE-2025-14847 (MongoBleed) exploitation on MongoDB servers by analyzing connection patterns in MongoD...
github.com
December 27, 2025 at 1:52 AM
MongoBleed update: We added MongoDB CVE-2025-14847 tagging today that is version based. This results in 74,854 possibly unpatched versions (out of 78,725 exposed today). IP data on vulnerable instances shared in our Open MongoDB Report: www.shadowserver.org/what-we-do/n...
December 29, 2025 at 7:36 PM
Security decisions upstream can affect everyone downstream.

Security Now explains new code signing limits, Python package security improvements, and what MongoBleed exposed.
Listen here:
Security Now: MongoBleed | TWiT.TV
Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the “cabal” rewriting the rules for everyone who
buff.ly
January 8, 2026 at 8:03 PM
MongoBleed (CVE-2025-14847) Information Leak Vulnerability Exploited in the Wild by Peled Eldan & Erez Hasson XM Cyber. Vulnerability is currently being exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities Catalog on December 29, 2025. cybersec.xmcyber.com/s/mongobleed...
January 29, 2026 at 3:15 PM
When I read the details of the Mongobleed exploit, I gasped. It's so stunning in its naivete.

What do you mean: "Instead, it trusts the user’s input and uses that as the canonical size of the payload, even if it got a different number."?

bigdata.2minutestreaming.com/p/mongobleed...
MongoBleed explained simply
CVE-2025-14847 allows attackers to read any arbitrary data from the database's heap memory. It affects all MongoDB versions since 2017, here's a simple explanation:
bigdata.2minutestreaming.com
January 2, 2026 at 4:39 AM