#MongoBleed
Weaponized GitHub PoC repos are delivering ChocoPoC, a Python RAT hidden in PyPI deps like frint and skytext, targeting researchers and testers via compromised accounts and abused datasets. #ChocoPoC #GitHub #PyPI
New ChocoPoC malware targets researchers via trojanized PoC exploits
Sekoia uncovered weaponized GitHub proof-of-concept repositories that deliver the ChocoPoC Python RAT by hiding malicious behavior inside PyPI dependencies like frint and skytext. The campaign appears aimed at cybersecurity researchers and testers, and it abuses compromised accounts, multiple vulnerable products, and even Mapbox datasets to deploy and exfiltrate data. #ChocoPoC #Sekoia #GitHub #PyPI #frint #skytext #Mapbox #FortiWeb #React2Shell #MongoBleed #PANOS #IvantiSentry #CheckPointVPN #JoomlaSPPageBuilder
www.hendryadrian.com
July 2, 2026 at 12:15 AM
The Hacker News lists top attack-surface exposures for 2026; internet-facing services are at risk. Defenders: audit and restrict admin panels and brute-force entry points. #Cybersecurity #ZeroDay #DataBreach

Source: https://thehackernews.com/2026/06/the-top-10-attack-surface-exposures-in.html
The Top 10 Attack Surface Exposures in 2026
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk. With time-to-exploit now down to a
thehackernews.com
June 18, 2026 at 4:00 AM
The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull cre…
#hackernews #news
The Top 10 Attack Surface Exposures in 2026
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk. With time-to-exploit now down to a
thehackernews.com
June 18, 2026 at 2:47 AM
MongoBleedという脆弱性により、認証なしでサーバーメモリから認証情報やセッションを抜き取ることが可能。インターネットに公開されたものがリスクにさらされる。
The Top 10 Attack Surface Exposures in 2026
Intruder analyzed 3,000 attack surfaces and found 60% exposed HTTP panels, 49% risky ports, and 42% internet-facing databases.
thehackernews.com
June 17, 2026 at 12:47 PM
Data governance is not surging because executives finally cared.

It is surging because PostgreSQL dropped MD5 auth, MongoBleed is leaking server memory, and SQL Server exposed system tables across three clouds.

The boring database work is now load-bearing.
May 20, 2026 at 10:00 AM
Everything you need to know about MongoBleed (CVE-2025-14847) Learn what MongoBleed (CVE-2025-14847) is, how the vulnerability leaks MongoDB server memory, which versions are affected, and how to p...

#Databases #Featured #MongoDB #Security #and #Compliance #Database

Origin | Interest | Match
April 8, 2026 at 2:53 PM
Mongobleed - CVE-2025-14847
Mongobleed - CVE-2025-14847
doublepulsar.com
April 5, 2026 at 7:10 AM
🟢 New MongoDB Zero‑Day Vulnerability Actively Exploited in Attacks

🗨️ The RCE vulnerability CVE-2025-14847 fixed last week, also dubbed MongoBleed, is already being exploited by hackers. Sec…

#news
New MongoDB Zero‑Day Vulnerability Actively Exploited in Attacks
Read more
hackmag.com
March 30, 2026 at 3:00 PM
Hackers Getting Hacked: The ‘Mongobleed’ Supply Chain Poison That Turns Red Teams into Targets + Video

Introduction: In the ever-escalating arms race of cybersecurity, offensive security professionals and threat actors frequently rely on shared tools to streamline post-exploitation activities. A…
Hackers Getting Hacked: The ‘Mongobleed’ Supply Chain Poison That Turns Red Teams into Targets + Video
Introduction: In the ever-escalating arms race of cybersecurity, offensive security professionals and threat actors frequently rely on shared tools to streamline post-exploitation activities. A recent incident highlights a sophisticated twist in supply chain attacks, where a modified version of a database post-exploitation tool was weaponized against its users. When attackers deployed a poisoned module named ‘mongobleed’ that imported a malicious logging library called ‘slogsec’, they inadvertently executed a backdoor on their own infrastructure, turning the hunters into the hunted.
undercodetesting.com
March 28, 2026 at 9:40 AM
Notícia da SecurityWeek

"Fresh MongoDB Vulnerability Exploited in Attacks" #bolhasec
Fresh MongoDB Vulnerability Exploited in Attacks
Hackers are exploiting CVE-2025-14847, aka MongoBleed, a MongoDB vulnerability, to leak sensitive information from server memory.
www.securityweek.com
March 8, 2026 at 12:30 AM
Notícia da BleepingComputer

"Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed" #bolhasec
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the ...
www.bleepingcomputer.com
March 6, 2026 at 11:30 PM
Notícia da BleepingComputer

"CISA orders feds to patch MongoBleed flaw exploited in attacks" #bolhasec
CISA orders feds to patch MongoBleed flaw exploited in attacks
CISA ordered U.S. federal agencies to patch an actively exploited MongoDB vulnerability (MongoBleed) that can be exploited to steal credentials, API keys, and other sensitive data.
www.bleepingcomputer.com
February 27, 2026 at 7:30 PM
Mongobleed sounds like a bad sci-fi villain but it's actually a MongoDB security flaw CVE-2025-14847. Percona to the rescue patching it with urgency and transparency. Let's keep our databases from joining the dark side!
Urgent Security Update: Patching “Mongobleed” (CVE-2025-14847) in Percona Server for MongoDB
Urgent Security Update: Patching “Mongobleed” (CVE-2025-14847) in Percona Server for MongoDB
www.percona.com
February 7, 2026 at 11:11 AM
My new MongoDB honeypot usually gets mostly scans and an occasional attempt to exploit MongoBleed. However, the last night someone actually tried password-spraying it. Sadly, the protocol doesn't let me capture the passwords used - only the user names.
February 3, 2026 at 7:27 AM
MongoBleed (CVE-2025-14847) Information Leak Vulnerability Exploited in the Wild by Peled Eldan & Erez Hasson XM Cyber. Vulnerability is currently being exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities Catalog on December 29, 2025. cybersec.xmcyber.com/s/mongobleed...
January 29, 2026 at 3:15 PM
MongoBleed's leaking more than just secrets - it's causing headaches everywhere. From MongoDB Community to Atlas and Percona Server for MongoDB no one is safe. Time to patch or pray!
CVE-2025-14847 (MongoBleed) — A High-Severity Memory Leak in MongoDB
CVE-2025-14847 (MongoBleed) — A High-Severity Memory Leak in MongoDB
www.percona.com
January 27, 2026 at 11:12 AM
My MongoBleed Hell is almost over after a month-ish of work. Should be complete by end of the week.

Then I need to finish sorting out the mold problem in my basement. Kinda just through a HEPA filter in the room & stayed out of the room for the past week, but I would like to stream again soon ;-;
January 27, 2026 at 5:18 AM
📣 Säkerhetspodcasten #296 - Ostrukturerat V.5 📣 AWS regexp fail, Sjölogistik hade alla säkerhetshål, MongoBleed, Pre-boot attack mot UEFI, och Powershell XSS!
50:42 AWS hackat via regexp bug AWS CodeBuild kasst regexp lämnade viktiga repon vidöppna för konton med snarlika ID!
Länkar:
wiz.io/...
Säkerhetspodcasten #296 - Ostrukturerat V.5
AWS regexp fail, Sjölogistik hade alla säkerhetshål, MongoBleed, Pre-boot attack mot UEFI, och Powershell XSS! 50:42 AWS hackat via regexp bug AWS CodeBuild kasst regexp lämnade viktiga repon vidöppna för konton med snarlika ID! Länkar: wiz.io/ Yuval Avrahami, Nir Ohfeld: CodeBreach - Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog - Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
sakerhetspodcasten.se
January 26, 2026 at 2:45 PM
🚨 87,000 databases exposed. Could yours be next?

CyberHoot breaks down the MongoBleed vulnerability and how to lock down your MongoDB before attackers strike. 🔒

Read more 👉 cyberhoot.com/blog/mongobl...

#CyberHoot
MongoBleed: Why 87,000 Databases Had Their Front Doors Wide Open (And How to Close Yours) - CyberHoot
MongoBleed exposed 87,000 internet-facing MongoDB databases. Learn who’s at risk, how to patch immediately, and how to secure your data.
cyberhoot.com
January 22, 2026 at 4:00 PM
Notícia da BleepingComputer

"Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed" #bolhasec
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the ...
www.bleepingcomputer.com
January 21, 2026 at 10:30 PM
MongoBleed Unleashed: The Critical Memory Leak Exploiting Thousands of Databases + Video

Introduction: A severe vulnerability, dubbed "MongoBleed" (CVE-2025-14847), is actively being exploited in the wild, threatening MongoDB instances globally. This critical flaw allows unauthenticated remote…
MongoBleed Unleashed: The Critical Memory Leak Exploiting Thousands of Databases + Video
Introduction: A severe vulnerability, dubbed "MongoBleed" (CVE-2025-14847), is actively being exploited in the wild, threatening MongoDB instances globally. This critical flaw allows unauthenticated remote attackers to read uninitialized server memory, potentially leaking database credentials, API keys, session tokens, and sensitive personal data. With a high CVSS score of 8.7 and over 87,000 instances exposed on the internet, immediate action is required to secure affected database servers.
undercodetesting.com
January 18, 2026 at 5:32 PM
this is a certified classic

Probably revived after mongobleed lol
January 17, 2026 at 11:43 AM