Sysdig Security Briefing: September 2025
ID: 1648e145-1213-57fb-9202-b858f83e5bfc
STIX ID: report--1648e145-1213-57fb-9202-b858f83e5bfc
Feed Name: Sysdig Blog
September’s Sysdig Threat Research Team bulletin details a series of high-impact supply-chain and malware incidents: mass compromises of NPM packages (including chalk, debug, and a wormed campaign that exposed secrets and affected ~200 packages), a credential‑stealing package (Fezbox), the discovery of ZynorRAT (a Go-based RAT targeting Linux/Windows), and multiple active exploits and CVEs (DDR5 rowhammer-style exploit, Android/Chrome zero-days, Cisco vulnerabilities) that together underscore urgent need for dependency audits, runtime/CI monitoring, and rapid detection/mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
