logo

Sysdig Security Briefing: September 2025

ID: 1648e145-1213-57fb-9202-b858f83e5bfc

STIX ID: report--1648e145-1213-57fb-9202-b858f83e5bfc

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2025-10-06

Date Updated: 2026-05-01

...
...

September’s Sysdig Threat Research Team bulletin details a series of high-impact supply-chain and malware incidents: mass compromises of NPM packages (including chalk, debug, and a wormed campaign that exposed secrets and affected ~200 packages), a credential‑stealing package (Fezbox), the discovery of ZynorRAT (a Go-based RAT targeting Linux/Windows), and multiple active exploits and CVEs (DDR5 rowhammer-style exploit, Android/Chrome zero-days, Cisco vulnerabilities) that together underscore urgent need for dependency audits, runtime/CI monitoring, and rapid detection/mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.