logo

Sysdig Security Briefing: September 2025

ID: 182ba64f-6a45-55c2-9447-8c8dfa71c658

STIX ID: report--182ba64f-6a45-55c2-9447-8c8dfa71c658

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2025-10-06

Date Updated: 2026-05-01

...
...

In September, the Sysdig Threat Research Team reported widespread NPM supply-chain compromises—dozens to hundreds of packages (including popular packages like chalk, debug, duck, and @ctrl/tinycolor) were backdoored via maintainer compromise and a self-replicating worm (Shai‑Hulud) that exfiltrated secrets; a separate malicious package (Fezbox) stole browser cookies and embedded QR-code payloads. The team also published analysis of ZynorRAT (a Turkish Go-based RAT), and summarized active, high-impact exploits and vulnerabilities (Phoenix rowhammer CVE-2025-6202, Android/Chrome zero-days, Cisco CVEs), providing IOCs, detection guidance, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.