Sysdig Security Briefing: September 2025
ID: 182ba64f-6a45-55c2-9447-8c8dfa71c658
STIX ID: report--182ba64f-6a45-55c2-9447-8c8dfa71c658
Feed Name: Sysdig Blog
In September, the Sysdig Threat Research Team reported widespread NPM supply-chain compromises—dozens to hundreds of packages (including popular packages like chalk, debug, duck, and @ctrl/tinycolor) were backdoored via maintainer compromise and a self-replicating worm (Shai‑Hulud) that exfiltrated secrets; a separate malicious package (Fezbox) stole browser cookies and embedded QR-code payloads. The team also published analysis of ZynorRAT (a Turkish Go-based RAT), and summarized active, high-impact exploits and vulnerabilities (Phoenix rowhammer CVE-2025-6202, Android/Chrome zero-days, Cisco CVEs), providing IOCs, detection guidance, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
