Mystery OAST With Exploit for 200 CVEs Leveraging Google Cloud to Launch Attacks
ID: bbea8dd9-53be-5bdd-bcfd-01263688a171
STIX ID: report--bbea8dd9-53be-5bdd-bcfd-01263688a171
Feed Name: cybersecurityNews.com
Threat Score
Security researchers identified a sustained, focused exploit-verification campaign using a private OAST service (detectors-testing.com) hosted on Google Cloud; between October and November 2025 roughly 1,400 exploit attempts across 200+ CVEs were observed targeting systems in Brazil, employing modified public exploit code (e.g., a changed TouchFile.class), a mixture of old and new Nuclei templates, and callback verification to an Interactsh-style host at 34.136.22.26.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
