logo

Wiz Cloud Threat Landscape

ID: 4da5a88c-35f6-5acd-8921-2a75ef66a358

STIX ID: identity--4da5a88c-35f6-5acd-8921-2a75ef66a358

Feed Type: rss

Earliest post: 2010-01-12

Latest post: 2026-05-27

A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques. Powered by Wiz Research.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
JINX-0164 Targeting Cryptocurrency Development Infrastructure (Campaign)2026-05-27True[email protected] (Wiz Threat Research)True
Supply Chain Campaign Targeting Composer and GitHub Repositories (Campaign)2026-05-24True[email protected] (Wiz Threat Research)True
Megalodon Campaign Backdoors GitHub Repositories via CI Workflow Compromise (Campaign)2026-05-22True[email protected] (Wiz Threat Research)True
TeamPCP Claims Breach of Internal GitHub Repositories (Incident)2026-05-20True[email protected] (Wiz Threat Research)True
New Mini-Shai-Hulud Wave Targets NPM, PyPi Packages and VSCode Extension (Campaign)2026-05-18True[email protected] (Wiz Threat Research)True
node-ipc npm Distribution Compromised (Campaign)2026-05-14True[email protected] (Wiz Threat Research)True
Tanstack and other Packages Compromised in Supply Chain Attack (Campaign)2026-05-11True[email protected] (Wiz Threat Research)True
DDoS Botnet Leveraging Jenkins Misconfigurations for Initial Access (Campaign)2026-05-10True[email protected] (Wiz Threat Research)True
Compromise of Checkmarx Jenkins AST Plugin by TeamPCP (Campaign)2026-05-09True[email protected] (Wiz Threat Research)True
Lightning and Intercom Packages Compromised in Supply Chain Attack (Campaign)2026-04-30True[email protected] (Wiz Threat Research)True
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (Campaign)2026-04-29True[email protected] (Wiz Threat Research)True
Critical SQL Injection Vulnerability in LiteLLM Exploited in-the-Wild (Campaign)2026-04-27True[email protected] (Wiz Threat Research)True
Elementary Data Compromised in Supply Chain Attack (Campaign)2026-04-23True[email protected] (Wiz Threat Research)True
Checkmarx KICS and Bitwarden CLI Compromised in Fresh Supply Chain Attack (Campaign)2026-04-22True[email protected] (Wiz Threat Research)True
Xinference Compromised in Supply Chain Attack (Campaign)2026-04-22True[email protected] (Wiz Threat Research)True
PolinRider Campaign: DPRK-Linked Supply Chain Attack Infects GitHub Repositories (Campaign)2026-04-09True[email protected] (Wiz Threat Research)True
Stolen SaaS Integration Tokens Enable Data Theft Across Snowflake Environments (Campaign)2026-04-07True[email protected] (Wiz Threat Research)True
UAT-10608 Campaign Abuses React2Shell for Cloud Credential Harvesting (Campaign)2026-04-02True[email protected] (Wiz Threat Research)True
Axios supply chain attack (Incident)2026-03-31True[email protected] (Wiz Threat Research)True
Apifox supply chain attack (Incident)2026-03-26True[email protected] (Wiz Threat Research)True
BuddyBoss supply chain attack (Incident)2026-03-25True[email protected] (Wiz Threat Research)True
LiteLLM supply chain attack (Incident)2026-03-24True[email protected] (Wiz Threat Research)True
Exploitation of S1ngularity-exposed cloud keys for lateral movement (Incident)2026-03-11True[email protected] (Wiz Threat Research)True
xygeni-action repository hijack (Incident)2026-03-09True[email protected] (Wiz Threat Research)True
PolinRider supply chain attack (Incident)2026-03-08True[email protected] (Wiz Threat Research)True
Trivy supply chain attack (Incident)2026-03-01True[email protected] (Wiz Threat Research)True
SANDWORM_MODE: Typosquatted npm Packages Used to Hijack CI Workflows (Campaign)2026-02-20True[email protected] (Wiz Threat Research)True
TeamPCP Cloud-Native Campaign Targeting Exposed Control Planes (Campaign)2026-02-05True[email protected] (Wiz Threat Research)True
Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)2026-02-02True[email protected] (Wiz Threat Research)True
Supply-Chain Attack via Force Pushes on Plone GitHub Repositories (Campaign)2026-01-31True[email protected] (Wiz Threat Research)True
Operation Bizarre Bazaar: Commercialized LLMjacking (Campaign)2026-01-28True[email protected] (Wiz Threat Research)True
Cloud-Native Phishing Infrastructure via Abused AWS WorkMail (Campaign)2026-01-27True[email protected] (Wiz Threat Research)True
GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)2026-01-24True[email protected] (Wiz Threat Research)True
Amadey Loader Abuses Compromised Self-Hosted GitLab to Deliver StealC Infostealer (Campaign)2025-12-18True[email protected] (Wiz Threat Research)True
China-nexus Campaign Exploits CVE-2025-20393 in Cisco Email Security Devices (Campaign)2025-12-17True[email protected] (Wiz Threat Research)True
Shai-Hulud 2.0 Supply Chain Attack (Campaign)2025-11-24True[email protected] (Wiz Threat Research)True
Cryptomining Campaign Exploiting Exposed Ray AI Infrastructure (Campaign)2025-11-19True[email protected] (Wiz Threat Research)True
Cisco ISE Vulnerability Exploited as 0day by APT (Campaign)2025-11-13True[email protected] (Wiz Threat Research)True
Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign)2025-11-12True[email protected] (Wiz Threat Research)True
Gambling Network Exploits Abandoned Subdomains (Campaign)2025-11-11True[email protected] (Wiz Threat Research)True
China-Linked Actors Target U.S. Policy-Oriented Non-Profit Organisations (Campaign)2025-11-05True[email protected] (Wiz Threat Research)True
TruffleNet Campaign Exploits AWS SES for Large-Scale Cloud Abuse and BEC Fraud (Campaign)2025-10-31True[email protected] (Wiz Threat Research)True
PassiveNeuron Campaign: Espionage Campaign Targeting Windows Server Environments (Campaign)2025-10-21True[email protected] (Wiz Threat Research)True
F5 incident (Incident)2025-10-15True[email protected] (Wiz Threat Research)True
eBPF Rootkit Targeting AWS and Linux Environments (Campaign)2025-10-14True[email protected] (Wiz Threat Research)True
Supply Chain Risk in Axis Autodesk Revit Plugin Due to Exposed Azure Storage Credentials and Revit RCE Vulnerabilities (Research)2025-10-08True[email protected] (Wiz Threat Research)True
Cl0p Extortion Campaign Claims Theft via Oracle E-Business Suite (Campaign)2025-10-02True[email protected] (Wiz Threat Research)True
“Crimson Collective” Claims Theft of Customer Data from Red Hat (Campaign)2025-10-02True[email protected] (Wiz Threat Research)True
Renewed "ArcaneDoor" Campaign Targeting 0-day Vulnerabilities in Cisco ASA (Campaign)2025-09-26True[email protected] (Wiz Threat Research)True
SonicWall MySonicWall Cloud Backup File Security Incident (Incident)2025-09-25True[email protected] (Wiz Threat Research)True

1–50 of 369