Unpatched Argo CD RCE, ChocoPoC researcher targeting, Scattered Spider extraditions
ID: 4add887a-6bfb-5217-9069-3cf5a828ada9
STIX ID: report--4add887a-6bfb-5217-9069-3cf5a828ada9
Feed Name: defend.network
TL;DR: A high-severity briefing reports an unpatched Argo CD repo-server RCE that could enable unauthenticated Kubernetes cluster takeover, trojanized GitHub proof-of-concept exploits distributing the ChocoPoC RAT targeting researchers, a breach of DHS’s HSIN intelligence-sharing platform, month-long unauthorized access at Kubota, and legal action against members of the Scattered Spider group — advising urgent discovery, access restriction, patch monitoring, GitHub and endpoint audits, and incident log review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
