North Korea npm attacks, Azure Cosmos DB flaw patched, TeamCity RCE
ID: 79ecd319-d983-54f6-ad6e-be343136fa7e
STIX ID: report--79ecd319-d983-54f6-ad6e-be343136fa7e
Feed Name: defend.network
Executive summary: A high-priority briefing reports active nation-state–linked npm supply-chain compromises attributed to North Korean actors (Debug and Chalk), a patched but serious Azure Cosmos DB cross-tenant key exposure (CosmosEscape), a Microsoft Copilot for Word prompt-injection weakness that can persist hidden instructions, a JetBrains TeamCity authentication bypass enabling RCE, and a Cisco FMC hard-coded credential CVE listed in CISA KEV; urgent actions include auditing npm dependencies, verifying and patching affected cloud and on-prem systems, disabling Copilot for Word pending fixes, and reviewing relevant logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
