惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
罗磊的独立博客
T
Tailwind CSS Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
V
V2EX
美团技术团队
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
量子位
MyScale Blog
MyScale Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
B
Blog

Sysdig Blog

Masterclass: AI is more than ChatGPT and LLMs CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace Kubernetes 1.36 - New security features 5 steps to securing AI workloads Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours Security briefing: March 2026 The Sysdig MCP server is now available in AWS Marketplace Risk isn’t reduced until you take action: How teams resolve issues in the cloud AI infrastructure security: Why it deserves its own category Three pillars for building effective runtime-powered cloud defense, the right way Closing the cloud security gap with runtime security Seeing risk isn’t stopping it: Why visibility alone isn’t enough TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions AI coding agents are running on your machines — Do you know what they're doing? Runtime security for AI coding agents: Protecting AI-assisted development How runtime insights power every cloud security use case CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours Inline Cloud Response: Accelerating AWS threat containment for SOC teams Runtime malware detection for AWS Fargate Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes Malware detection with Sysdig Security briefing: February 2026 Leveling up Kubernetes Posture: From baselines to risk-aware admission Eliminating runtime blind spots: How CleanStart and Sysdig build continuous trust across the container lifecycle LLMjacking: From Emerging Threat to Black Market Reality Real risks live at runtime: Why CISOs must care about deep telemetry in 2026 Sysdig named a Leader in the Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 How to run rootless containers AI-assisted cloud intrusion achieves admin access in 8 minutes Security briefing: January 2026
Sysdig Security Briefing: September 2025
2025-10-06 · via Sysdig Blog

Sysdig Security Briefing: September 2025

Published:

October 6, 2025

Table of contents

falco feeds by sysdig

Falco Feeds extends the power of Falco by giving open source-focused companies access to expert-written rules that are continuously updated as new threats are discovered.

learn more

Green background with a circular icon on the left and three bullet points listing: Automatically detect threats, Eliminate rule maintenance, Stay compliant, with three black and white cursor arrows pointing at the text.

Security gone viral

Last month, the NPM ecosystem was ablaze with hundreds of NPM packages compromised. After the first half of the month, every security researcher seemed to be hunting for issues in the NPM ecosystem, trying to find the next viral story.

Sept. 8–9: NPM chalk, debug, and duck packages compromised

  • More than 20 NPM packages, with a combined two billion weekly downloads, contained malicious code.
  • The most popular packages included chalk, debug, and duck.
  • The root cause was a successful spear phishing attack against a maintainer.
  • The attacker’s motive was financial: finding and redirecting crypto payments.
  • NPM quickly removed the compromised package versions, but users had to update their packages or revert to old, secure versions.
  • Sysdig’s response: Customers had same-day access to vulnerable package identification on the Threat Intelligence dashboard and received a threat bulletin on September 12.

Sept. 15: The Shai-Hulud worm

  • Approximately 200 packages were compromised, including @ctrl/tinycolor.
  • The attack was believed to be by an attacker who had compromised Nx packages in late August.
  • This time, the attacker used an advanced worm to steal secrets from compromised packages, published them publicly on GitHub, and attempted to make victim repositories public.
  • Sysdig’s response: Customers were able to review any impact on the same day via the Threat Intelligence dashboard, received a threat bulletin on Sept. 16, and Sysdig TRT published a blog that included an open source Falco rule.

Sept. 22: Fezbox

  • A malicious package was reported by the Socket Threat Research Team.
  • It’s designed to steal usernames and passwords from browser web cookies.
  • It also embeds malicious code into a QR code.
  • Don’t assume popular = safe. Even the most trusted packages can be compromised.
  • What you can do: Scan your environment for the package dist.fezbox.cjs, contain and remove it if found, and review and monitor logs for credential exfiltration attempts.

Security lesson for the month

Supply chains are always a prime target for attackers. Audit your dependencies, reduce bloat (the things you don’t need), and always be monitoring for and alerting on unusual behavior in builds, CI/CD, or runtime environments.

Sysdig Threat Research Team novel findings

Sept. 9: ZynorRAT

  • An advanced malware was discovered and analyzed by the team while it was still in the development phase.
  • Written in Go, of Turkish origin, it provides a custom suite of C2 capabilities to target Linux and Windows environments.
  • The malware developer was actively working to improve detection evasion and seemed to be focused on the Linux version, with the Windows version of ZynorRAT still needing customization.
  • Sysdig’s response: Technical blog published with IOCs and multiple detection methods.

Also in the news

  • New rowhammer-style attacks on DDR5 memory chips: The new Phoenix exploit (CVE-2025-6202) is able to flip bits, steal SSH keys, and escalate privileges.
  • Google zero-days actively exploited: Google quickly patched two Android zero-days and a Chrome V8 zero-day that were being exploited in the wild.
  • Cisco patches 14 vulnerabilities: Some of these vulnerabilities were being actively exploited, which triggered an emergency directive from CISA. CVE-2025-20352 was said to have impacted up to two million devices.
  • Operational disruptions: A cyberattack on Collins Aerospace disrupted check-in systems at major European airports. Jaguar Land Rover was forced to shut down production in the UK for the whole month of September following an attack on Aug. 31.

Closing thoughts

From the NPM compromises and ZynorRAT to new and active exploits, September reinforced one thing: The threat landscape never stops evolving, nor should we. As we head into October, Cybersecurity Awareness Month, remain focused on detections, intelligence, and tools that work in real time.

Don’t wait for next month’s wrap up! Get the latest news from the Sysdig Threat Research Team.

Register for our webinar on Shai-Hulud here.

Cloud Security

Threat Research

featured resources

Test drive the right way to defend the cloud
with a security expert