Next.js middleware authorisation bypass via crafted header — weaponised by PCPJack worm
cve · CVE-2025-29927
Coverage timeline
3
first 2026-05-10 → last 2026-05-10
Briefs
3
3 distinct
Sources cited
18
10 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-19CTI Daily Brief — 2026-05-19
- 2026-05-10CTI Daily Brief — 2026-05-10
- 2026-W19CTI Weekly Summary — 2026-W19 (May 04 – May 10, 2026)
Source distribution
- nvd.nist.gov5 (28%)
- thehackernews.com3 (17%)
- attack.mitre.org2 (11%)
- securityweek.com2 (11%)
- checkmarx.com1 (6%)
- isc.sans.edu1 (6%)
- ox.security1 (6%)
- securitylabs.datadoghq.com1 (6%)
- other2 (11%)
External references
All cited sources (18)
- sentinelone.comprimaryinlineSentinelLabshttps://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/
- attack.mitre.orginlineT1195.002 Compromise Software Supply Chainhttps://attack.mitre.org/techniques/T1195/002/
- attack.mitre.orginlineT1552.001 Credentials In Fileshttps://attack.mitre.org/techniques/T1552/001/
- checkmarx.cominlineCheckmarx, 2026-05-12https://checkmarx.com/blog/ongoing-security-updates/
- isc.sans.eduinlineSANS Internet Storm Center, 2026-05-18https://isc.sans.edu/diary/rss/32994
- nvd.nist.govinlineCVE-2025-29927https://nvd.nist.gov/vuln/detail/CVE-2025-29927
- nvd.nist.govinlineCVE-2025-48703https://nvd.nist.gov/vuln/detail/CVE-2025-48703
- nvd.nist.govinlineCVE-2025-55182https://nvd.nist.gov/vuln/detail/CVE-2025-55182
- nvd.nist.govinlineCVE-2025-9501https://nvd.nist.gov/vuln/detail/CVE-2025-9501
- nvd.nist.govinlineCVE-2026-1357https://nvd.nist.gov/vuln/detail/CVE-2026-1357
- ox.securityinlineOx Securityhttps://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/
- securitylabs.datadoghq.cominlineDatadog Security Labs static analysis, 2026-05-13https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/
- securityweek.cominlineSecurityWeek, 2026-05-11https://www.securityweek.com/checkmarx-jenkins-ast-plugin-compromised-in-supply-chain-attack/
- securityweek.cominlineSecurityWeek, 2026-05-08https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/four-malicious-npm-packages-deliver.html
- thehackernews.cominlineThe Hacker News, 2026-05-07https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
- thehackernews.cominlineThe Hacker News, 2026-05-11https://thehackernews.com/2026/05/teampcp-compromises-checkmarx-jenkins.html
- wiz.ioinlineWiz Blog, 2026-05-11https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
Items in briefs about Next.js middleware authorisation bypass via crafted header — weaponised by PCPJack worm
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.