Wiz Research Blog
wiz-blog · B · active
Cloud security research; strong on cloud-native CVEs, container escapes, and misconfiguration. Promoted from candidate → active 2026-05-08 after 2026-05-08 audit returned 5 dated 2026-05-06/08 items including Dirty Frag and Akamai integration. (v2.55: rss_url verified — use `python3 tools/fetch_source.py feed https://www.wiz.io/api/feed/cloud-threat-landscape/rss.xml [N]`) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.wiz.io/blog (listing) then webfetch per-article wiz.io/blog/<slug> URL; RSS at https://www.wiz.io/api/feed/cloud-threat-landscape/rss.xml (cloud-threat-landscape slice only). AVOID: Listing renders the article hero IMAGE url first and the real link as a relative /blog/<slug> path — resolve it against www.wiz.io. The documented RSS only covers the cloud-threat-landscape slice, not all blog posts.. | 2026-07-05 admiralty audit: B — original cloud-security research from Wiz Research, but the blog feed mixes in marketing and policy re-reporting; resolve slugs against www.wiz.io. No status change.
Cited in 21 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 15).
- Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter2026-07-19
- AsyncAPI npm packages backdoored via a GitHub Actions pull_request_target token theft, delivering a multi-stage IPFS implant (M-RED-TEAM)2026-07-14
- GhostApproval (CVE-2026-12958, CVE-2026-50549) — symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants' workspace sandbox2026-07-09
- Gogs CVE-2026-52806 moves from "no observed exploitation" to active cryptojacking campaign2026-06-29
- CVE-2026-12957 — Amazon Q Developer auto-loaded workspace MCP configs, enabling repo-planted code execution and AWS credential theft (Wiz)2026-06-27
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative2026-06-09
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse2026-06-02
- Wiz CIRT names JINX-0164 — LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD2026-05-29
- Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit2026-05-25
- TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause2026-05-21
- CVE-2026-46300 — Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- Mini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)2026-05-13
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain2026-05-13
- TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence2026-05-11
- TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak2026-05-11
- Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirmed ITW, RxRPC distro patches still propagating2026-05-11
- CVE-2026-46300 — Linux kernel xfrm ESP-in-TCP LPE ("Fragnesia"), PoC public2026-05-11
- CVE-2026-43284 / CVE-2026-43500 — Linux "Dirty Frag": deterministic LPE chain via page-cache write primitives in xfrm-ESP and RxRPC, active exploitation confirmed2026-05-09
- CVE-2025-68670 — xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09
- Looking ahead — 2026-W192026-05-04
- CVE-2026-31431 "Copy Fail" + CVE-2026-43284 / CVE-2026-43500 "Dirty Frag" — Linux kernel LPE pair confirmed in complementary post-compromise campaigns2026-05-04