#mongobleed — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mongobleed, aggregated by home.social.
-
#MongoBleed and #Shodan is a dangerous combination. #security
-
One more side project? :blobcat:
🥭 🩸 🍯#mongobleed #CVE-2025-14847
-
Weltweit ca. 90k verwundbare #MongoDB-Instanzen
#MongoBleed: Mehr als 11.500 verwundbare MongoDB-Instanzen in Deutschland | Security https://www.heise.de/news/MongoBleed-Mehr-als-11-500-verwundbare-MongoDB-Instanzen-in-Deutschland-11126702.html #Patchday #exploit #zlib #NoSQL
-
„#MongoBleed“: #Exploit für kritische Lücke in #MongoDB erleichtert Angriffe | heise online https://www.heise.de/news/MongoBleed-Exploit-fuer-kritische-Luecke-in-MongoDB-erleichtert-Angriffe-11125112.html #Patchday #zlib #NoSQL
-
🫤 We know the *last* thing you want to deal with on Dec 31st is a new vulnerability. But #MongoBleed (CVE-2025-14847) isn't waiting for the ball to drop.
Our team already updated the Pentest-Tools.com Network Scanner to detect this information disclosure flaw that's currently letting unauthenticated attackers leak MongoDB server info.
Whether you’re on-call or just checking in, we’ve made it fast to see if your servers are at risk. 🎯 Scan your IPs for CVE-2025-14847, patch it fast, and have a safe New Year.
Deets and detection here: 👉 https://pentest-tools.com/vulnerabilities-exploits/mongodb-server-information-disclosure-mongobleed_28455
-
MongoDB have a blog out about #MongoBleed
Notably:
- Internal find at MongoDB
- they notified customers of the issue and patch availability on December 23rd
- A security vendor published technical details on December 24th, Christmas Eve
- Somebody at Elastic, a direct competitor, published an exploit with full secret extraction feature on December 25th, Christmas Day
That was an impossible situation for orgs - the security industry poured fire on them and set their own customers on fire.
-
Une faille de sécurité importante concerne presque toutes les versions de MongoDB. Tous les serveurs que nous infogérons ont été patchés (même si évidemment le port MongoDB était restreint). #MongoBleed
Plus de détails sur https://next.ink/216574/mongobleed-une-tres-vilaine-faille-mongodb-laisse-fuiter-des-donnees-sensibles/ -
Ubisoft shuts down Rainbow Six Siege after the new #MongoBleed exploit hit players, causing account disruption and forcing rollback of in‑game transactions.
Read: https://hackread.com/mongodb-exploit-ubisoft-rainbow-six-siege-players/
#Cybersecurity #Vulnerability #Gaming #RainbowSixSiege #Ubisoft
-
Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed
From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts
-
MongoBLEED - La faille critique qui fait fuir la mémoire de votre MongoDB
https://fed.brid.gy/r/https://korben.info/mongobleed-faille-mongodb-memoire.html
-
Rainbow Six Siege hacké - 2 milliards de crédits distribués à tous les joueurs
https://fed.brid.gy/r/https://korben.info/rainbow-six-siege-hack-credits-ubisoft-mongodb.html
-
MongoBleed – krytyczna podatność umożliwiająca zdalne czytanie pamięci z serwera (hasła, klucze API, klucze prywatne, inne sekrety). CVE-2025-14847
Do wykorzystania podatności wystarczy udostępnienie usług MongoDB do Internetu (luka nie wymaga uwierzytelnienia). Atakujący wysyła skompresowane/złośliwe wiadomości – a przy dekompresji następuje czytanie fragmentów pamięci z serwera i wysłanie ich w odpowiedzi. Opublikowany został exploit / trwają próby masowego wykorzystania podatności. Dostępne są łatki od linii 4.x aż do najnowszej...
-
„MongoBleed“: Exploit für kritische Lücke in MongoDB erleichtert Angriffe
Wer für eine MongoDB-Instanz verantwortlich ist, kann sich nicht zurücklehnen: Ein Exploit für eine schwerwiegende Lücke macht Upgrades jetzt noch dringender.
#Datenbanken #Exploit #IT #MongoBleed #MongoDB #Sicherheitslücken
-
🚀✨ Behold, the latest "MongoBleed" saga, where #developers gather for another #GitHub jamboree, because nothing spells #security like hopping on the #AI bandwagon to patch gaping holes! 🤖🔧 Let's all pretend that a #Python script will magically fix everything while sipping our artisanal lattes. ☕️💻
https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py #MongoBleed #HackerNews #ngated -