home.social

#mongobleed — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mongobleed, aggregated by home.social.

fetched live
  1. One more side project? :blobcat:
    🥭 🩸 🍯

    #mongobleed #CVE-2025-14847

  2. 🫤 We know the *last* thing you want to deal with on Dec 31st is a new vulnerability. But #MongoBleed (CVE-2025-14847) isn't waiting for the ball to drop.

    Our team already updated the Pentest-Tools.com Network Scanner to detect this information disclosure flaw that's currently letting unauthenticated attackers leak MongoDB server info.

    Whether you’re on-call or just checking in, we’ve made it fast to see if your servers are at risk. 🎯 Scan your IPs for CVE-2025-14847, patch it fast, and have a safe New Year.

    Deets and detection here: 👉 pentest-tools.com/vulnerabilit

  3. MongoDB have a blog out about #MongoBleed

    Notably:

    - Internal find at MongoDB

    - they notified customers of the issue and patch availability on December 23rd

    - A security vendor published technical details on December 24th, Christmas Eve

    - Somebody at Elastic, a direct competitor, published an exploit with full secret extraction feature on December 25th, Christmas Day

    That was an impossible situation for orgs - the security industry poured fire on them and set their own customers on fire.

  4. Une faille de sécurité importante concerne presque toutes les versions de MongoDB. Tous les serveurs que nous infogérons ont été patchés (même si évidemment le port MongoDB était restreint). #MongoBleed
    Plus de détails sur next.ink/216574/mongobleed-une

  5. Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed

    From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts

    censys.com/advisory/cve-2025-1

  6. MongoBleed – krytyczna podatność umożliwiająca zdalne czytanie pamięci z serwera (hasła, klucze API, klucze prywatne, inne sekrety). CVE-2025-14847

    Do wykorzystania podatności wystarczy udostępnienie usług MongoDB do Internetu (luka nie wymaga uwierzytelnienia). Atakujący wysyła skompresowane/złośliwe wiadomości – a przy dekompresji następuje czytanie fragmentów pamięci z serwera i wysłanie ich w odpowiedzi. Opublikowany został exploit / trwają próby masowego wykorzystania podatności. Dostępne są łatki od linii 4.x aż do najnowszej...

    #WBiegu #Mongobleed #Mongodb #Podatność #Wyciek

    sekurak.pl/mongobleed-krytyczn

  7. „MongoBleed“: Exploit für kritische Lücke in MongoDB erleichtert Angriffe

    Wer für eine MongoDB-Instanz verantwortlich ist, kann sich nicht zurücklehnen: Ein Exploit für eine schwerwiegende Lücke macht Upgrades jetzt noch dringender.

    heise.de/news/MongoBleed-Explo

    #Datenbanken #Exploit #IT #MongoBleed #MongoDB #Sicherheitslücken

  8. 🚀✨ Behold, the latest "MongoBleed" saga, where #developers gather for another #GitHub jamboree, because nothing spells #security like hopping on the #AI bandwagon to patch gaping holes! 🤖🔧 Let's all pretend that a #Python script will magically fix everything while sipping our artisanal lattes. ☕️💻
    github.com/joe-desimone/mongob #MongoBleed #HackerNews #ngated