#MongoBleed and #Shodan is a dangerous combination. #security

I added my own #MongoDB stack to #OpenCanary in 41 minutes!!

It seems attackers care less about #MongoBleed and more about deployments facing the Internet and having no authentication.... 🤷‍♂️

https://toce.ch/opencanary-mongodb-honeypot/

#AllUIRDataRBelongUs

🔥 Latest issue of my curated #cybersecurity and #infosec list of resources for week #03/2026 is out!

→ It includes the following and much more:

🔓️ #BreachForums had its user database leaked;

#RedVDS Infrastructure seized by #Microsoft and Law Enforcement;

🇪🇸 🇪🇺 #Europol and Spanish police arrested 34 people linked to the Black Axe;

🇮🇷 🔌 #Iran has cut off internet and phone access nationwide for more than a week

🐧 New modular #Linux malware framework called #VoidLink;

🩸 #MongoBleed, a critical, unauthenticated #MongoDB memory-leak vulnerability;

📆 🩹 Microsoft #PatchTuesday addresses 112 defects, including one actively exploited zero-day;

--

👉 NEVER MISS my curations and updates on information security and cybersecurity news and challenges 📨 Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-03-2026

🕵🏻‍♂️ [InfoSec MASHUP] 03/2026

BreachForums had its user database leaked; RedVDS Infrastructure seized by Microsoft and Law Enforcement; Europol and Spanish police arrested 34 people linked to the Black Axe; New modular Linux malware framework called VoidLink; MongoBleed, a critical, unauthenticated MongoDB memory-leak vulnerability; Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day;

X’s InfoSec Newsletter
Security Now: MongoBleed | TWiT.TV

Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the “cabal” rewriting the rules for everyone who

TWiT.tv
MongoBleed-Scanner für Admins

Viele MongoDB-Instanzen sind oder waren potenziell für MongoBleed anfällig. Ein Tool hilft bei der Server-Analyse auf Angriffsspuren.

heise online

One more side project?  
🥭 🩸 🍯

#mongobleed #CVE-2025-14847

Mongobleed (CVE-2025-14847): Lỗ hổng lộ lọt bộ nhớ thời gian chạy trong MongoDB có thể làm lộ dữ liệu nhạy cảm mà không kích hoạt cảnh báo. Làm thế nào để phát hiện rò rỉ bộ nhớ thời gian chạy trong khi vẫn giữ tiếng ồn ở mức tối thiểu? Xem bài viết trên blog của Armosec.io. #cybersecurity #vulnerability #MongoDB #Mongobleed #CVE202514847 #bảo_mật #lỗ_hổng #phát_hiện_rò_rỉ_bộ_nhớ

https://www.reddit.com/r/SaaS/comments/1q1y7w5/runtime_memory_vulnerabilities_in_mongodb/

Weltweit ca. 90k verwundbare #MongoDB-Instanzen

#MongoBleed: Mehr als 11.500 verwundbare MongoDB-Instanzen in Deutschland | Security https://www.heise.de/news/MongoBleed-Mehr-als-11-500-verwundbare-MongoDB-Instanzen-in-Deutschland-11126702.html #Patchday #exploit #zlib #NoSQL

MongoBleed: Mehr als 11.500 verwundbare MongoDB-Instanzen in Deutschland

IT-Sicherheitsforscher haben die Verbreitung von für MongoBleed anfällige Instanzen untersucht. In Deutschland stehen über 11.500.

heise online
„MongoBleed“: Exploit für kritische Lücke in MongoDB erleichtert Angriffe

Wer für eine MongoDB-Instanz verantwortlich ist, kann sich nicht zurücklehnen: Ein Exploit für eine schwerwiegende Lücke macht Upgrades jetzt noch dringender.

heise online
Hunting MongoBleed (CVE-2025-14847)

Detecting CVE-2025-14847 Exploitation with Velociraptor

Eric’s Substack