Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2025-14847
CVE
CVE-2025-14847
View on NVD ↗
Zlib compressed protocol header length confusion may allow memory read
Exploitation IoCs
2
Domain
morning/v1/{redacted}
Filename
wp2shell
MITRE ATT&CK TTPs
1
T1059.001
PowerShell
Execution
Source Articles
Agentless Visibility: Uncovering Cloud Blind Spots
Wiz's agentless visibility capabilities have uncovered extensive threat activity across cloud environments, including exploitation of zero-day vulnerabilities in FortiGate and PAN-OS devices, credential stuffing campaigns, and supply chain attacks via malicious npm packages. Attackers are leveraging misconfigurations in Redis and MongoDB to achieve remote code execution and data exfiltration. Webshells are being deployed on WordPress instances via the wp2shell vulnerability, enabling persistent access and command execution. These findings highlight the risk posed by unmonitored virtual appliances and exposed services in cloud infrastructures.
wiz