wiz · Crawled Jul 21, 2026

Agentless Visibility: Uncovering Cloud Blind Spots

2 IoCs 1 CVEs
Read original article ↗

AI Summary

Wiz's agentless visibility capabilities have uncovered extensive threat activity across cloud environments, including exploitation of zero-day vulnerabilities in FortiGate and PAN-OS devices, credential stuffing campaigns, and supply chain attacks via malicious npm packages. Attackers are leveraging misconfigurations in Redis and MongoDB to achieve remote code execution and data exfiltration. Webshells are being deployed on WordPress instances via the wp2shell vulnerability, enabling persistent access and command execution. These findings highlight the risk posed by unmonitored virtual appliances and exposed services in cloud infrastructures.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain morning/v1/{redacted} Details →
Filename wp2shell Details →

MITRE ATT&CK TTPs 1 techniques