Amitai Cohen🎗️🤟

@amitaico.bsky.social

personal website @ cloudcurio.us ✦ researching @ Wiz Security (threats.wiz.io) 🐞 maintaining @ cloudvulndb.org 🎙️ podcasting @ cryingoutcloud.io 🗺️ pivoting @ Pivot Atlas (gopivot.ing)

New threat hunting blogpost from our team - by checking which Linux processes normally use the Instance Metadata Service across thousands of cloud environments, we can identify exploitation of novel SSRF & RCE vulnerabilities when a process that shouldn't use IMDS suddenly does.

IMDS Abused: Hunting Rare Behaviors to Uncover Exploits | Wiz Blog

Wiz uncovered a zero-day vulnerability using IMDS anomaly detection. Learn how attackers exploit metadata services and how Wiz helps stop them.

wiz.io

🚨 New Wiz research: Active exploitation of Ivanti EPMM flaws (CVE-2025-4427 & 4428) enables RCE in the wild. Cloud systems are at risk; patch now. Wiz customers can find pre-built detection queries in the Threat Intelligence Center. Full details 👉 www.wiz.io/blog/ivanti-...

Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild | Wiz Blog

Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-4427 and CVE-2025-4428, the latest vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).

wiz.io

wife: how was guarding the two paths today, honey? guard: [looking away] fine wife: did something happen? guard: [tearing up] no wife: would the other guard tell me something happened?

🚨 OH NOOOO! Someone stole the secret recipe of ExfilCola. We need your help tomorrow to get it back. Set your clocks for 9 a.m. ET ⏰ You'll need curiosity, cloud IR skills, and a taste for solving mysteries. 🧠 Do you think you can crack it?

BildBildBildBild

This. is. massive! 🥁✨ Meet the Wiz Vulnerability Database—for CVEs that actually matter in the cloud. AI-powered reports, expert insights & fix guidance. No fluff, just essentials. 🔍 Explore: wiz.io/vulnerabilit...

#IngressNightmare: Wiz Research uncovers a critical vulnerability in Ingress-NGINX 🚨 Wiz Research found a novel attack vector in one of Kubernetes's most fundamental projects, Ingress-NGINX, which is rated CVSS 9.8.

Bild

BREAKING: Internal #DeepSeek database publicly exposed 🚨 Wiz Research has discovered "DeepLeak" - a publicly accessible ClickHouse database belonging to DeepSeek, exposing highly sensitive information, including secret keys, plain-text chat messages, backend details, and logs.

Bild

Pantheon is such an amazing show, I feel so late to the game only watching it now. I also appreciate how it was released slightly before Gen AI became mainstream, otherwise I suspect the script might have been different. Almost makes it seem like an alternate history.

📢 JUST DROPPED: Analyzing 150K+ cloud accounts, we took a deep dive into #AI adoption. And the results? Wild.

Bild

I get what they're trying to do, but this isn't an ideal solution. Would be better if MITRE / NIST maintained an EOL enumeration database similar to CVE. Meanwhile, for those not familiar, endoflife.date is a great reference for determining which versions of popular software are EOL.

Socket@socket.dev · 2y ago

📌 Node.js EOL versions just got their own CVE and critics are calling it “the worst CVE of the year.” Is this CVE a helpful PSA or an abuse of the system? Dive into the debate: socket.dev/blog/node-js... #NodeJS #cybersecurity #JavaScript