Research for Aqua Security
← All companiesAqua Security
Former Director of Threat Intelligence, Aqua Security
- ResearchOpen Investigate and Respond to Sobolan Malware with Aqua Security
Investigate and Respond to Sobolan Malware with Aqua Security
Read on MoragCyber - ResearchOpen AI-Generated Malware in Panda Image Hides Persistent Linux Threat
AI-Generated Malware in Panda Image Hides Persistent Linux Threat
Read on MoragCyber - TalkOpen Shadows in the Cloud: The Invisible Pathways to Breaching AWS Accounts
Shadows in the Cloud: The Invisible Pathways to Breaching AWS Accounts
TyphoonCon 2025
- ResearchOpen Tomcat in the Crosshairs: New Research Reveals Ongoing Attacks
Tomcat in the Crosshairs: New Research Reveals Ongoing Attacks
Read on MoragCyber - ResearchOpen Stopping Sobolan Malware with Aqua Runtime Protection
Stopping Sobolan Malware with Aqua Runtime Protection
Read on MoragCyber - ResearchOpen Investigate and Respond to Sobolan Malware
Investigate and Respond to Sobolan Malware
Read on MoragCyber - ResearchOpen Matrix Unleashes A New Widespread DDoS Campaign
Matrix Unleashes A New Widespread DDoS Campaign
Read on MoragCyber - ResearchOpen Threat Actors Hijack Misconfigured Servers for Live Sports Streaming
Threat Actors Hijack Misconfigured Servers for Live Sports Streaming
Read on MoragCyber - ResearchOpen TeamTNT's Docker Gatling Gun Campaign
TeamTNT's Docker Gatling Gun Campaign
Read on MoragCyber - ResearchOpen TeamTNT Reemerged with New Aggressive Cloud Campaign
TeamTNT Reemerged with New Aggressive Cloud Campaign
Read on MoragCyber - ResearchOpen The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets
The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets
Read on MoragCyber - ResearchOpen 250M Artifacts Exposed via Misconfigured Registries
250M Artifacts Exposed via Misconfigured Registries
Read on MoragCyber - ResearchOpen HeadCrab: A Novel State-of-the-Art Redis Malware
HeadCrab: A Novel State-of-the-Art Redis Malware
Read on MoragCyber - ResearchOpen HeadCrab 2.0: Evolving Threat in Redis Malware Landscape
HeadCrab 2.0: Evolving Threat in Redis Malware Landscape
Read on MoragCyber - ResearchOpen New Vulnerability in curl and libcurl Could Lead to Heap Buffer Overflow
New Vulnerability in curl and libcurl Could Lead to Heap Buffer Overflow
Read on MoragCyber - ResearchOpen pg_mem: A Malware Hidden in the Postgres Processes
pg_mem: A Malware Hidden in the Postgres Processes
Read on MoragCyber - ResearchOpen Kinsing Malware Exploits Novel OpenFire Vulnerability
Kinsing Malware Exploits Novel OpenFire Vulnerability
Read on MoragCyber - ResearchOpen Loony Tunables Vulnerability Exploited by Kinsing
Loony Tunables Vulnerability Exploited by Kinsing
Read on MoragCyber - ResearchOpen Protect Containers from pg_mem Malware with Aqua Runtime Security
Protect Containers from pg_mem Malware with Aqua Runtime Security
Read on MoragCyber - ResearchOpen GitHub Action tj-actions/changed-files Compromised
GitHub Action tj-actions/changed-files Compromised
Read on MoragCyber - ResearchOpen Panamorfi: A New Discord DDoS Campaign
Panamorfi: A New Discord DDoS Campaign
Read on MoragCyber - ResearchOpen Real-world Cyber Attacks Targeting Data Science Tools
Real-world Cyber Attacks Targeting Data Science Tools
Read on MoragCyber - ResearchOpen Threat Alert: First Python Ransomware Attack Targeting Jupyter Notebooks
Threat Alert: First Python Ransomware Attack Targeting Jupyter Notebooks
Read on MoragCyber - ResearchOpen 300,000 Prometheus Servers and Exporters Exposed to DoS Attacks
300,000 Prometheus Servers and Exporters Exposed to DoS Attacks
Read on MoragCyber - ResearchOpen CVE-2022-42889 Text4shell Apache Commons Vulnerability
CVE-2022-42889 Text4shell Apache Commons Vulnerability
Read on MoragCyber - ResearchOpen Threat Alert: Anatomy of SilentBob's Cloud Attack
Threat Alert: Anatomy of SilentBob's Cloud Attack
Read on MoragCyber - ResearchOpen Cryptojacking Cloud Network Bandwidth
Cryptojacking Cloud Network Bandwidth
Read on MoragCyber - ResearchOpen Risks of Misconfigured Kubernetes Policy Engines: OPA Gatekeeper
Risks of Misconfigured Kubernetes Policy Engines: OPA Gatekeeper
Read on MoragCyber - ResearchOpen Tracee Rules: Detect Attackers Out of the Box
Tracee Rules: Detect Attackers Out of the Box
Read on MoragCyber - ResearchOpen Threat Alert: Exploited SSH Servers Offered in the Dark Web as Proxy Pools
Threat Alert: Exploited SSH Servers Offered in the Dark Web as Proxy Pools
Read on MoragCyber - ResearchOpen The Great Escape: A Blast Radius Analysis of Container Attacks
The Great Escape: A Blast Radius Analysis of Container Attacks
Read on MoragCyber - ResearchOpen Threat Alert: Supply Chain Attacks Using Container Images
Threat Alert: Supply Chain Attacks Using Container Images
Read on MoragCyber - ResearchOpen JDWP Misconfiguration in Container Images and K8s
JDWP Misconfiguration in Container Images and K8s
Read on MoragCyber - ResearchOpen Kubernetes Exposed: Exploiting the Kubelet API
Kubernetes Exposed: Exploiting the Kubelet API
Read on MoragCyber - ResearchOpen Advanced Persistent Threat Techniques in Container Attacks
Advanced Persistent Threat Techniques in Container Attacks
Read on MoragCyber - ResearchOpen Container Security Alert: Campaign Abusing GitHub, DockerHub, Travis CI, Circle CI
Container Security Alert: Campaign Abusing GitHub, DockerHub, Travis CI, Circle CI
Read on MoragCyber - ResearchOpen Kubernetes Exposed: One YAML Away from Disaster
Kubernetes Exposed: One YAML Away from Disaster
Read on MoragCyber - ResearchOpen GitHub Repos Expose Azure and Red Hat Secrets
GitHub Repos Expose Azure and Red Hat Secrets
Read on MoragCyber - ResearchOpen Container Security: TNT Container Attack
Container Security: TNT Container Attack
Read on MoragCyber - ResearchOpen CVE-2021-3156: Sudo Vulnerability Allows Root Privileges
CVE-2021-3156: Sudo Vulnerability Allows Root Privileges
Read on MoragCyber - ResearchOpen Travis CI Security: Protecting Your CI/CD Pipeline
Travis CI Security: Protecting Your CI/CD Pipeline
Read on MoragCyber - ResearchOpen Kubernetes UI Tools Security Threat
Kubernetes UI Tools Security Threat
Read on MoragCyber - ResearchOpen New Malware in the Cloud by TeamTNT
New Malware in the Cloud by TeamTNT
Read on MoragCyber - ResearchOpen GAFGYT Malware Variant Exploits GPU Power and Cloud-Native Environments
GAFGYT Malware Variant Exploits GPU Power and Cloud-Native Environments
Read on MoragCyber - ResearchOpen Phishing as a Service to Ramp Up Supply Chain Attacks
Phishing as a Service to Ramp Up Supply Chain Attacks
Read on MoragCyber - ResearchOpen Perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Read on MoragCyber - ResearchOpen Leveraging Kubernetes RBAC to Backdoor Clusters
Leveraging Kubernetes RBAC to Backdoor Clusters
Read on MoragCyber - ResearchOpen Malicious Container Image: Docker Container Host
Malicious Container Image: Docker Container Host
Read on MoragCyber - ResearchOpen Hadooken Malware Targets WebLogic Applications
Hadooken Malware Targets WebLogic Applications
Read on MoragCyber - ResearchOpen Threat Alert: Fileless Malware Executing in Containers
Threat Alert: Fileless Malware Executing in Containers
Read on MoragCyber - ResearchOpen Threat Alert: Market-First Container Image Built to Attack Kubernetes Clusters
Threat Alert: Market-First Container Image Built to Attack Kubernetes Clusters
Read on MoragCyber