Back to cases

Live public case

Confirmed compromise

Last activity Sep 10, 10:53:05 AM PDT

criticalImpact confirmed

Evidence-grounded assessment

Pending

Broad unauthenticated route and HTTP method enumeration observed

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Remote command execution
  • Root execution
  • Server identity disclosure
  • State changing http activity after compromise
  • System discovery
  • System information disclosure

Recommended actions

    Attack timeline

    2 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Attempted exploitationopen

      Broad unauthenticated route and HTTP method enumeration observed

    2. 2
      Confirmed compromiseconfirmed

      Broad unauthenticated route and HTTP method enumeration observed

    Relationship reasoning

    Same source cluster86%

    same privacy-preserving traffic source cluster and target within a bounded time window