<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: MongoDB Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving MongoDB.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</title><link>https://sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale</link><guid isPermaLink="false">cst-606</guid><description>SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.</description><pubDate>Thu, 07 May 2026 10:00:17 GMT</pubDate></item><item><title>MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know</title><link>https://wiz.io/blog/mongobleed-cve-2025-14847-exploited-in-the-wild-mongodb</link><guid isPermaLink="false">cst-1368</guid><description>CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB, is being actively exploited in the wild. Organizations running affected MongoDB instances face immediate risk of data exposure and should apply patches urgently.</description><pubDate>Sun, 28 Dec 2025 09:24:54 GMT</pubDate></item><item><title>Merry Christmas Day! Have a MongoDB security incident.</title><link>https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-587</guid><description>A public exploit for CVE-2025-14847 was released on Christmas Day, enabling unauthenticated memory reads from MongoDB instances. The vulnerability affects all MongoDB versions over the past decade and allows attackers to extract sensitive data such as database passwords and AWS secret keys. With over 200,000 MongoDB instances exposed to the internet and the exploit now publicly available, mass exploitation is expected.</description><pubDate>Fri, 26 Dec 2025 16:52:57 GMT</pubDate></item></channel></rss>