In 2025, the boundaries between cloud, AI, and software supply chains continued to blur. Security incidents in 2025 clearly demonstrate how cyber threats are evolving in tandem with AI, cloud platforms, and modern development environments. Wiz Research analyzes how attackers adapt their methods to these changing conditions and has revealed several significant vulnerabilities during the year that exposed millions of users to risk.
A new compilation shows a clear pattern where the most critical vulnerabilities revolved around three main areas. These include AI exposure, attacks on software supply chains, and vulnerabilities in central cloud infrastructure.
The discovery of an exposed DeepSeek database received a lot of attention and marked the beginning of a year marked by rapid development in large language models and AI tools for developers.
At the same time, it became increasingly common for critical vulnerabilities to spread through common software components, highlighting a continued hidden risk in the underlying software used in many modern cloud platforms.
Cloud-based software supply chains quickly evolved into a new front line for cyberattacks. Malicious code campaigns were designed to spread via CI CD systems, package registries, and pipelines. In many cases, the extensive use of npm and GitHub.
New methods pave the way for attacks in 2026
The wave of new AI technology led to misconfigurations, leaked tokens, and pipeline flaws – weaknesses that attackers will continue to exploit in 2026. During the year, malicious code campaigns are also likely to target developer IDE add-ons and AI artifacts such as models and MCP servers.

“At the end of January we saw how Moltbook, a platform built for AI agents, literally exploded. Just a few days later, Wiz Research ”We uncovered extensive security vulnerabilities that exposed 35,000 email addresses, while also revealing how humans were largely behind the AI agents. This development highlights two important things: the rapid innovation in AI is creating new attack surfaces, and security efforts must evolve at the same pace to meet this new reality,” says Jesper Rellme, Manager Solutions Engineering at Wiz.
Here are five of the most notable vulnerabilities in 2025.

Wiz Research reveals exposed DeepSeek database
Wiz Research identified a publicly accessible ClickHouse database belonging to DeepSeek, which gave full control over database operations, including access to internal data. The exposure included over a million rows of log streams containing chat history, secret keys, backend details, and other extremely sensitive information.

Shai-Hulud 2.0 supply chain attack
A second Shai-Hulud-related npm-supply-chain campaign compromised important packages, some of which were widely distributed, and was found in approximately 27 percent of the cloud and code environments scanned by Wiz. The blast radius was massive and grew rapidly due to extensive automated replication: over 25,000 malicious repos across approximately 500 GitHub users, with a growth rate of approximately 1,000 new repos every 30 minutes.

React2Shell (CVE-2025-55182)
A critical vulnerability was identified in the React Server Components (RSC) ”Flight” protocol, affecting the React 19 ecosystem and the frameworks that implement it, most notably Next.js. The vulnerability was assigned CVE-2025-55182 and allowed unauthenticated remote code execution (RCE) on the server due to insecure deserialization. Data from Wiz Research showed that 39 percent of cloud environments contained vulnerable instances.

IngressNightmare
Wiz Research discovered CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974 – a series of unauthenticated RCE vulnerabilities in the Ingress NGINX Controller for Kubernetes, collectively known as #IngressNightmare. Exploitation of these vulnerabilities could have led to unauthorized access to all secrets stored in all namespaces in the Kubernetes cluster, with the potential to result in a complete takeover of the cluster.

Shai-Hulud
The first Shai-Hulud attack on the software supply chain occurred when tampered versions of several popular packages were published on npm. These contained a post-install script that collected sensitive information and exfiltrated it into public GitHub repositories that the attackers had created under the name Shai-Hulud. In addition to data theft, the malicious code exhibited worm-like behavior: when a compromised package encountered additional npm tokens in the environment it was running in, it automatically published tampered versions of all packages it had access to, allowing it to spread throughout the npm ecosystem.
From supply chain attacks to AI-driven risk and vulnerabilities in core infrastructure, the same theme recurs: complexity creates opportunities for attackers. As new technologies create new conditions in 2026, Wiz Research continues to share insights that help teams understand where risks are accumulating and how best to respond.
The full list is available here.








