TI Mindmap HUB
Threat Intelligence Report

UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications

📅 April 2, 2026 📰 blog.talosintelligence.com 🔍 1 CVE(s) referenced

A highly automated threat campaign dubbed UAT-10608 is exploiting a Next.js vulnerability to compromise hundreds of web applications worldwide, harvesting and aggregating a vast array of sensitive credentials—including SSH keys, cloud tokens, and payment secrets—via a sophisticated exfiltration framework with a web-based control panel.

CVE-2025-55182

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle