Product
Caddy
- First Reported
- Sep 17, 2026
- Latest Reported
- Sep 29, 2026
Reported Context (2)
- classify and fingerprint services, harvest credentials and metadata, inject stored XSS into vast.ai's Caddy auth portals to steal session tokens, rent cheap containers on the same physical host as the target to VHX Harvester Uses npm Typosquats to Target Vast.ai GPU Instances
- We use Caddy as the reverse proxy and the coraza-caddy module to add Coraza inspection. Wazuh Tutorial Shows How to Monitor Coraza WAF Events and Detect Web Attacks
MITRE ATT&CK (5)
Vendors (1)
Products (8)
Tools (4)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.