MongoBleed (CVE-2025-14847) is a remotely exploitable MongoDB vulnerability that allows unauthenticated attackers to leak uninitialized heap memory that allows remote, unauthenticated attackers to leak sensitive server memory—without ever logging in. With public proof-of-concept tooling already available and the vulnerability impacting nearly a decade of MongoDB releases, defenders need a fast, reliable way to identify exposure and detect exploitation attempts across both internet-facing and internal environments.
In this Attack Lab session, we’ll break down how MongoBleed works, what makes it uniquely dangerous (even in environments with authentication and TLS enabled), and why “do we even run MongoDB?” is often harder to answer than it seems. We’ll then move from theory to practice by showing how network metadata can be used to rapidly hunt for MongoDB services—even on non-standard ports and even when traffic is encrypted—using indicators like predictable session behavior, byte patterns, and TLS fingerprinting (JA3/JA4 and server-side equivalents).
To close, we’ll deliver a live demo of the open-source MongoBleed security testing tool, showing how defenders can safely validate risk and confirm the presence of vulnerable systems in authorized environments. We’ll walk through scan modes and output interpretation, including how attackers can extract meaningful fragments of data from memory leaks.
Who should attend: Security leaders, SOC teams, incident responders, and threat hunters responsible for detecting and reducing real-world exposure to high-impact vulnerabilities in modern hybrid networks.

Vectra AI is the leader in hybrid attack detection, investigation and response. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Vectra AI’s patented Attack Signal Intelligence empowers security teams to rapidly detect, prioritize, investigate and stop the most advanced hybrid cyber-attacks. With 35 patents in AI-driven detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI Platform and MXDR services to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai.