T1071.001Web Protocols
T1071.001 — Web Protocols is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 250 detection use cases covering it and 244 threat-intel articles citing it.
Command and Control
250Use cases
244Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1071 · Application Layer Protocol
Use cases covering this technique (250)
Beaconing — periodic outbound to small set of destinations [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script Windows Non-System Process Querying Definition Update Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Cisco Secure Firewall - Connection to File Sharing Domain Cisco Secure Firewall - High EVE Threat Confidence Cisco Secure Firewall - Wget or Curl Download HTTP C2 Framework User Agent HTTP Malware User Agent HTTP PUA User Agent HTTP RMM User Agent HTTP Duplicated Header HTTP Possible Request Smuggling HTTP Rapid POST with Mixed Status Codes HTTP Request to Reserved Name on IIS Server HTTP Scripting Tool User Agent Detect web traffic to dynamic domain providers HTTP Suspicious Tool User Agent [LLM] Artifactory host egress to public internet (package-registry sandbox escape) [LLM] Flying Eagle Android RAT C2 / panel infrastructure callback (confirmed IOCs) [LLM] Flying Eagle / SQLRCE / Night Dragon control-panel exposed on monitored web server [LLM] RAT C2 egress to hardcoded joyfill IPs and /$/boot request paths [LLM] Node.js resolving C2 via Tron + Binance Smart Chain dead-drop RPC [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) [LLM] Anonymous access to Artifactory Terraform/Cargo/Ansible remote repositories [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 [LLM] Trojanized MeshAgent covert backdoor: SYSTEM service beaconing over WSS (Sinobi) [LLM] Outbound C2 / reverse shell from TeamCity server process — CVE-2026-63077 [LLM] NightLedger C2 beacon to realhealthshop[.]com / tjconsultingservices[.]com with hardcoded URIs [LLM] BridgeHead WebSocket SOCKS5 tunnel to smartconnect.azurewebsites.net with hardcoded Edg/86 UA [LLM] Mirage Kitten (UNC1549) infrastructure & payload IOC sweep [LLM] Dysphoria botnet blockchain C2 resolution via ENS/SNS (.eth/.sol) domains [LLM] Egress to Dysphoria distribution-node / relay IPs (194.87.198.x, 194.58.38.x) [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) [LLM] Cruciferra C2 beacon to known IOC domains/IPs (incl. .gu.cc cluster) [LLM] Telegram Bot API used for C2 by non-browser/non-messaging process [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) [LLM] BINDCLOAK C2 beacon to cert.hypersnet.com / ssl.blsouqs.com [LLM] Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) [LLM] TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure [LLM] msaRAT: Headless Chrome/Edge launched with remote-debugging (CDP abuse) [LLM] msaRAT: Headless browser initiating WebRTC STUN/TURN egress [LLM] Network/DNS contact to Q2 2026 campaign infrastructure (pixeldrain payload + ClickUp dropper hosts) [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 [LLM] msaRAT CDP abuse: headless Chrome/Edge with remote-debugging port spawned by non-browser parent [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain [LLM] Anomalous DLL-host process reaching Microsoft Graph/login.microsoftonline for calendar C2 [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org [LLM] ClickFix RunMRU entry launching rundll32 against WebDAV GUID share (ACR Stealer) [LLM] rundll32 loading DLL from remote WebDAV @ssl GUID share with ordinal export (ACR Stealer) [LLM] Endpoint traffic to ACR Stealer C2 / dead-drop domains [LLM] Blockchain-anchored C2 fallback: non-browser process contacting polygon-rpc.com [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains [LLM] HelloProxy C2-handler artifact: tesh4RPC.txt written to C:\Users\Public [LLM] HelloNet C2 egress to 5.39.253.206 / 176.32.34.135 [LLM] Starland RAT / WLDR C2 beaconing to UAT-11795 HWID-parameterized domains [LLM] Starland RAT blockchain fallback C2 via Polygon eth_call (polygon-rpc.com) [LLM] Outbound C2 to Miasma controller 85.137.53.71 on ports 8080/8081/8091 [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) [LLM] Outbound connection to UAT-7810 (LapDogs ORB) SHORTLEASH/DOGLEASH C2 VPS [LLM] Neo4j server outbound egress to public IP (LOAD CSV / apoc.load SSRF) [LLM] Outbound egress from shell/downloader child of a Python (Langroid) process [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 [LLM] HTTP request to an executable PHP file under Mautic /media (web-shell interaction) [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) [LLM] Dormant crypto-miner on servers: sustained stratum egress to mining pools [LLM] easy-day-js second-stage C2 beacon to Mastra supply-chain infrastructure [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 [LLM] JetBrains IDE JVM plaintext HTTP POST to AI-key stealer endpoint /api/software/ [LLM] AI coding-assistant egress to first-seen external domain (phantom squatting) [LLM] Outbound connection to CL-STA-1062 / TinyRCT C2 and tool-staging infrastructure [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) [LLM] Bun process reaching GitHub commit-search API — Miasma dead-drop C2 [LLM] Network egress to ClawHavoc cluw / AMOS C2 infrastructure [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) [LLM] Developer-runtime exfiltration to webhook.site (Shai-Hulud token drop) [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 [LLM] JetBrains IDE plugin AI-key exfil: endpoint egress to C2 39.107.60.51 [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path [LLM] axios npm RAT C2 beacon to UNC1069 infra (142.11.206.73 / sfrclak.com) [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs [LLM] SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) [LLM] Rust build script making outbound network connection (build-time exfil) [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) [LLM] node child of npm install initiating outbound network to non-registry destination [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) [LLM] BTMOB C2/phishing domain contact — arbsniper.com [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 [LLM] Endpoint DNS or web traffic to fake FIFA World Cup 2026 typosquat domain [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) [LLM] FIRESCALE GitHub dead-drop fallback C2 lookup (api.github.com commit search) [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) [LLM] Mini Shai-Hulud C2 backchannel: python polling GitHub commit search for 'firedalazer' [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header [LLM] Qinglong cryptominer payload download from file.551911.xyz [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro [LLM] Non-browser process posting to Slack Web API (LaxGopher C2) [LLM] Non-browser process posting to Discord API (RatGopher C2) [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil [LLM] GlassWorm Solana blockchain dead-drop C2 lookup via public RPC endpoints from Node [LLM] Outbound TCP beacon to BlokTrooper Socket.IO C2 195.201.104.53:6931/6936/6939 [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 [LLM] BeardShell C2: outbound to Icedrive cloud-storage API as non-browser process [LLM] Covenant C2: outbound to Filen cloud-storage API as non-browser process [LLM] PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) [LLM] Ultralytics coinminer C2 — Stratum to connect.consrensys.com:8080 mining pool [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line [LLM] Dev endpoint contacts ClawHub / skills.sh agent-skill marketplace [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree [LLM] PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint [LLM] Connection to Beamglea phishing credential-harvesting domains [LLM] DNS or HTTP egress to giftshop.club exfil domain [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob [LLM] npm/PyPI install-script beacon to hardcoded C2 3.72.6.53 (django-yauth supply chain) [LLM] CircleCI breach C2 egress to potrax[.]com and 8 hardcoded attacker IPs [LLM] Python child-of-python making download-and-exec egress to non-PyPI host [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) [LLM] node-ipc/peacenotwar geolocation beacon to api.ipgeolocation.io from Node runtime [LLM] Outbound or inbound connection to TrojanOrders C2/source IP 45.134.20.11 [LLM] Network activity involving CVE-2022-24086 attacker IP 45.134.20.11 [LLM] CodeCov uploader egress to non-CodeCov host (surfaces exfil server IP) [LLM] Outbound connection/DNS to npm exfil endpoint entfet95itcxpuu.m.pipedream.net [LLM] npm/node install lifecycle spawning interactive or reverse shell [LLM] ImageMagick convert lineage egress to public IP (url() delegate / netcat reverse shell) [LLM] Mintegral SourMint SDK config/analytics beacon to rayjump.com [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter [LLM] Exfiltration callback to mironanoru.zzz.com.ua (rest-client backdoor C2) [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.ua [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) [LLM] CRLF / HTTP-header injection in URL query string (urllib3 CVE-2019-11236 PoC shape) [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie [LLM] ImageMagick binary making outbound network connection (ImageTragick URL/HTTPS coder SSRF)Articles citing this technique (244)
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Don’t swing at everything art-106
crit Begun, the Patch Wars have art-150
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-253
crit [GHSA / CRITICAL] CVE-2026-9559: Mautic vulnerable to Path Traversal via Campaign Import art-258
high Catan and Mouse art-261
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
low Snyk @ RSAC 2025 art-971
crit CISA KEV: CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability art-1118
high Ethical Hacking: Top Tools art-1702
med New IaC security workshop from Snyk, HashiCorp, and AWS at KubeCon Europe 2023 and on-demand art-1772
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2203
crit CISA KEV: CVE-2021-45382 — D-Link Multiple Routers Remote Code Execution Vulnerability art-2340
med Checking Terraform IaC security in CI/CD with Regula and Bitbucket Pipelines [Tutorial] art-2715