T1204.002Malicious File
T1204.002 — Malicious File is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 531 detection use cases covering it and 558 threat-intel articles citing it.
Execution
531Use cases
558Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (531)
Email attachment opened from external sender [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install O365 SharePoint Malware Detection O365 Threat Intelligence Suspicious File Detected Batch File Write to System32 Cisco NVM - Susp Script From Archive Triggering Network Activity Drop IcedID License dat Linux Ghostscript Exploitation Single Letter Process On Endpoint Suspicious Process Executed From Container File Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppX Deployment Full Trust Package Installation Windows AppX Deployment Package Installation Success Windows AppX Deployment Unsigned Package Installation Windows Binary Execution from an Archive Windows Default Cobalt Strike PowerShell Beacon Windows Developer-Signed MSIX Package Installation Windows EFI Volume Mount Attempt Via Mountvol Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows MSIX Package Interaction Windows Mustang Panda USB Tool Execution Windows NorthStar C2 Agent Execution Windows PowerShell Script From WindowsApps Directory Windows Suspect Process With Authentication Traffic Windows Suspicious QEMU Execution Windows Universal Data Link File Creation Windows User Execution Malicious URL Shortcut File Uncommon Processes On Endpoint Article-specific behavioural hunt — Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-m5w8-4gq2-6f8x: vm2: NodeVM `builtin: ['*']` exposes `os` Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47686: VM2 has Missing Error.cause Sanitization that Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55158: conflibot vulnerable to command injection via Article-specific behavioural hunt — Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Pro Article-specific behavioural hunt — Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Article-specific behavioural hunt — ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-dro Article-specific behavioural hunt — Top enterprise SCA tools in 2026 [LLM] Execution/write of published Sable Squirrel malware sample (SHA256 0464caa1...) Article-specific behavioural hunt — Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Window Article-specific behavioural hunt — Curiouser and Curiouser [LLM] PATCHCORD delivery via TMS_AfghanTelecom.exe Inno Setup installer / known hashes Article-specific behavioural hunt — Dissecting the JWR phishing framework Article-specific behavioural hunt — Armored Likho expands its cyber-espionage toolkit [LLM] Armored Likho Tauri donation-app dropper C2 (orderapiserver.info catalog endpoints) Article-specific behavioural hunt — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor [LLM] Trojanized Enveil 'SecurityPDF' viewer downloaded from fake sites and dropping Troy loader (new.exe) Article-specific behavioural hunt — 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You H Article-specific behavioural hunt — ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Acce Article-specific behavioural hunt — Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS Article-specific behavioural hunt — Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Att Article-specific behavioural hunt — Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Article-specific behavioural hunt — Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channe Article-specific behavioural hunt — Kimwolf v7: An Evolution of the Kimwolf Botnet Article-specific behavioural hunt — DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized rec Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptograph Article-specific behavioural hunt — Why metaphor may dictate your security strategy Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication Bypass via Path Traver Article-specific behavioural hunt — ChainDrop supply chain compromise: Anatomy of a self-propagating worm Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70477: Flowise: CSV Agent Prompt Injection Remote Cod [LLM] mshta.exe launched with inline http/https URL argument [LLM] RunMRU registry write launching mshta / URL / PowerShell (ClickFix-style user persistence) Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent csvFile data URI bas Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph b Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69259: Flowise RCE via SQLite Record Manager Node Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via P Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sandbox Escape in exec Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69251: Flowise RCE via TypeORM DataSource Article-specific behavioural hunt — Keyv and friends compromised in active Shai-Hulud supply chain attack Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69240: Sequelize: SQL Injection (Oracle DB) Article-specific behavioural hunt — An analysis of incidents at Brazilian educational institutions Article-specific behavioural hunt — Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52887: NocoBase: SQL injection in /api/myInAppChannel Article-specific behavioural hunt — Anthropic's Fever Dream: Claude's package that stole real keys Article-specific behavioural hunt — Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfus Article-specific behavioural hunt — You were onto something with “It’s the Climb,” Miley Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67426: Flyto2 Core: Unauthenticated flyto-verificatio Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67429: Flyto2 Core: Arbitrary file write via image.do Article-specific behavioural hunt — Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in N Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73649: Velocity.js: Remote Code Execution via propert Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Article-specific behavioural hunt — Don’t swing at everything Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73421: Auth.js: Configuration errors can cause existe Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73420: Auth.js: Email normalizer validates the addres Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73653: @vitest/browser: Browser Mode provider command Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Article-specific behavioural hunt — Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised C Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Article-specific behavioural hunt — What is a dependency firewall? Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Article-specific behavioural hunt — Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Re [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Article-specific behavioural hunt — Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Reposito [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Article-specific behavioural hunt — Dev Machine Guard Now Supports Linux Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Article-specific behavioural hunt — A rigged game: ScarCruft compromises gaming platform in a supply-chain attack [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Article-specific behavioural hunt — Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, Article-specific behavioural hunt — CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentia Article-specific behavioural hunt — Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Article-specific behavioural hunt — lightning PyPI Compromise: A Bun-Based Credential Stealer in Python Article-specific behavioural hunt — Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer Article-specific behavioural hunt — Someone published four versions of a fake "tanstack" package in 27 minutes to st Article-specific behavioural hunt — "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Article-specific behavioural hunt — Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Reme Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Article-specific behavioural hunt — Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomini Article-specific behavioural hunt — Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Wo Article-specific behavioural hunt — GopherWhisper: A burrow full of malware Article-specific behavioural hunt — GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Article-specific behavioural hunt — Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest np Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Article-specific behavioural hunt — Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw Article-specific behavioural hunt — GlassWorm goes native: New Zig dropper infects every IDE on your machine Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Article-specific behavioural hunt — litellm: Credential Stealer Hidden in PyPI Wheel [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Article-specific behavioural hunt — Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags Article-specific behavioural hunt — CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Article-specific behavioural hunt — Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup- Article-specific behavioural hunt — bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys Article-specific behavioural hunt — Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Do Article-specific behavioural hunt — Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wa Article-specific behavioural hunt — ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Article-specific behavioural hunt — xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Article-specific behavioural hunt — Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard Article-specific behavioural hunt — DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laund [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Article-specific behavioural hunt — kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package Article-specific behavioural hunt — Sednit reloaded: Back in the trenches Article-specific behavioural hunt — The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Article-specific behavioural hunt — PlugX Meeting Invitation via MSBuild and GDATA Article-specific behavioural hunt — Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Article-specific behavioural hunt — Exploitability Isn’t the Answer. Breakability Is. [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Article-specific behavioural hunt — Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Stu Article-specific behavioural hunt — CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Co Article-specific behavioural hunt — Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component Article-specific behavioural hunt — Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE- Article-specific behavioural hunt — Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Article-specific behavioural hunt — Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders Article-specific behavioural hunt — PlushDaemon compromises network devices for adversary-in-the-middle attacks Article-specific behavioural hunt — Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Link Article-specific behavioural hunt — Snyk Studio brings security scanning and automated fixes to Factory's Droids Article-specific behavioural hunt — Phishing Campaign Leveraging the NPM Ecosystem Article-specific behavioural hunt — CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Article-specific behavioural hunt — Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack Article-specific behavioural hunt — npm Supply Chain Attack via Open Source maintainer compromise Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Article-specific behavioural hunt — Cursor IDE Malware Extension Compromise in $500k Crypto Heist [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Article-specific behavioural hunt — Security Testing for Single-Page Applications (SPAs) Article-specific behavioural hunt — CVE-2025-29927 Authorization Bypass in Next.js Middleware Article-specific behavioural hunt — Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Article-specific behavioural hunt — Can Snyk Detect JWT Security Issues? Article-specific behavioural hunt — Solving Security Challenges with Snyk Code and Symbolic AI Article-specific behavioural hunt — CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability Article-specific behavioural hunt — Creating SBOMs with the Snyk CLI Article-specific behavioural hunt — CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Article-specific behavioural hunt — Ultralytics AI Pwn Request Supply Chain Attack Article-specific behavioural hunt — Lottie Player npm package compromised for crypto wallet theft Article-specific behavioural hunt — The mysterious supply chain concern of string-width-cjs npm package Article-specific behavioural hunt — Proactive AppSec continuous vulnerability management for developers and security Article-specific behavioural hunt — Promise queues and batching concurrent tasks in Deno Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Article-specific behavioural hunt — Want to avoid a data breach? Employ secrets detection Article-specific behavioural hunt — CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability Article-specific behavioural hunt — Vulnerabilities in NodeJS C/C++ add-on extensions Article-specific behavioural hunt — A denial of service Regex breaks FastAPI security Article-specific behavioural hunt — 10 Dimensions of Python Static Analysis Article-specific behavioural hunt — Polyfill supply chain attack embeds malware in JavaScript CDN assets Article-specific behavioural hunt — Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk Article-specific behavioural hunt — Essential Node.js backend examples for developers in 2024 Article-specific behavioural hunt — 10 modern Node.js runtime features to start using in 2024 Article-specific behavioural hunt — CISA KEV: CVE-2024-4978 — Justice AV Solutions (JAVS) Viewer Installer Embedded Article-specific behavioural hunt — Fastify plugins as building blocks for a backend Node.js API Article-specific behavioural hunt — Preventing broken access control in express Node.js applications Article-specific behavioural hunt — Symmetric vs. asymmetric encryption: Practical Python examples Article-specific behavioural hunt — Building an npm package compatible with ESM and CJS in 2024 Article-specific behavioural hunt — Nine Docker pro tips for Node.js developers Article-specific behavioural hunt — Exploiting HTTP/2 CONTINUATION frames for DoS attacks Article-specific behavioural hunt — GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok Article-specific behavioural hunt — CISA KEV: CVE-2024-21338 — Microsoft Windows Kernel Exposed IOCTL with Insuffici Article-specific behavioural hunt — 5 Node.js security code snippets every backend developer should know Article-specific behavioural hunt — Preventing server-side request forgery in Node.js applications Article-specific behavioural hunt — Preventing SQL injection attacks in Node.js Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Article-specific behavioural hunt — Build and deploy a Node.js security scanning API to Platformatic Cloud Article-specific behavioural hunt — Command injection in Python: examples and prevention Article-specific behavioural hunt — Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE? Article-specific behavioural hunt — Code injection in Python: examples and prevention Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages Article-specific behavioural hunt — Exploring WebExtension security vulnerabilities in React Developer Tools and Vue Article-specific behavioural hunt — File encryption in Python: An in-depth exploration of symmetric and asymmetric t Article-specific behavioural hunt — Dependency injection in Python Article-specific behavioural hunt — The art of conditional rendering: Tips and tricks for React and Next.js develope Article-specific behavioural hunt — Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & Article-specific behavioural hunt — Installing and managing Java on macOS Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Article-specific behavioural hunt — Modern VS Code extension development tutorial: Building a secure extension Article-specific behavioural hunt — Security implications of cross-origin resource sharing (CORS) in Node.js Article-specific behavioural hunt — A guide to input validation with Spring Boot Article-specific behavioural hunt — Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison Article-specific behavioural hunt — Using JLink to create smaller Docker images for your Spring Boot Java applicatio Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Article-specific behavioural hunt — Mitigating DOM clobbering attacks in JavaScript Article-specific behavioural hunt — Implementing TLS in Kubernetes Article-specific behavioural hunt — Finding and fixing insecure direct object references in Python Article-specific behavioural hunt — Swift deserialization security primer Article-specific behavioural hunt — XS leaks: What they are and how to avoid them Article-specific behavioural hunt — Building a security-conscious CI/CD pipeline Article-specific behavioural hunt — The importance of verifying webhook signatures Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Article-specific behavioural hunt — The SecurityManager is getting removed in Java: What that means for you Article-specific behavioural hunt — Ethical Hacking: Top Tools Article-specific behavioural hunt — Setting up the Docker image scan GitHub Action Article-specific behavioural hunt — Secure JavaScript URL validation Article-specific behavioural hunt — Security implications of HTTP response headers Article-specific behavioural hunt — Preventing insecure deserialization in Node.js Article-specific behavioural hunt — Timing out synchronous functions with regex Article-specific behavioural hunt — Avoiding mass assignment vulnerabilities in Node.js Article-specific behavioural hunt — The Docker project turns 10! Looking back at a decade of containers Article-specific behavioural hunt — Comparing Node.js web frameworks: Which is most secure? Article-specific behavioural hunt — Mitigating path traversal vulns in Java with Snyk Code Article-specific behavioural hunt — Node.js multithreading with worker threads: pros and cons Article-specific behavioural hunt — The security concerns of a JavaScript sandbox with the Node.js VM module Article-specific behavioural hunt — Building Vue 3 components with Tailwind CSS Article-specific behavioural hunt — CISA KEV: CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows Denial-o Article-specific behavioural hunt — CSPRNG: Random algorithms need security too! Article-specific behavioural hunt — Adding security to Nuxt 3 [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Article-specific behavioural hunt — You should be using HTTP Strict Transport Security (HSTS) headers in your Node.j Article-specific behavioural hunt — 5 "no experience needed" tips for building secure applications Article-specific behavioural hunt — Azure Bicep security fundamentals Article-specific behavioural hunt — Dependency injection in JavaScript Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Treasure Trove Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Moongoose Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: File Explorer Article-specific behavioural hunt — NPM security: preventing supply chain attacks Article-specific behavioural hunt — Secure Python URL validation Article-specific behavioural hunt — Ruby on Rails Docker for local development environment Article-specific behavioural hunt — New OpenSSL critical vulnerability: What you need to know Article-specific behavioural hunt — Node.js multithreading with worker threads series: worker_threads tutorial Article-specific behavioural hunt — Improving code quality with linting in Python Article-specific behavioural hunt — Choosing the best Node.js Docker image Article-specific behavioural hunt — The npm faker package and the unexpected demise of open source libraries Article-specific behavioural hunt — Solve Hack the Box and other CTF challenges with Snyk Article-specific behavioural hunt — Building a secure API with gRPC Article-specific behavioural hunt — Rediscovering argument injection when using VCS tools — git and mercurial Article-specific behavioural hunt — The dangers of assert in Python Article-specific behavioural hunt — Ruby gem installations can expose you to lockfile injection attacks Article-specific behavioural hunt — Snyk finds PyPi malware that steals Discord and Roblox credential and payment in Article-specific behavioural hunt — Controlling your server with a reverse shell attack Article-specific behavioural hunt — Securing PHP containers Article-specific behavioural hunt — Slidev 101: Coding presentations with Markdown Article-specific behavioural hunt — Safer together: Snyk and CISPA collaborate for the greater good Article-specific behavioural hunt — CISA KEV: CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerabil Article-specific behavioural hunt — Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confu Article-specific behavioural hunt — CISA KEV: CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — 3 Jedi-inspired lessons to level up your JavaScript security Article-specific behavioural hunt — Building Docker images in Kubernetes Article-specific behavioural hunt — Targeted npm dependency confusion attack caught red-handed Article-specific behavioural hunt — Generating fake security data with Python and faker-security Article-specific behavioural hunt — Modernizing SAST rules maintenance to catch vulnerabilities faster Article-specific behavioural hunt — Improving GraphQL security with static analysis and Snyk Code Article-specific behavioural hunt — CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vul Article-specific behavioural hunt — Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit Article-specific behavioural hunt — CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution V Article-specific behavioural hunt — Exploring 3 types of directory traversal vulnerabilities in C/C++ Article-specific behavioural hunt — Building a secure GraphQL API with Node.js Article-specific behavioural hunt — CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vu Article-specific behavioural hunt — CISA KEV: CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2011-2005 — Microsoft Ancillary Function Driver (afd.sys) Improper Article-specific behavioural hunt — CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow V Article-specific behavioural hunt — CISA KEV: CVE-2014-6332 — Microsoft Windows Object Linking & Embedding (OLE) Aut Article-specific behavioural hunt — Alert: peacenotwar module sabotages npm developers in the node-ipc package to pr Article-specific behavioural hunt — Build a software bill of materials (SBOM) for open source supply chain security Article-specific behavioural hunt — "Dirty Pipe" Linux vulnerability and your containerized applications (CVE-2022-0 Article-specific behavioural hunt — Celebrating amazing open source innovation from Ukraine Article-specific behavioural hunt — CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnera Article-specific behavioural hunt — CISA KEV: CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerab Article-specific behavioural hunt — CISA KEV: CVE-2013-0640 — Adobe Reader and Acrobat Memory Corruption Vulnerabili Article-specific behavioural hunt — CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulner Article-specific behavioural hunt — Visibly invisible malicious Node.js packages: When configuration niche meets inv Article-specific behavioural hunt — Join The Big Fix: a 24-hour livestream dedicated to fixing security vulnerabilit Article-specific behavioural hunt — Case study: Python RCE vulnerability in Celery Article-specific behavioural hunt — Automating Terraform security in Scalr deployments with Regula [Tutorial] Article-specific behavioural hunt — CISA KEV: CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability Article-specific behavioural hunt — Using Pulumi to automate the Snyk Kubernetes integration for containers Article-specific behavioural hunt — CISA KEV: CVE-2021-21315 — System Information Library for Node.JS Command Inject Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Article-specific behavioural hunt — Open source maintainer pulls the plug on npm packages colors and faker, now what Article-specific behavioural hunt — Log4Shell in a nutshell (for non-developers & non-Java developers) Article-specific behavioural hunt — Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17 Article-specific behavioural hunt — Scanning ARM templates for misconfigurations with the Snyk CLI Article-specific behavioural hunt — Exploring extensions of dependency confusion attacks via npm package aliasing Article-specific behavioural hunt — JavaScript type confusion: Bypassed input validation (and how to remediate) Article-specific behavioural hunt — CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Article-specific behavioural hunt — CISA KEV: CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2020-0601 — Microsoft Windows CryptoAPI Spoofing Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization Article-specific behavioural hunt — CISA KEV: CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cr Article-specific behavioural hunt — Snyk Code CLI support now in public beta Article-specific behavioural hunt — A (soft) introduction to Python dependency management Article-specific behavioural hunt — Detect and prevent dependency confusion attacks on npm to maintain supply chain Article-specific behavioural hunt — The 8 best IntelliJ plugins for improving your coding experience Article-specific behavioural hunt — Plugins to put Node.js application security and observability in your IDE Article-specific behavioural hunt — Building Java container images using Jib Article-specific behavioural hunt — Use Snyk security policies to prioritize fixes more efficiently Article-specific behavioural hunt — Better Ruby Gemfile security: A step-by-step guide using Snyk Article-specific behavioural hunt — Getting started with Snyk for secure Python development Article-specific behavioural hunt — Four steps for hardening Amazon EKS security Article-specific behavioural hunt — Managing Node.js Docker images in GitHub Packages using GitHub Actions Article-specific behavioural hunt — Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging Article-specific behavioural hunt — Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extens Article-specific behavioural hunt — Snyk takes on responsibility for Node.js ecosystem vulnerability disclosure prog Article-specific behavioural hunt — SuiteCRM: PHAR deserialization vulnerability to code execution Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Article-specific behavioural hunt — Why developer-first SAST tools are the future of code security Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Article-specific behavioural hunt — Docker Hub authentication: Is 2021 the year you enable 2FA on Docker Hub? Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Article-specific behavioural hunt — AWS vulnerability scanning using the Snyk integration Article-specific behavioural hunt — What makes Verdaccio a successful project? Article-specific behavioural hunt — Docker for Node.js developers: 5 things you need to know not to fail your securi Article-specific behavioural hunt — What is typosquatting and how typosquatting attacks are responsible for maliciou Article-specific behavioural hunt — Securing your Kubernetes application development with Snyk and Tilt Article-specific behavioural hunt — What makes Fastify a successful project? Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Article-specific behavioural hunt — Kernel privilege escalation: how Kubernetes container isolation impacts privileg Article-specific behavioural hunt — 10 git aliases for a faster and productive git workflow Article-specific behavioural hunt — Command injection: how it works, what are the risks, and how to prevent it Article-specific behavioural hunt — DevSecOps tools for open source projects in JavaScript and Node.js Article-specific behavioural hunt — Container image formats under the hood Article-specific behavioural hunt — RPM Package Manager: RPM package security scanning with Snyk Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Article-specific behavioural hunt — From zero to security hero: test your GitHub projects for known vulnerabilities Article-specific behavioural hunt — GitHub Actions to securely publish npm packages Article-specific behavioural hunt — Node.js security: lessons from the Node.js Security Working Group in triaging vu Article-specific behavioural hunt — Privileged Docker containers—do you really need them? Article-specific behavioural hunt — Regular Expression Denial of Service (REDoS) in UAParser.js Article-specific behavioural hunt — SourMint malicious SDK research write up Article-specific behavioural hunt — JHipster security scanning with Snyk Article-specific behavioural hunt — SourMint malicious SDK research writeup Article-specific behavioural hunt — Breaking out of message brokers Article-specific behavioural hunt — Demystifying HTTP request smuggling Article-specific behavioural hunt — Regular Expression Denial-of-Service in websocket-extensions Article-specific behavioural hunt — Checking Helm Charts for security misconfigurations Article-specific behavioural hunt — Why do organizations trust Snyk to win the open source security battle? Article-specific behavioural hunt — Using Snyk to implement end-to-end DevSecOps on Microsoft Azure Article-specific behavioural hunt — Why did is-promise happen and what can we learn from it Article-specific behavioural hunt — Snyk vulnerability disclosure program: what’s going on behind the scenes? Article-specific behavioural hunt — Yarn 2 plugins - an introduction Article-specific behavioural hunt — VS Code extension: building auto CI/CD with GitHub Actions Article-specific behavioural hunt — Yarn 2 — the future of package managers for JavaScript? Article-specific behavioural hunt — March in review: State of Open Source Security survey, All.The.Talks virtual con Article-specific behavioural hunt — Using UBI images to minimize container vulnerabilities Article-specific behavioural hunt — Creating an automated cloud infrastructure testing tool with Terraform and PyTes Article-specific behavioural hunt — Exploring the minimist prototype pollution security vulnerability Article-specific behavioural hunt — The State of Open Source Security Survey - 2020 Article-specific behavioural hunt — What is a backdoor? Let’s build one with Node.js Article-specific behavioural hunt — Fastify Node.js framework improves JSON security thanks to a security report Article-specific behavioural hunt — Node.js release fixes a critical HTTP security vulnerability Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Article-specific behavioural hunt — See Snyk and GitHub in action at GitHub Universe Article-specific behavioural hunt — Angular vs React: security bakeoff 2019 Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Article-specific behavioural hunt — JavaScript frameworks security report 2019 Article-specific behavioural hunt — A Snyk peek into Node.js and npm’s state of open source security report 2019 Article-specific behavioural hunt — Why npm lockfiles can be a security blindspot for injecting malicious modules Article-specific behavioural hunt — Sequelize ORM npm library found vulnerable to SQL Injection attacks Article-specific behavioural hunt — Mastering Node.js version management and npm registry sources like a pro Article-specific behavioural hunt — A year-old dormant malicious remote code execution vulnerability discovered in W Article-specific behavioural hunt — Staying ahead of security vulnerabilities with security patches Article-specific behavioural hunt — Snyk research team discovers severe prototype pollution security vulnerabilities Article-specific behavioural hunt — Serverless is great, but what about the security of my AWS Lambda functions and Article-specific behavioural hunt — npm passes the 1 millionth package milestone! What can we learn? Article-specific behavioural hunt — Scoring security vulnerabilities 101: Introducing CVSS for CVEs Article-specific behavioural hunt — A Denial of Service vulnerability discovered in the Axios JavaScript package - a Article-specific behavioural hunt — Add a SECURITY.md file to your Azure Repos Article-specific behavioural hunt — Azure Repos enriched with DevSecOps capabilities Article-specific behavioural hunt — The top two most popular Docker base images each have over 500 vulnerabilities Article-specific behavioural hunt — Take actions to improve security in your Docker images Article-specific behavioural hunt — After three years of silence, a new jQuery prototype pollution vulnerability eme Article-specific behavioural hunt — Securing Bitbucket Cloud with Snyk Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Article-specific behavioural hunt — Open source maintainers want to be secure, but 70% lack skills Article-specific behavioural hunt — Top ten most popular docker images each contain at least 30 vulnerabilities Article-specific behavioural hunt — Snyking in - Directory traversal vulnerability exploit in the st package Article-specific behavioural hunt — Scanning Docker images for key binaries - going beyond package managers Article-specific behavioural hunt — How even quick Node.js async functions can block the Event-Loop Article-specific behavioural hunt — Severe security vulnerability in Bower’s zip archive extraction Article-specific behavioural hunt — Snyk CLI drops support for Node.js 4 (Argon) Article-specific behavioural hunt — Snyk - Your Next Career Move! Article-specific behavioural hunt — 2018 Year in Review Article-specific behavioural hunt — Codefresh + Snyk = ship fast and securely Article-specific behavioural hunt — Faster & improved tests for JavaScript lockfile based projects Article-specific behavioural hunt — A post-mortem of the malicious event-stream backdoor Article-specific behavioural hunt — JVM Ecosystem report 2018 - About your Platform and Application Article-specific behavioural hunt — The most common vulnerabilities in Maven Central and npm Article-specific behavioural hunt — JavaScript and Node.js Security – The Common Pitfalls Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Article-specific behavioural hunt — Python Mocking 101: Fake it before you make it Article-specific behavioural hunt — Where do security patches come from? Article-specific behavioural hunt — npm Shrinkwrap reloaded: Locking npm Deps with Package-Lock and Yarn.Lock Article-specific behavioural hunt — Bower is dead, long live npm. And Yarn. And webpack. Article-specific behavioural hunt — 77% of 433,000 sites use vulnerable JavaScript libraries Article-specific behavioural hunt — Open source vulnerabilities tripped Equifax, how can you defend yourself? Article-specific behavioural hunt — Snyk and Atlassian, Sitting in a Tree Article-specific behavioural hunt — Bitbucket Server Integration in Beta Article-specific behavioural hunt — Serverless Security implications—from infra to OWASP Article-specific behavioural hunt — Maven support is here! Article-specific behavioural hunt — Continuously secure all apps with unlimited Snyk projects Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Article-specific behavioural hunt — Regular Expression Denial of Service (ReDoS) and Catastrophic Backtracking Article-specific behavioural hunt — Differences in version handling between RubyGems and npm Article-specific behavioural hunt — Launching serverless Snyk Article-specific behavioural hunt — Yarn is Micro Secure Article-specific behavioural hunt — Launching "The Secure Developer" Podcast Article-specific behavioural hunt — Threat modelling For Node.js applications Article-specific behavioural hunt — Using ES2015 Proxy for fun and profit Article-specific behavioural hunt — Enriching bitHound with Snyk Article-specific behavioural hunt — Architecting a Serverless web application in AWS Article-specific behavioural hunt — Mitigating ImageMagick vulnerabilities in Node.js Article-specific behavioural hunt — Free vulnerability testing and monitoring for public GitHub projects Article-specific behavioural hunt — Exploiting Buffer Article-specific behavioural hunt — Using Node.js event loop for timing attacks Article-specific behavioural hunt — Keeping your open source credentials closed Article-specific behavioural hunt — Launching SnykArticles citing this technique (558)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection art-91
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193
crit Don’t swing at everything art-213
crit [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimited input art-241
crit Begun, the Patch Wars have art-253
crit [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-enabled user art-283
crit ESET Threat Report H1 2026 art-312
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-365
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-426
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-477
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
med Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira art-516
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-623
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-782
med Creating SBOMs with the Snyk CLI art-1104
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1125
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1253
high Defense in Depth art-1415
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1506
med File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques art-1507
high Dependency injection in Python art-1540
crit Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133) art-1545
med Implementing TLS in Kubernetes art-1646
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
med Adding security to Nuxt 3 art-1881
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1897
crit Secure Python URL validation art-1960
high Building a secure API with gRPC art-2066
high The dangers of assert in Python art-2085
high Securing PHP containers art-2105
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2226
crit CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vulnerability art-2347
crit CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability art-2355
crit CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vulnerability art-2390
crit CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability art-2409
crit CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnerability art-2587
crit CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulnerability art-2613
crit CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Vulnerability art-2875
high Detect and prevent dependency confusion attacks on npm to maintain supply chain security art-3111
high Developer driven workflows: Dockerfile image scanning, prioritization, and remediation art-3213
med Python Poetry package manager and security integration with software composition analysis tool art-3283
high Node.js security: lessons from the Node.js Security Working Group in triaging vulnerabilities art-3290
crit Breaking out of message brokers art-3345
high After three years of silence, a new jQuery prototype pollution vulnerability emerges once again art-3564
high Snyk - Your Next Career Move! art-3598
high 2018 Year in Review art-3600
crit XSS Attacks: The Next Wave art-3664
high Maven support is here! art-3670
med Launching serverless Snyk art-3689
high Yarn is Micro Secure art-3691
med Enriching bitHound with Snyk art-3699
high Exploiting Buffer art-3710
med Launching Snyk art-3715