Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.002

T1204.002Malicious File

T1204.002 — Malicious File is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 529 detection use cases covering it and 575 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
529Use cases
575Articles
0Sub-techniques
1Tactic

Use cases covering this technique (529)

Email attachment opened from external sender Internal delivery · hunting DSP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD O365 SharePoint Malware Detection ESCU actions · alerting P O365 Threat Intelligence Suspicious File Detected ESCU actions · alerting P Batch File Write to System32 ESCU actions · alerting P Cisco NVM - Susp Script From Archive Triggering Network Activity ESCU actions · hunting P Drop IcedID License dat ESCU actions · hunting P Single Letter Process On Endpoint ESCU actions · alerting P Suspicious Process Executed From Container File ESCU actions · alerting P Windows Advanced Installer MSIX with AI_STUBS Execution ESCU actions · alerting P Windows AppX Deployment Full Trust Package Installation ESCU actions · hunting P Windows AppX Deployment Package Installation Success ESCU actions · hunting P Windows AppX Deployment Unsigned Package Installation ESCU actions · alerting P Windows Binary Execution from an Archive ESCU actions · hunting P Windows Default Cobalt Strike PowerShell Beacon ESCU actions · alerting P Windows Developer-Signed MSIX Package Installation ESCU actions · hunting P Windows EFI Volume Mount Attempt Via Mountvol ESCU actions · hunting P Windows Explorer.exe Spawning PowerShell or Cmd ESCU actions · hunting P Windows Explorer LNK Exploit Process Launch With Padding ESCU actions · alerting P Windows MSIX Package Interaction ESCU actions · hunting P Windows Mustang Panda USB Tool Execution ESCU actions · alerting P Windows NorthStar C2 Agent Execution ESCU actions · alerting P Windows PowerShell Script From WindowsApps Directory ESCU actions · alerting P Windows Suspect Process With Authentication Traffic ESCU actions · hunting P Windows Suspicious QEMU Execution ESCU actions · alerting P Windows Universal Data Link File Creation ESCU actions · hunting P Windows User Execution Malicious URL Shortcut File ESCU actions · hunting P Uncommon Processes On Endpoint ESCU actions · hunting P Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cisco warns of FMC static credential flaw exploited in zero-day attacks Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Bespoke install · hunting DSP Article-specific behavioural hunt — New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Bespoke install · hunting DSP Article-specific behavioural hunt — Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates Bespoke exploit · hunting DSP [LLM] Flying Eagle / SpyNote malicious APK download by hash or distribution domain Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Bespoke install · hunting DSP Article-specific behavioural hunt — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mirage Kitten targets Middle East and Africa region with new malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process Bespoke exploit · hunting DSP Article-specific behavioural hunt — Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Bespoke exploit · hunting DSP [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell Bespoke install · alerting DSΣPDDCS [LLM] Cruciferra known-sample SHA256 execution/write Bespoke exploit · hunting DSΣPDDCS [LLM] ISO-delivered signed RegSchdTask.exe executed from non-standard/removable path Bespoke delivery · hunting DSΣPDDCS [LLM] TELESHIM/MIXEDKEY/BINDCLOAK known-bad file hash execution Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executabl Bespoke exploit · hunting DSP [LLM] Browser-assembled SourTrade executable dropped with campaign-domain origin (MotW) Bespoke install · hunting DSPDDCS [LLM] DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7gfh-x38p-prh3: Velocity.js: Remote Code Execution via pr Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Bespoke install · hunting DSP Article-specific behavioural hunt — Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Doma Bespoke exploit · hunting DSP Article-specific behavioural hunt — Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Min Bespoke exploit · hunting DSP [LLM] TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Don’t swing at everything Bespoke exploit · hunting DSP [LLM] msaRAT: MSI impersonating Windows update executed from ProgramData Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Email threat landscape: Q2 2026 trends and insights Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-8fpg-xm3f-6cx3: Auth.js: Configuration errors can cause e Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7rqj-j65f-68wh: Auth.js: Email normalizer validates the a Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-p63j-vcc4-9vmv: @vitest/browser: Browser Mode provider co Bespoke exploit · hunting DSP Article-specific behavioural hunt — New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA rec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro Bespoke install · hunting DSP [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Bespoke install · hunting DSP [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Bespoke install · hunting DSP Article-specific behavioural hunt — The serpent’s tongue: Luring the Python out of its den Bespoke exploit · hunting DSP Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is a dependency firewall? Bespoke exploit · hunting DSP Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary Bespoke exploit · hunting DSP [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Bespoke exploit · hunting DSP Article-specific behavioural hunt — Winning 54% of the time Bespoke exploit · hunting DSP [LLM] Talos prevalent-malware SHA256 execution (UAT-7810 telemetry batch) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Bespoke exploit · hunting DSP Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Bespoke exploit · hunting DSP Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52831: Nuclio: Unsanitized cron trigger event headers Bespoke install · hunting DSP [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint Bespoke delivery · hunting DSΣP [LLM] Browser-dropped .bin password-protected archive (fake software crack lure) Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-27823: EGroupware has a Remote Code Execution Vulnera Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55500: 9routers has Exposure of Sensitive Information Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55615: Langroid: Neo4jChatAgent executes LLM-generate Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/ Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54769: Langroid: Sandbox Escape to Remote Code Execut Bespoke install · hunting DSP [LLM] ZDI-CAN-25373 (CVE-2025-9491) LNK spawning PowerShell to fetch BusySnake loader Bespoke delivery · alerting DSΣPDDCS Article-specific behavioural hunt — How We Added WebAuthn to a Browser-Based RDP Client Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54617: LaunchServer FileServerHandler has an unauthen Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52830: fast-mcp-telegram: Bearer token path traversal Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Bespoke exploit · hunting DSP Article-specific behavioural hunt — Catan and Mouse Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50027: mcp-memory-service: Missing Authentication on Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44939: Rancher vulnerable to command injection throug Bespoke install · hunting DSP [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Bespoke install · hunting DSP [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) Bespoke delivery · hunting DSΣPDDCS [LLM] Montana Empire phishing-kit ZIP + companion APK by SHA256 on endpoints Bespoke delivery · hunting DSΣPCS Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets Bespoke exploit · hunting DSP [LLM] cluw infostealer and malicious ClawHub skill payload hashes on macOS Bespoke install · hunting DSΣPCS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Bespoke exploit · hunting DSP Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting Bespoke exploit · hunting DSP [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Bespoke delivery · alerting DSΣPDDCS Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori Bespoke exploit · hunting DSP [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Re Bespoke install · hunting DSP [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Bespoke exploit · hunting DSP Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory Bespoke exploit · hunting DSP [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Reposito Bespoke install · hunting DSP [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Dev Machine Guard Now Supports Linux Bespoke install · hunting DSP Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Bespoke exploit · hunting DSP Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com Bespoke exploit · hunting DSP [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Bespoke exploit · hunting DSP Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Bespoke exploit · hunting DSP Article-specific behavioural hunt — A rigged game: ScarCruft compromises gaming platform in a supply-chain attack Bespoke exploit · hunting DSP [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Bespoke exploit · hunting DSP Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Bespoke install · hunting DSP Article-specific behavioural hunt — Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentia Bespoke exploit · hunting DSP Article-specific behavioural hunt — Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud Bespoke exploit · hunting DSP [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — lightning PyPI Compromise: A Bun-Based Credential Stealer in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Someone published four versions of a fake "tanstack" package in 27 minutes to st Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Reme Bespoke exploit · hunting DSP Article-specific behavioural hunt — "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Bespoke exploit · hunting DSP Article-specific behavioural hunt — Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomini Bespoke exploit · hunting DSP Article-specific behavioural hunt — Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Wo Bespoke exploit · hunting DSP Article-specific behavioural hunt — GopherWhisper: A burrow full of malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Bespoke exploit · hunting DSP Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Bespoke exploit · hunting DSP Article-specific behavioural hunt — Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest np Bespoke exploit · hunting DSP Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw Bespoke exploit · hunting DSP Article-specific behavioural hunt — GlassWorm goes native: New Zig dropper infects every IDE on your machine Bespoke exploit · hunting DSP Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Bespoke exploit · hunting DSP Article-specific behavioural hunt — axios compromised on npm: maintainer account hijacked, RAT deployed Bespoke exploit · hunting DSP Article-specific behavioural hunt — litellm: Credential Stealer Hidden in PyPI Wheel Bespoke exploit · hunting DSP [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Bespoke install · alerting DS Article-specific behavioural hunt — Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Bespoke exploit · hunting DSP Article-specific behavioural hunt — Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup- Bespoke exploit · hunting DSP Article-specific behavioural hunt — bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Do Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wa Bespoke exploit · hunting DSP Article-specific behavioural hunt — ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Bespoke exploit · hunting DSP Article-specific behavioural hunt — xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning Bespoke install · hunting DSP Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Bespoke exploit · hunting DSP Article-specific behavioural hunt — TeamPCP deploys CanisterWorm on NPM following Trivy compromise Bespoke exploit · hunting DSP Article-specific behavioural hunt — fast-draft Open VSX Extension Compromised by BlokTrooper Bespoke install · hunting DSP Article-specific behavioural hunt — Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard Bespoke exploit · hunting DSP Article-specific behavioural hunt — DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laund Bespoke install · hunting DSP [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process Bespoke install · alerting DSΣPDDCS [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Bespoke delivery · alerting DSPDD Article-specific behavioural hunt — kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package Bespoke exploit · hunting DSP Article-specific behavioural hunt — Sednit reloaded: Back in the trenches Bespoke exploit · hunting DSP Article-specific behavioural hunt — The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source Bespoke exploit · hunting DSP Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Bespoke exploit · hunting DSP Article-specific behavioural hunt — PlugX Meeting Invitation via MSBuild and GDATA Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploitability Isn’t the Answer. Breakability Is. Bespoke exploit · hunting DSP [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) Bespoke delivery · alerting DSΣPDDCS [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke weapon · hunting DSPDDCS Article-specific behavioural hunt — Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Stu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Co Bespoke exploit · hunting DSP Article-specific behavioural hunt — Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE- Bespoke exploit · hunting DSP Article-specific behavioural hunt — Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers Bespoke exploit · hunting DSP [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders Bespoke exploit · hunting DSP Article-specific behavioural hunt — PlushDaemon compromises network devices for adversary-in-the-middle attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Link Bespoke exploit · hunting DSP [LLM] Execution / write of ESET APT Q2-Q3 2025 known-bad SHA256 payload Bespoke install · hunting DSΣPDDCS [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Bespoke install · alerting DSΣP Article-specific behavioural hunt — Snyk Studio brings security scanning and automated fixes to Factory's Droids Bespoke install · hunting DSP Article-specific behavioural hunt — Phishing Campaign Leveraging the NPM Ecosystem Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Bespoke exploit · hunting DSP Article-specific behavioural hunt — Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm Supply Chain Attack via Open Source maintainer compromise Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cursor IDE Malware Extension Compromise in $500k Crypto Heist Bespoke exploit · hunting DSP [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) Bespoke exploit · alerting DSΣPDDCS [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Bespoke weapon · hunting DSΣPDDCS Article-specific behavioural hunt — Security Testing for Single-Page Applications (SPAs) Bespoke exploit · hunting DSP Article-specific behavioural hunt — CVE-2025-29927 Authorization Bypass in Next.js Middleware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings Bespoke exploit · hunting DSP Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Bespoke exploit · hunting DSP Article-specific behavioural hunt — Can Snyk Detect JWT Security Issues? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Solving Security Challenges with Snyk Code and Symbolic AI Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Creating SBOMs with the Snyk CLI Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ultralytics AI Pwn Request Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Lottie Player npm package compromised for crypto wallet theft Bespoke exploit · hunting DSP Article-specific behavioural hunt — The mysterious supply chain concern of string-width-cjs npm package Bespoke exploit · hunting DSP Article-specific behavioural hunt — Proactive AppSec continuous vulnerability management for developers and security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Promise queues and batching concurrent tasks in Deno Bespoke exploit · hunting DSP Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Bespoke install · hunting DSP Article-specific behavioural hunt — Want to avoid a data breach? Employ secrets detection Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Vulnerabilities in NodeJS C/C++ add-on extensions Bespoke exploit · hunting DSP Article-specific behavioural hunt — A denial of service Regex breaks FastAPI security Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 Dimensions of Python Static Analysis Bespoke exploit · hunting DSP Article-specific behavioural hunt — Polyfill supply chain attack embeds malware in JavaScript CDN assets Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Essential Node.js backend examples for developers in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 modern Node.js runtime features to start using in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-4978 — Justice AV Solutions (JAVS) Viewer Installer Embedded Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fastify plugins as building blocks for a backend Node.js API Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing broken access control in express Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Symmetric vs. asymmetric encryption: Practical Python examples Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building an npm package compatible with ESM and CJS in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nine Docker pro tips for Node.js developers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploiting HTTP/2 CONTINUATION frames for DoS attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-21338 — Microsoft Windows Kernel Exposed IOCTL with Insuffici Bespoke exploit · hunting DSP Article-specific behavioural hunt — 5 Node.js security code snippets every backend developer should know Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing server-side request forgery in Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing SQL injection attacks in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Bespoke exploit · hunting DSP Article-specific behavioural hunt — Build and deploy a Node.js security scanning API to Platformatic Cloud Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command injection in Python: examples and prevention Bespoke exploit · hunting DSP Article-specific behavioural hunt — Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Code injection in Python: examples and prevention Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring WebExtension security vulnerabilities in React Developer Tools and Vue Bespoke exploit · hunting DSP Article-specific behavioural hunt — File encryption in Python: An in-depth exploration of symmetric and asymmetric t Bespoke exploit · hunting DSP Article-specific behavioural hunt — Dependency injection in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — The art of conditional rendering: Tips and tricks for React and Next.js develope Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & Bespoke exploit · hunting DSP Article-specific behavioural hunt — Installing and managing Java on macOS Bespoke exploit · hunting DSP Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Bespoke install · hunting DSP Article-specific behavioural hunt — Modern VS Code extension development tutorial: Building a secure extension Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security implications of cross-origin resource sharing (CORS) in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — A guide to input validation with Spring Boot Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using JLink to create smaller Docker images for your Spring Boot Java applicatio Bespoke exploit · hunting DSP Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating DOM clobbering attacks in JavaScript Bespoke exploit · hunting DSP Article-specific behavioural hunt — Implementing TLS in Kubernetes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding and fixing insecure direct object references in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Swift deserialization security primer Bespoke install · hunting DSP Article-specific behavioural hunt — XS leaks: What they are and how to avoid them Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building a security-conscious CI/CD pipeline Bespoke exploit · hunting DSP Article-specific behavioural hunt — The importance of verifying webhook signatures Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Bespoke exploit · hunting DSP Article-specific behavioural hunt — The SecurityManager is getting removed in Java: What that means for you Bespoke install · hunting DSP Article-specific behavioural hunt — Ethical Hacking: Top Tools Bespoke exploit · hunting DSP Article-specific behavioural hunt — Setting up the Docker image scan GitHub Action Bespoke exploit · hunting DSP Article-specific behavioural hunt — Secure JavaScript URL validation Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security implications of HTTP response headers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing insecure deserialization in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Timing out synchronous functions with regex Bespoke exploit · hunting DSP Article-specific behavioural hunt — Avoiding mass assignment vulnerabilities in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — The Docker project turns 10! Looking back at a decade of containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Comparing Node.js web frameworks: Which is most secure? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating path traversal vulns in Java with Snyk Code Bespoke install · hunting DSP Article-specific behavioural hunt — Node.js multithreading with worker threads: pros and cons Bespoke exploit · hunting DSP Article-specific behavioural hunt — The security concerns of a JavaScript sandbox with the Node.js VM module Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Vue 3 components with Tailwind CSS Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows Denial-o Bespoke exploit · hunting DSP Article-specific behavioural hunt — CSPRNG: Random algorithms need security too! Bespoke install · hunting DSP Article-specific behavioural hunt — Adding security to Nuxt 3 Bespoke exploit · hunting DSP [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — You should be using HTTP Strict Transport Security (HSTS) headers in your Node.j Bespoke exploit · hunting DSP Article-specific behavioural hunt — 5 "no experience needed" tips for building secure applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Azure Bicep security fundamentals Bespoke exploit · hunting DSP Article-specific behavioural hunt — Dependency injection in JavaScript Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Treasure Trove Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Moongoose Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: File Explorer Bespoke exploit · hunting DSP Article-specific behavioural hunt — NPM security: preventing supply chain attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Secure Python URL validation Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ruby on Rails Docker for local development environment Bespoke exploit · hunting DSP Article-specific behavioural hunt — New OpenSSL critical vulnerability: What you need to know Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js multithreading with worker threads series: worker_threads tutorial Bespoke exploit · hunting DSP Article-specific behavioural hunt — Improving code quality with linting in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Choosing the best Node.js Docker image Bespoke exploit · hunting DSP Article-specific behavioural hunt — The npm faker package and the unexpected demise of open source libraries Bespoke exploit · hunting DSP Article-specific behavioural hunt — Solve Hack the Box and other CTF challenges with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building a secure API with gRPC Bespoke exploit · hunting DSP Article-specific behavioural hunt — Rediscovering argument injection when using VCS tools — git and mercurial Bespoke exploit · hunting DSP Article-specific behavioural hunt — The dangers of assert in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ruby gem installations can expose you to lockfile injection attacks Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk finds PyPi malware that steals Discord and Roblox credential and payment in Bespoke exploit · hunting DSP Article-specific behavioural hunt — Controlling your server with a reverse shell attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing PHP containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Slidev 101: Coding presentations with Markdown Bespoke exploit · hunting DSP Article-specific behavioural hunt — Safer together: Snyk and CISPA collaborate for the greater good Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerabil Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — 3 Jedi-inspired lessons to level up your JavaScript security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Docker images in Kubernetes Bespoke install · hunting DSP Article-specific behavioural hunt — Targeted npm dependency confusion attack caught red-handed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Generating fake security data with Python and faker-security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Modernizing SAST rules maintenance to catch vulnerabilities faster Bespoke exploit · hunting DSP Article-specific behavioural hunt — Improving GraphQL security with static analysis and Snyk Code Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vul Bespoke exploit · hunting DSP Article-specific behavioural hunt — Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit Bespoke install · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution V Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring 3 types of directory traversal vulnerabilities in C/C++ Bespoke install · hunting DSP Article-specific behavioural hunt — Building a secure GraphQL API with Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2011-2005 — Microsoft Ancillary Function Driver (afd.sys) Improper Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow V Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2014-6332 — Microsoft Windows Object Linking & Embedding (OLE) Aut Bespoke exploit · hunting DSP Article-specific behavioural hunt — Alert: peacenotwar module sabotages npm developers in the node-ipc package to pr Bespoke exploit · hunting DSP Article-specific behavioural hunt — Build a software bill of materials (SBOM) for open source supply chain security Bespoke exploit · hunting DSP Article-specific behavioural hunt — "Dirty Pipe" Linux vulnerability and your containerized applications (CVE-2022-0 Bespoke install · hunting DSP Article-specific behavioural hunt — Celebrating amazing open source innovation from Ukraine Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnera Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerab Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-0640 — Adobe Reader and Acrobat Memory Corruption Vulnerabili Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulner Bespoke exploit · hunting DSP Article-specific behavioural hunt — Visibly invisible malicious Node.js packages: When configuration niche meets inv Bespoke exploit · hunting DSP Article-specific behavioural hunt — Join The Big Fix: a 24-hour livestream dedicated to fixing security vulnerabilit Bespoke exploit · hunting DSP Article-specific behavioural hunt — Case study: Python RCE vulnerability in Celery Bespoke install · hunting DSP Article-specific behavioural hunt — Automating Terraform security in Scalr deployments with Regula [Tutorial] Bespoke install · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Pulumi to automate the Snyk Kubernetes integration for containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-21315 — System Information Library for Node.JS Command Inject Bespoke exploit · hunting DSP Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source maintainer pulls the plug on npm packages colors and faker, now what Bespoke exploit · hunting DSP Article-specific behavioural hunt — Log4Shell in a nutshell (for non-developers & non-Java developers) Bespoke install · hunting DSP Article-specific behavioural hunt — Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17 Bespoke install · hunting DSP Article-specific behavioural hunt — Scanning ARM templates for misconfigurations with the Snyk CLI Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring extensions of dependency confusion attacks via npm package aliasing Bespoke exploit · hunting DSP Article-specific behavioural hunt — JavaScript type confusion: Bypassed input validation (and how to remediate) Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2020-0601 — Microsoft Windows CryptoAPI Spoofing Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cr Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk Code CLI support now in public beta Bespoke exploit · hunting DSP Article-specific behavioural hunt — A (soft) introduction to Python dependency management Bespoke exploit · hunting DSP Article-specific behavioural hunt — Detect and prevent dependency confusion attacks on npm to maintain supply chain Bespoke exploit · hunting DSP Article-specific behavioural hunt — The 8 best IntelliJ plugins for improving your coding experience Bespoke exploit · hunting DSP Article-specific behavioural hunt — Plugins to put Node.js application security and observability in your IDE Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Java container images using Jib Bespoke install · hunting DSP Article-specific behavioural hunt — Use Snyk security policies to prioritize fixes more efficiently Bespoke exploit · hunting DSP Article-specific behavioural hunt — Better Ruby Gemfile security: A step-by-step guide using Snyk Bespoke install · hunting DSP Article-specific behavioural hunt — Getting started with Snyk for secure Python development Bespoke exploit · hunting DSP Article-specific behavioural hunt — Four steps for hardening Amazon EKS security Bespoke install · hunting DSP Article-specific behavioural hunt — Managing Node.js Docker images in GitHub Packages using GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk takes on responsibility for Node.js ecosystem vulnerability disclosure prog Bespoke exploit · hunting DSP Article-specific behavioural hunt — SuiteCRM: PHAR deserialization vulnerability to code execution Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why developer-first SAST tools are the future of code security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Docker Hub authentication: Is 2021 the year you enable 2FA on Docker Hub? Bespoke exploit · hunting DSP Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Bespoke exploit · hunting DSP Article-specific behavioural hunt — AWS vulnerability scanning using the Snyk integration Bespoke exploit · hunting DSP Article-specific behavioural hunt — What makes Verdaccio a successful project? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Docker for Node.js developers: 5 things you need to know not to fail your securi Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is typosquatting and how typosquatting attacks are responsible for maliciou Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing your Kubernetes application development with Snyk and Tilt Bespoke exploit · hunting DSP Article-specific behavioural hunt — What makes Fastify a successful project? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Kernel privilege escalation: how Kubernetes container isolation impacts privileg Bespoke install · hunting DSP Article-specific behavioural hunt — 10 git aliases for a faster and productive git workflow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command injection: how it works, what are the risks, and how to prevent it Bespoke exploit · hunting DSP Article-specific behavioural hunt — DevSecOps tools for open source projects in JavaScript and Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Container image formats under the hood Bespoke exploit · hunting DSP Article-specific behavioural hunt — RPM Package Manager: RPM package security scanning with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Bespoke exploit · hunting DSP Article-specific behavioural hunt — From zero to security hero: test your GitHub projects for known vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub Actions to securely publish npm packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js security: lessons from the Node.js Security Working Group in triaging vu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Privileged Docker containers—do you really need them? Bespoke install · hunting DSP Article-specific behavioural hunt — Regular Expression Denial of Service (REDoS) in UAParser.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — SourMint malicious SDK research write up Bespoke install · hunting DSP Article-specific behavioural hunt — JHipster security scanning with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — SourMint malicious SDK research writeup Bespoke install · hunting DSP Article-specific behavioural hunt — Breaking out of message brokers Bespoke install · hunting DSP Article-specific behavioural hunt — Demystifying HTTP request smuggling Bespoke exploit · hunting DSP Article-specific behavioural hunt — Regular Expression Denial-of-Service in websocket-extensions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Checking Helm Charts for security misconfigurations Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why do organizations trust Snyk to win the open source security battle? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Snyk to implement end-to-end DevSecOps on Microsoft Azure Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why did is-promise happen and what can we learn from it Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk vulnerability disclosure program: what’s going on behind the scenes? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn 2 plugins - an introduction Bespoke exploit · hunting DSP Article-specific behavioural hunt — VS Code extension: building auto CI/CD with GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn 2 — the future of package managers for JavaScript? Bespoke exploit · hunting DSP Article-specific behavioural hunt — March in review: State of Open Source Security survey, All.The.Talks virtual con Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using UBI images to minimize container vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Creating an automated cloud infrastructure testing tool with Terraform and PyTes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring the minimist prototype pollution security vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — The State of Open Source Security Survey - 2020 Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is a backdoor? Let’s build one with Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fastify Node.js framework improves JSON security thanks to a security report Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js release fixes a critical HTTP security vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Bespoke exploit · hunting DSP Article-specific behavioural hunt — See Snyk and GitHub in action at GitHub Universe Bespoke exploit · hunting DSP Article-specific behavioural hunt — Angular vs React: the security risk of indirect dependencies Bespoke exploit · hunting DSP Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — JavaScript frameworks security report 2019 Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Snyk peek into Node.js and npm’s state of open source security report 2019 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why npm lockfiles can be a security blindspot for injecting malicious modules Bespoke install · hunting DSP Article-specific behavioural hunt — Sequelize ORM npm library found vulnerable to SQL Injection attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastering Node.js version management and npm registry sources like a pro Bespoke exploit · hunting DSP Article-specific behavioural hunt — A year-old dormant malicious remote code execution vulnerability discovered in W Bespoke install · hunting DSP Article-specific behavioural hunt — Staying ahead of security vulnerabilities with security patches Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk research team discovers severe prototype pollution security vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Serverless is great, but what about the security of my AWS Lambda functions and Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm passes the 1 millionth package milestone! What can we learn? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Scoring security vulnerabilities 101: Introducing CVSS for CVEs Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Denial of Service vulnerability discovered in the Axios JavaScript package - a Bespoke exploit · hunting DSP Article-specific behavioural hunt — Add a SECURITY.md file to your Azure Repos Bespoke exploit · hunting DSP Article-specific behavioural hunt — Azure Repos enriched with DevSecOps capabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — The top two most popular Docker base images each have over 500 vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Take actions to improve security in your Docker images Bespoke exploit · hunting DSP Article-specific behavioural hunt — After three years of silence, a new jQuery prototype pollution vulnerability eme Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing Bitbucket Cloud with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Top ten most popular docker images each contain at least 30 vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source maintainers want to be secure, but 70% lack skills Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyking in - Directory traversal vulnerability exploit in the st package Bespoke install · hunting DSP Article-specific behavioural hunt — Scanning Docker images for key binaries - going beyond package managers Bespoke exploit · hunting DSP Article-specific behavioural hunt — How even quick Node.js async functions can block the Event-Loop Bespoke exploit · hunting DSP Article-specific behavioural hunt — Severe security vulnerability in Bower’s zip archive extraction Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk CLI drops support for Node.js 4 (Argon) Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk - Your Next Career Move! Bespoke exploit · hunting DSP Article-specific behavioural hunt — 2018 Year in Review Bespoke exploit · hunting DSP Article-specific behavioural hunt — Codefresh + Snyk = ship fast and securely Bespoke exploit · hunting DSP Article-specific behavioural hunt — Faster & improved tests for JavaScript lockfile based projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — A post-mortem of the malicious event-stream backdoor Bespoke exploit · hunting DSP Article-specific behavioural hunt — The most common vulnerabilities in Maven Central and npm Bespoke install · hunting DSP Article-specific behavioural hunt — JavaScript and Node.js Security – The Common Pitfalls Bespoke exploit · hunting DSP Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Bespoke exploit · hunting DSP Article-specific behavioural hunt — Python Mocking 101: Fake it before you make it Bespoke exploit · hunting DSP Article-specific behavioural hunt — Where do security patches come from? Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm Shrinkwrap reloaded: Locking npm Deps with Package-Lock and Yarn.Lock Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bower is dead, long live npm. And Yarn. And webpack. Bespoke exploit · hunting DSP Article-specific behavioural hunt — 77% of 433,000 sites use vulnerable JavaScript libraries Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source vulnerabilities tripped Equifax, how can you defend yourself? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk and Atlassian, Sitting in a Tree Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bitbucket Server Integration in Beta Bespoke exploit · hunting DSP Article-specific behavioural hunt — Serverless Security implications—from infra to OWASP Bespoke exploit · hunting DSP Article-specific behavioural hunt — Maven support is here! Bespoke exploit · hunting DSP Article-specific behavioural hunt — Continuously secure all apps with unlimited Snyk projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Regular Expression Denial of Service (ReDoS) and Catastrophic Backtracking Bespoke exploit · hunting DSP Article-specific behavioural hunt — Differences in version handling between RubyGems and npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching serverless Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn is Micro Secure Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching "The Secure Developer" Podcast Bespoke exploit · hunting DSP Article-specific behavioural hunt — Threat modelling For Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using ES2015 Proxy for fun and profit Bespoke install · hunting DSP Article-specific behavioural hunt — Enriching bitHound with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Architecting a Serverless web application in AWS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating ImageMagick vulnerabilities in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Free vulnerability testing and monitoring for public GitHub projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploiting Buffer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Node.js event loop for timing attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Keeping your open source credentials closed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching Snyk Bespoke exploit · hunting DSP

Articles citing this technique (575)