Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.002

T1204.002Malicious File

T1204.002 — Malicious File is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 531 detection use cases covering it and 558 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
531Use cases
558Articles
0Sub-techniques
1Tactic

Use cases covering this technique (531)

Email attachment opened from external sender Internal delivery · hunting DSP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD O365 SharePoint Malware Detection ESCU actions · alerting P O365 Threat Intelligence Suspicious File Detected ESCU actions · alerting P Batch File Write to System32 ESCU actions · hunting P Cisco NVM - Susp Script From Archive Triggering Network Activity ESCU actions · hunting P Drop IcedID License dat ESCU actions · hunting P Linux Ghostscript Exploitation ESCU actions · alerting P Single Letter Process On Endpoint ESCU actions · alerting P Suspicious Process Executed From Container File ESCU actions · alerting P Windows Advanced Installer MSIX with AI_STUBS Execution ESCU actions · alerting P Windows AppX Deployment Full Trust Package Installation ESCU actions · hunting P Windows AppX Deployment Package Installation Success ESCU actions · hunting P Windows AppX Deployment Unsigned Package Installation ESCU actions · alerting P Windows Binary Execution from an Archive ESCU actions · hunting P Windows Default Cobalt Strike PowerShell Beacon ESCU actions · alerting P Windows Developer-Signed MSIX Package Installation ESCU actions · hunting P Windows EFI Volume Mount Attempt Via Mountvol ESCU actions · hunting P Windows Explorer.exe Spawning PowerShell or Cmd ESCU actions · hunting P Windows Explorer LNK Exploit Process Launch With Padding ESCU actions · alerting P Windows MSIX Package Interaction ESCU actions · hunting P Windows Mustang Panda USB Tool Execution ESCU actions · alerting P Windows NorthStar C2 Agent Execution ESCU actions · alerting P Windows PowerShell Script From WindowsApps Directory ESCU actions · alerting P Windows Suspect Process With Authentication Traffic ESCU actions · hunting P Windows Suspicious QEMU Execution ESCU actions · alerting P Windows Universal Data Link File Creation ESCU actions · hunting P Windows User Execution Malicious URL Shortcut File ESCU actions · hunting P Uncommon Processes On Endpoint ESCU actions · hunting P Article-specific behavioural hunt — Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-m5w8-4gq2-6f8x: vm2: NodeVM `builtin: ['*']` exposes `os` Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47686: VM2 has Missing Error.cause Sanitization that Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55158: conflibot vulnerable to command injection via Bespoke exploit · hunting DSP Article-specific behavioural hunt — Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Pro Bespoke exploit · hunting DSP Article-specific behavioural hunt — Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Bespoke exploit · hunting DSP Article-specific behavioural hunt — ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-dro Bespoke exploit · hunting DSP Article-specific behavioural hunt — Top enterprise SCA tools in 2026 Bespoke exploit · hunting DSP [LLM] Execution/write of published Sable Squirrel malware sample (SHA256 0464caa1...) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Window Bespoke exploit · hunting DSP Article-specific behavioural hunt — Curiouser and Curiouser Bespoke exploit · hunting DSP [LLM] PATCHCORD delivery via TMS_AfghanTelecom.exe Inno Setup installer / known hashes Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — Dissecting the JWR phishing framework Bespoke exploit · hunting DSP Article-specific behavioural hunt — Armored Likho expands its cyber-espionage toolkit Bespoke exploit · hunting DSP [LLM] Armored Likho Tauri donation-app dropper C2 (orderapiserver.info catalog endpoints) Bespoke delivery · alerting DSΣPDDCS Article-specific behavioural hunt — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Bespoke exploit · hunting DSP [LLM] Trojanized Enveil 'SecurityPDF' viewer downloaded from fake sites and dropping Troy loader (new.exe) Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You H Bespoke install · hunting DSP Article-specific behavioural hunt — ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Acce Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Att Bespoke exploit · hunting DSP Article-specific behavioural hunt — Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channe Bespoke exploit · hunting DSP Article-specific behavioural hunt — Kimwolf v7: An Evolution of the Kimwolf Botnet Bespoke install · hunting DSP Article-specific behavioural hunt — DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized rec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptograph Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why metaphor may dictate your security strategy Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication Bypass via Path Traver Bespoke exploit · hunting DSP Article-specific behavioural hunt — ChainDrop supply chain compromise: Anatomy of a self-propagating worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70477: Flowise: CSV Agent Prompt Injection Remote Cod Bespoke exploit · hunting DSP [LLM] mshta.exe launched with inline http/https URL argument Bespoke delivery · alerting DSΣPDDCS [LLM] RunMRU registry write launching mshta / URL / PowerShell (ClickFix-style user persistence) Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent csvFile data URI bas Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph b Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69259: Flowise RCE via SQLite Record Manager Node Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via P Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sandbox Escape in exec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69251: Flowise RCE via TypeORM DataSource Bespoke exploit · hunting DSP Article-specific behavioural hunt — Keyv and friends compromised in active Shai-Hulud supply chain attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69240: Sequelize: SQL Injection (Oracle DB) Bespoke exploit · hunting DSP Article-specific behavioural hunt — An analysis of incidents at Brazilian educational institutions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52887: NocoBase: SQL injection in /api/myInAppChannel Bespoke install · hunting DSP Article-specific behavioural hunt — Anthropic's Fever Dream: Claude's package that stole real keys Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfus Bespoke exploit · hunting DSP Article-specific behavioural hunt — You were onto something with “It’s the Climb,” Miley Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67426: Flyto2 Core: Unauthenticated flyto-verificatio Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67429: Flyto2 Core: Arbitrary file write via image.do Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Bespoke install · hunting DSP Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in N Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73649: Velocity.js: Remote Code Execution via propert Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Bespoke install · hunting DSP Article-specific behavioural hunt — Don’t swing at everything Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73421: Auth.js: Configuration errors can cause existe Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73420: Auth.js: Email normalizer validates the addres Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73653: @vitest/browser: Browser Mode provider command Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro Bespoke install · hunting DSP [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised C Bespoke exploit · hunting DSP Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Bespoke install · hunting DSP [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Bespoke install · hunting DSP Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is a dependency firewall? Bespoke exploit · hunting DSP Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary Bespoke exploit · hunting DSP [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Bespoke exploit · hunting DSP Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Bespoke exploit · hunting DSP Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Bespoke install · hunting DSP [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint Bespoke delivery · hunting DSΣP [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Bespoke install · hunting DSP [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets Bespoke exploit · hunting DSP [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Bespoke exploit · hunting DSP Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting Bespoke exploit · hunting DSP [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Bespoke delivery · alerting DSΣPDDCS Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori Bespoke exploit · hunting DSP [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Re Bespoke install · hunting DSP [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Bespoke exploit · hunting DSP Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory Bespoke exploit · hunting DSP [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Reposito Bespoke install · hunting DSP [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Dev Machine Guard Now Supports Linux Bespoke install · hunting DSP Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Bespoke exploit · hunting DSP Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com Bespoke exploit · hunting DSP [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Bespoke exploit · hunting DSP Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Bespoke exploit · hunting DSP Article-specific behavioural hunt — A rigged game: ScarCruft compromises gaming platform in a supply-chain attack Bespoke exploit · hunting DSP [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Bespoke exploit · hunting DSP Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Bespoke install · hunting DSP Article-specific behavioural hunt — Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentia Bespoke exploit · hunting DSP Article-specific behavioural hunt — Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud Bespoke exploit · hunting DSP [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — lightning PyPI Compromise: A Bun-Based Credential Stealer in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Someone published four versions of a fake "tanstack" package in 27 minutes to st Bespoke exploit · hunting DSP Article-specific behavioural hunt — "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Reme Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Bespoke exploit · hunting DSP Article-specific behavioural hunt — Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomini Bespoke exploit · hunting DSP Article-specific behavioural hunt — Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Wo Bespoke exploit · hunting DSP Article-specific behavioural hunt — GopherWhisper: A burrow full of malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Bespoke exploit · hunting DSP Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Bespoke exploit · hunting DSP Article-specific behavioural hunt — Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest np Bespoke exploit · hunting DSP Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw Bespoke exploit · hunting DSP Article-specific behavioural hunt — GlassWorm goes native: New Zig dropper infects every IDE on your machine Bespoke exploit · hunting DSP Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Bespoke exploit · hunting DSP Article-specific behavioural hunt — litellm: Credential Stealer Hidden in PyPI Wheel Bespoke exploit · hunting DSP [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Bespoke install · alerting DS Article-specific behavioural hunt — Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Bespoke exploit · hunting DSP Article-specific behavioural hunt — Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup- Bespoke exploit · hunting DSP Article-specific behavioural hunt — bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Do Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wa Bespoke exploit · hunting DSP Article-specific behavioural hunt — ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Bespoke exploit · hunting DSP Article-specific behavioural hunt — xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning Bespoke install · hunting DSP Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard Bespoke exploit · hunting DSP Article-specific behavioural hunt — DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laund Bespoke install · hunting DSP [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process Bespoke install · alerting DSΣPDDCS [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Bespoke delivery · alerting DSPDD Article-specific behavioural hunt — kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package Bespoke exploit · hunting DSP Article-specific behavioural hunt — Sednit reloaded: Back in the trenches Bespoke exploit · hunting DSP Article-specific behavioural hunt — The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source Bespoke exploit · hunting DSP Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Bespoke exploit · hunting DSP Article-specific behavioural hunt — PlugX Meeting Invitation via MSBuild and GDATA Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploitability Isn’t the Answer. Breakability Is. Bespoke exploit · hunting DSP [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) Bespoke delivery · alerting DSΣPDDCS [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke weapon · hunting DSPDDCS Article-specific behavioural hunt — Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Stu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Co Bespoke exploit · hunting DSP Article-specific behavioural hunt — Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE- Bespoke exploit · hunting DSP Article-specific behavioural hunt — Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers Bespoke exploit · hunting DSP [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders Bespoke exploit · hunting DSP Article-specific behavioural hunt — PlushDaemon compromises network devices for adversary-in-the-middle attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Link Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk Studio brings security scanning and automated fixes to Factory's Droids Bespoke install · hunting DSP Article-specific behavioural hunt — Phishing Campaign Leveraging the NPM Ecosystem Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Bespoke exploit · hunting DSP Article-specific behavioural hunt — Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm Supply Chain Attack via Open Source maintainer compromise Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cursor IDE Malware Extension Compromise in $500k Crypto Heist Bespoke exploit · hunting DSP [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) Bespoke exploit · alerting DSΣPDDCS [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Bespoke weapon · hunting DSΣPDDCS Article-specific behavioural hunt — Security Testing for Single-Page Applications (SPAs) Bespoke exploit · hunting DSP Article-specific behavioural hunt — CVE-2025-29927 Authorization Bypass in Next.js Middleware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings Bespoke exploit · hunting DSP Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Bespoke exploit · hunting DSP Article-specific behavioural hunt — Can Snyk Detect JWT Security Issues? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Solving Security Challenges with Snyk Code and Symbolic AI Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Creating SBOMs with the Snyk CLI Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ultralytics AI Pwn Request Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Lottie Player npm package compromised for crypto wallet theft Bespoke exploit · hunting DSP Article-specific behavioural hunt — The mysterious supply chain concern of string-width-cjs npm package Bespoke exploit · hunting DSP Article-specific behavioural hunt — Proactive AppSec continuous vulnerability management for developers and security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Promise queues and batching concurrent tasks in Deno Bespoke exploit · hunting DSP Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Bespoke install · hunting DSP Article-specific behavioural hunt — Want to avoid a data breach? Employ secrets detection Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Vulnerabilities in NodeJS C/C++ add-on extensions Bespoke exploit · hunting DSP Article-specific behavioural hunt — A denial of service Regex breaks FastAPI security Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 Dimensions of Python Static Analysis Bespoke exploit · hunting DSP Article-specific behavioural hunt — Polyfill supply chain attack embeds malware in JavaScript CDN assets Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Essential Node.js backend examples for developers in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 modern Node.js runtime features to start using in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-4978 — Justice AV Solutions (JAVS) Viewer Installer Embedded Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fastify plugins as building blocks for a backend Node.js API Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing broken access control in express Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Symmetric vs. asymmetric encryption: Practical Python examples Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building an npm package compatible with ESM and CJS in 2024 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nine Docker pro tips for Node.js developers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploiting HTTP/2 CONTINUATION frames for DoS attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2024-21338 — Microsoft Windows Kernel Exposed IOCTL with Insuffici Bespoke exploit · hunting DSP Article-specific behavioural hunt — 5 Node.js security code snippets every backend developer should know Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing server-side request forgery in Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing SQL injection attacks in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Bespoke exploit · hunting DSP Article-specific behavioural hunt — Build and deploy a Node.js security scanning API to Platformatic Cloud Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command injection in Python: examples and prevention Bespoke exploit · hunting DSP Article-specific behavioural hunt — Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Code injection in Python: examples and prevention Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring WebExtension security vulnerabilities in React Developer Tools and Vue Bespoke exploit · hunting DSP Article-specific behavioural hunt — File encryption in Python: An in-depth exploration of symmetric and asymmetric t Bespoke exploit · hunting DSP Article-specific behavioural hunt — Dependency injection in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — The art of conditional rendering: Tips and tricks for React and Next.js develope Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & Bespoke exploit · hunting DSP Article-specific behavioural hunt — Installing and managing Java on macOS Bespoke exploit · hunting DSP Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Bespoke install · hunting DSP Article-specific behavioural hunt — Modern VS Code extension development tutorial: Building a secure extension Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security implications of cross-origin resource sharing (CORS) in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — A guide to input validation with Spring Boot Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using JLink to create smaller Docker images for your Spring Boot Java applicatio Bespoke exploit · hunting DSP Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating DOM clobbering attacks in JavaScript Bespoke exploit · hunting DSP Article-specific behavioural hunt — Implementing TLS in Kubernetes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding and fixing insecure direct object references in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Swift deserialization security primer Bespoke install · hunting DSP Article-specific behavioural hunt — XS leaks: What they are and how to avoid them Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building a security-conscious CI/CD pipeline Bespoke exploit · hunting DSP Article-specific behavioural hunt — The importance of verifying webhook signatures Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Bespoke exploit · hunting DSP Article-specific behavioural hunt — The SecurityManager is getting removed in Java: What that means for you Bespoke install · hunting DSP Article-specific behavioural hunt — Ethical Hacking: Top Tools Bespoke exploit · hunting DSP Article-specific behavioural hunt — Setting up the Docker image scan GitHub Action Bespoke exploit · hunting DSP Article-specific behavioural hunt — Secure JavaScript URL validation Bespoke exploit · hunting DSP Article-specific behavioural hunt — Security implications of HTTP response headers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Preventing insecure deserialization in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Timing out synchronous functions with regex Bespoke exploit · hunting DSP Article-specific behavioural hunt — Avoiding mass assignment vulnerabilities in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — The Docker project turns 10! Looking back at a decade of containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Comparing Node.js web frameworks: Which is most secure? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating path traversal vulns in Java with Snyk Code Bespoke install · hunting DSP Article-specific behavioural hunt — Node.js multithreading with worker threads: pros and cons Bespoke exploit · hunting DSP Article-specific behavioural hunt — The security concerns of a JavaScript sandbox with the Node.js VM module Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Vue 3 components with Tailwind CSS Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows Denial-o Bespoke exploit · hunting DSP Article-specific behavioural hunt — CSPRNG: Random algorithms need security too! Bespoke install · hunting DSP Article-specific behavioural hunt — Adding security to Nuxt 3 Bespoke exploit · hunting DSP [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — You should be using HTTP Strict Transport Security (HSTS) headers in your Node.j Bespoke exploit · hunting DSP Article-specific behavioural hunt — 5 "no experience needed" tips for building secure applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Azure Bicep security fundamentals Bespoke exploit · hunting DSP Article-specific behavioural hunt — Dependency injection in JavaScript Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Treasure Trove Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Moongoose Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: File Explorer Bespoke exploit · hunting DSP Article-specific behavioural hunt — NPM security: preventing supply chain attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Secure Python URL validation Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ruby on Rails Docker for local development environment Bespoke exploit · hunting DSP Article-specific behavioural hunt — New OpenSSL critical vulnerability: What you need to know Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js multithreading with worker threads series: worker_threads tutorial Bespoke exploit · hunting DSP Article-specific behavioural hunt — Improving code quality with linting in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Choosing the best Node.js Docker image Bespoke exploit · hunting DSP Article-specific behavioural hunt — The npm faker package and the unexpected demise of open source libraries Bespoke exploit · hunting DSP Article-specific behavioural hunt — Solve Hack the Box and other CTF challenges with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building a secure API with gRPC Bespoke exploit · hunting DSP Article-specific behavioural hunt — Rediscovering argument injection when using VCS tools — git and mercurial Bespoke exploit · hunting DSP Article-specific behavioural hunt — The dangers of assert in Python Bespoke exploit · hunting DSP Article-specific behavioural hunt — Ruby gem installations can expose you to lockfile injection attacks Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk finds PyPi malware that steals Discord and Roblox credential and payment in Bespoke exploit · hunting DSP Article-specific behavioural hunt — Controlling your server with a reverse shell attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing PHP containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — Slidev 101: Coding presentations with Markdown Bespoke exploit · hunting DSP Article-specific behavioural hunt — Safer together: Snyk and CISPA collaborate for the greater good Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerabil Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — 3 Jedi-inspired lessons to level up your JavaScript security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Docker images in Kubernetes Bespoke install · hunting DSP Article-specific behavioural hunt — Targeted npm dependency confusion attack caught red-handed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Generating fake security data with Python and faker-security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Modernizing SAST rules maintenance to catch vulnerabilities faster Bespoke exploit · hunting DSP Article-specific behavioural hunt — Improving GraphQL security with static analysis and Snyk Code Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vul Bespoke exploit · hunting DSP Article-specific behavioural hunt — Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit Bespoke install · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution V Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring 3 types of directory traversal vulnerabilities in C/C++ Bespoke install · hunting DSP Article-specific behavioural hunt — Building a secure GraphQL API with Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vu Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2011-2005 — Microsoft Ancillary Function Driver (afd.sys) Improper Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow V Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2014-6332 — Microsoft Windows Object Linking & Embedding (OLE) Aut Bespoke exploit · hunting DSP Article-specific behavioural hunt — Alert: peacenotwar module sabotages npm developers in the node-ipc package to pr Bespoke exploit · hunting DSP Article-specific behavioural hunt — Build a software bill of materials (SBOM) for open source supply chain security Bespoke exploit · hunting DSP Article-specific behavioural hunt — "Dirty Pipe" Linux vulnerability and your containerized applications (CVE-2022-0 Bespoke install · hunting DSP Article-specific behavioural hunt — Celebrating amazing open source innovation from Ukraine Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnera Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerab Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2013-0640 — Adobe Reader and Acrobat Memory Corruption Vulnerabili Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulner Bespoke exploit · hunting DSP Article-specific behavioural hunt — Visibly invisible malicious Node.js packages: When configuration niche meets inv Bespoke exploit · hunting DSP Article-specific behavioural hunt — Join The Big Fix: a 24-hour livestream dedicated to fixing security vulnerabilit Bespoke exploit · hunting DSP Article-specific behavioural hunt — Case study: Python RCE vulnerability in Celery Bespoke install · hunting DSP Article-specific behavioural hunt — Automating Terraform security in Scalr deployments with Regula [Tutorial] Bespoke install · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Pulumi to automate the Snyk Kubernetes integration for containers Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2021-21315 — System Information Library for Node.JS Command Inject Bespoke exploit · hunting DSP Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source maintainer pulls the plug on npm packages colors and faker, now what Bespoke exploit · hunting DSP Article-specific behavioural hunt — Log4Shell in a nutshell (for non-developers & non-Java developers) Bespoke install · hunting DSP Article-specific behavioural hunt — Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17 Bespoke install · hunting DSP Article-specific behavioural hunt — Scanning ARM templates for misconfigurations with the Snyk CLI Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring extensions of dependency confusion attacks via npm package aliasing Bespoke exploit · hunting DSP Article-specific behavioural hunt — JavaScript type confusion: Bypassed input validation (and how to remediate) Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2020-0601 — Microsoft Windows CryptoAPI Spoofing Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cr Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk Code CLI support now in public beta Bespoke exploit · hunting DSP Article-specific behavioural hunt — A (soft) introduction to Python dependency management Bespoke exploit · hunting DSP Article-specific behavioural hunt — Detect and prevent dependency confusion attacks on npm to maintain supply chain Bespoke exploit · hunting DSP Article-specific behavioural hunt — The 8 best IntelliJ plugins for improving your coding experience Bespoke exploit · hunting DSP Article-specific behavioural hunt — Plugins to put Node.js application security and observability in your IDE Bespoke exploit · hunting DSP Article-specific behavioural hunt — Building Java container images using Jib Bespoke install · hunting DSP Article-specific behavioural hunt — Use Snyk security policies to prioritize fixes more efficiently Bespoke exploit · hunting DSP Article-specific behavioural hunt — Better Ruby Gemfile security: A step-by-step guide using Snyk Bespoke install · hunting DSP Article-specific behavioural hunt — Getting started with Snyk for secure Python development Bespoke exploit · hunting DSP Article-specific behavioural hunt — Four steps for hardening Amazon EKS security Bespoke install · hunting DSP Article-specific behavioural hunt — Managing Node.js Docker images in GitHub Packages using GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk takes on responsibility for Node.js ecosystem vulnerability disclosure prog Bespoke exploit · hunting DSP Article-specific behavioural hunt — SuiteCRM: PHAR deserialization vulnerability to code execution Bespoke install · hunting DSP Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why developer-first SAST tools are the future of code security Bespoke exploit · hunting DSP Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Docker Hub authentication: Is 2021 the year you enable 2FA on Docker Hub? Bespoke exploit · hunting DSP Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Bespoke exploit · hunting DSP Article-specific behavioural hunt — AWS vulnerability scanning using the Snyk integration Bespoke exploit · hunting DSP Article-specific behavioural hunt — What makes Verdaccio a successful project? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Docker for Node.js developers: 5 things you need to know not to fail your securi Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is typosquatting and how typosquatting attacks are responsible for maliciou Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing your Kubernetes application development with Snyk and Tilt Bespoke exploit · hunting DSP Article-specific behavioural hunt — What makes Fastify a successful project? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Kernel privilege escalation: how Kubernetes container isolation impacts privileg Bespoke install · hunting DSP Article-specific behavioural hunt — 10 git aliases for a faster and productive git workflow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command injection: how it works, what are the risks, and how to prevent it Bespoke exploit · hunting DSP Article-specific behavioural hunt — DevSecOps tools for open source projects in JavaScript and Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Container image formats under the hood Bespoke exploit · hunting DSP Article-specific behavioural hunt — RPM Package Manager: RPM package security scanning with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Bespoke exploit · hunting DSP Article-specific behavioural hunt — From zero to security hero: test your GitHub projects for known vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub Actions to securely publish npm packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js security: lessons from the Node.js Security Working Group in triaging vu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Privileged Docker containers—do you really need them? Bespoke install · hunting DSP Article-specific behavioural hunt — Regular Expression Denial of Service (REDoS) in UAParser.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — SourMint malicious SDK research write up Bespoke install · hunting DSP Article-specific behavioural hunt — JHipster security scanning with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — SourMint malicious SDK research writeup Bespoke install · hunting DSP Article-specific behavioural hunt — Breaking out of message brokers Bespoke install · hunting DSP Article-specific behavioural hunt — Demystifying HTTP request smuggling Bespoke exploit · hunting DSP Article-specific behavioural hunt — Regular Expression Denial-of-Service in websocket-extensions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Checking Helm Charts for security misconfigurations Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why do organizations trust Snyk to win the open source security battle? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Snyk to implement end-to-end DevSecOps on Microsoft Azure Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why did is-promise happen and what can we learn from it Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk vulnerability disclosure program: what’s going on behind the scenes? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn 2 plugins - an introduction Bespoke exploit · hunting DSP Article-specific behavioural hunt — VS Code extension: building auto CI/CD with GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn 2 — the future of package managers for JavaScript? Bespoke exploit · hunting DSP Article-specific behavioural hunt — March in review: State of Open Source Security survey, All.The.Talks virtual con Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using UBI images to minimize container vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Creating an automated cloud infrastructure testing tool with Terraform and PyTes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploring the minimist prototype pollution security vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — The State of Open Source Security Survey - 2020 Bespoke exploit · hunting DSP Article-specific behavioural hunt — What is a backdoor? Let’s build one with Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Fastify Node.js framework improves JSON security thanks to a security report Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node.js release fixes a critical HTTP security vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Bespoke exploit · hunting DSP Article-specific behavioural hunt — See Snyk and GitHub in action at GitHub Universe Bespoke exploit · hunting DSP Article-specific behavioural hunt — Angular vs React: security bakeoff 2019 Bespoke exploit · hunting DSP Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — JavaScript frameworks security report 2019 Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Snyk peek into Node.js and npm’s state of open source security report 2019 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why npm lockfiles can be a security blindspot for injecting malicious modules Bespoke install · hunting DSP Article-specific behavioural hunt — Sequelize ORM npm library found vulnerable to SQL Injection attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastering Node.js version management and npm registry sources like a pro Bespoke exploit · hunting DSP Article-specific behavioural hunt — A year-old dormant malicious remote code execution vulnerability discovered in W Bespoke install · hunting DSP Article-specific behavioural hunt — Staying ahead of security vulnerabilities with security patches Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk research team discovers severe prototype pollution security vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Serverless is great, but what about the security of my AWS Lambda functions and Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm passes the 1 millionth package milestone! What can we learn? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Scoring security vulnerabilities 101: Introducing CVSS for CVEs Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Denial of Service vulnerability discovered in the Axios JavaScript package - a Bespoke exploit · hunting DSP Article-specific behavioural hunt — Add a SECURITY.md file to your Azure Repos Bespoke exploit · hunting DSP Article-specific behavioural hunt — Azure Repos enriched with DevSecOps capabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — The top two most popular Docker base images each have over 500 vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Take actions to improve security in your Docker images Bespoke exploit · hunting DSP Article-specific behavioural hunt — After three years of silence, a new jQuery prototype pollution vulnerability eme Bespoke exploit · hunting DSP Article-specific behavioural hunt — Securing Bitbucket Cloud with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source maintainers want to be secure, but 70% lack skills Bespoke exploit · hunting DSP Article-specific behavioural hunt — Top ten most popular docker images each contain at least 30 vulnerabilities Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyking in - Directory traversal vulnerability exploit in the st package Bespoke install · hunting DSP Article-specific behavioural hunt — Scanning Docker images for key binaries - going beyond package managers Bespoke exploit · hunting DSP Article-specific behavioural hunt — How even quick Node.js async functions can block the Event-Loop Bespoke exploit · hunting DSP Article-specific behavioural hunt — Severe security vulnerability in Bower’s zip archive extraction Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk CLI drops support for Node.js 4 (Argon) Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk - Your Next Career Move! Bespoke exploit · hunting DSP Article-specific behavioural hunt — 2018 Year in Review Bespoke exploit · hunting DSP Article-specific behavioural hunt — Codefresh + Snyk = ship fast and securely Bespoke exploit · hunting DSP Article-specific behavioural hunt — Faster & improved tests for JavaScript lockfile based projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — A post-mortem of the malicious event-stream backdoor Bespoke exploit · hunting DSP Article-specific behavioural hunt — JVM Ecosystem report 2018 - About your Platform and Application Bespoke exploit · hunting DSP Article-specific behavioural hunt — The most common vulnerabilities in Maven Central and npm Bespoke install · hunting DSP Article-specific behavioural hunt — JavaScript and Node.js Security – The Common Pitfalls Bespoke exploit · hunting DSP Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Bespoke exploit · hunting DSP Article-specific behavioural hunt — Python Mocking 101: Fake it before you make it Bespoke exploit · hunting DSP Article-specific behavioural hunt — Where do security patches come from? Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm Shrinkwrap reloaded: Locking npm Deps with Package-Lock and Yarn.Lock Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bower is dead, long live npm. And Yarn. And webpack. Bespoke exploit · hunting DSP Article-specific behavioural hunt — 77% of 433,000 sites use vulnerable JavaScript libraries Bespoke exploit · hunting DSP Article-specific behavioural hunt — Open source vulnerabilities tripped Equifax, how can you defend yourself? Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk and Atlassian, Sitting in a Tree Bespoke exploit · hunting DSP Article-specific behavioural hunt — Bitbucket Server Integration in Beta Bespoke exploit · hunting DSP Article-specific behavioural hunt — Serverless Security implications—from infra to OWASP Bespoke exploit · hunting DSP Article-specific behavioural hunt — Maven support is here! Bespoke exploit · hunting DSP Article-specific behavioural hunt — Continuously secure all apps with unlimited Snyk projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Bespoke exploit · hunting DSP Article-specific behavioural hunt — Regular Expression Denial of Service (ReDoS) and Catastrophic Backtracking Bespoke exploit · hunting DSP Article-specific behavioural hunt — Differences in version handling between RubyGems and npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching serverless Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Yarn is Micro Secure Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching "The Secure Developer" Podcast Bespoke exploit · hunting DSP Article-specific behavioural hunt — Threat modelling For Node.js applications Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using ES2015 Proxy for fun and profit Bespoke install · hunting DSP Article-specific behavioural hunt — Enriching bitHound with Snyk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Architecting a Serverless web application in AWS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mitigating ImageMagick vulnerabilities in Node.js Bespoke exploit · hunting DSP Article-specific behavioural hunt — Free vulnerability testing and monitoring for public GitHub projects Bespoke exploit · hunting DSP Article-specific behavioural hunt — Exploiting Buffer Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using Node.js event loop for timing attacks Bespoke exploit · hunting DSP Article-specific behavioural hunt — Keeping your open source credentials closed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Launching Snyk Bespoke exploit · hunting DSP

Articles citing this technique (558)