T1204.002Malicious File
T1204.002 — Malicious File is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 529 detection use cases covering it and 575 threat-intel articles citing it.
Execution
529Use cases
575Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (529)
Email attachment opened from external sender [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install O365 SharePoint Malware Detection O365 Threat Intelligence Suspicious File Detected Batch File Write to System32 Cisco NVM - Susp Script From Archive Triggering Network Activity Drop IcedID License dat Single Letter Process On Endpoint Suspicious Process Executed From Container File Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppX Deployment Full Trust Package Installation Windows AppX Deployment Package Installation Success Windows AppX Deployment Unsigned Package Installation Windows Binary Execution from an Archive Windows Default Cobalt Strike PowerShell Beacon Windows Developer-Signed MSIX Package Installation Windows EFI Volume Mount Attempt Via Mountvol Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows MSIX Package Interaction Windows Mustang Panda USB Tool Execution Windows NorthStar C2 Agent Execution Windows PowerShell Script From WindowsApps Directory Windows Suspect Process With Authentication Traffic Windows Suspicious QEMU Execution Windows Universal Data Link File Creation Windows User Execution Malicious URL Shortcut File Uncommon Processes On Endpoint Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Article-specific behavioural hunt — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Article-specific behavioural hunt — Cisco warns of FMC static credential flaw exploited in zero-day attacks Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Article-specific behavioural hunt — New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Article-specific behavioural hunt — Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates [LLM] Flying Eagle / SpyNote malicious APK download by hash or distribution domain Article-specific behavioural hunt — Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Article-specific behavioural hunt — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Article-specific behavioural hunt — Mirage Kitten targets Middle East and Africa region with new malware Article-specific behavioural hunt — n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process Article-specific behavioural hunt — Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell [LLM] Cruciferra known-sample SHA256 execution/write [LLM] ISO-delivered signed RegSchdTask.exe executed from non-standard/removable path [LLM] TELESHIM/MIXEDKEY/BINDCLOAK known-bad file hash execution Article-specific behavioural hunt — Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executabl [LLM] Browser-assembled SourTrade executable dropped with campaign-domain origin (MotW) [LLM] DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7gfh-x38p-prh3: Velocity.js: Remote Code Execution via pr Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Article-specific behavioural hunt — Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Doma Article-specific behavioural hunt — Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Min [LLM] TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) Article-specific behavioural hunt — Don’t swing at everything [LLM] msaRAT: MSI impersonating Windows update executed from ProgramData Article-specific behavioural hunt — Email threat landscape: Q2 2026 trends and insights Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-8fpg-xm3f-6cx3: Auth.js: Configuration errors can cause e Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7rqj-j65f-68wh: Auth.js: Email normalizer validates the a Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-p63j-vcc4-9vmv: @vitest/browser: Browser Mode provider co Article-specific behavioural hunt — New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA rec Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Article-specific behavioural hunt — The serpent’s tongue: Luring the Python out of its den Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Article-specific behavioural hunt — What is a dependency firewall? Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Article-specific behavioural hunt — Winning 54% of the time [LLM] Talos prevalent-malware SHA256 execution (UAT-7810 telemetry batch) Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52831: Nuclio: Unsanitized cron trigger event headers [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint [LLM] Browser-dropped .bin password-protected archive (fake software crack lure) Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-27823: EGroupware has a Remote Code Execution Vulnera Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55500: 9routers has Exposure of Sensitive Information Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55615: Langroid: Neo4jChatAgent executes LLM-generate Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/ Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54769: Langroid: Sandbox Escape to Remote Code Execut [LLM] ZDI-CAN-25373 (CVE-2025-9491) LNK spawning PowerShell to fetch BusySnake loader Article-specific behavioural hunt — How We Added WebAuthn to a Browser-Based RDP Client Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54617: LaunchServer FileServerHandler has an unauthen Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52830: fast-mcp-telegram: Bearer token path traversal Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Article-specific behavioural hunt — Catan and Mouse Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50027: mcp-memory-service: Missing Authentication on Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44939: Rancher vulnerable to command injection throug [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) [LLM] Montana Empire phishing-kit ZIP + companion APK by SHA256 on endpoints Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets [LLM] cluw infostealer and malicious ClawHub skill payload hashes on macOS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Article-specific behavioural hunt — Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Article-specific behavioural hunt — Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Re [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Article-specific behavioural hunt — Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Reposito [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Article-specific behavioural hunt — Dev Machine Guard Now Supports Linux Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Article-specific behavioural hunt — A rigged game: ScarCruft compromises gaming platform in a supply-chain attack [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Article-specific behavioural hunt — Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, Article-specific behavioural hunt — CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentia Article-specific behavioural hunt — Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Article-specific behavioural hunt — lightning PyPI Compromise: A Bun-Based Credential Stealer in Python Article-specific behavioural hunt — Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer Article-specific behavioural hunt — Someone published four versions of a fake "tanstack" package in 27 minutes to st Article-specific behavioural hunt — Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Reme Article-specific behavioural hunt — "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Article-specific behavioural hunt — Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomini Article-specific behavioural hunt — Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Wo Article-specific behavioural hunt — GopherWhisper: A burrow full of malware Article-specific behavioural hunt — GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Article-specific behavioural hunt — Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest np Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Article-specific behavioural hunt — Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw Article-specific behavioural hunt — GlassWorm goes native: New Zig dropper infects every IDE on your machine Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Article-specific behavioural hunt — axios compromised on npm: maintainer account hijacked, RAT deployed Article-specific behavioural hunt — litellm: Credential Stealer Hidden in PyPI Wheel [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Article-specific behavioural hunt — Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags Article-specific behavioural hunt — CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Article-specific behavioural hunt — Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup- Article-specific behavioural hunt — bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys Article-specific behavioural hunt — Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Do Article-specific behavioural hunt — Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wa Article-specific behavioural hunt — ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Article-specific behavioural hunt — xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Article-specific behavioural hunt — TeamPCP deploys CanisterWorm on NPM following Trivy compromise Article-specific behavioural hunt — fast-draft Open VSX Extension Compromised by BlokTrooper Article-specific behavioural hunt — Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard Article-specific behavioural hunt — DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laund [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Article-specific behavioural hunt — kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package Article-specific behavioural hunt — Sednit reloaded: Back in the trenches Article-specific behavioural hunt — The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Article-specific behavioural hunt — PlugX Meeting Invitation via MSBuild and GDATA Article-specific behavioural hunt — Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Article-specific behavioural hunt — Exploitability Isn’t the Answer. Breakability Is. [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Article-specific behavioural hunt — Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Stu Article-specific behavioural hunt — CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Co Article-specific behavioural hunt — Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component Article-specific behavioural hunt — Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE- Article-specific behavioural hunt — Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Article-specific behavioural hunt — Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders Article-specific behavioural hunt — PlushDaemon compromises network devices for adversary-in-the-middle attacks Article-specific behavioural hunt — Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Link [LLM] Execution / write of ESET APT Q2-Q3 2025 known-bad SHA256 payload [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Article-specific behavioural hunt — Snyk Studio brings security scanning and automated fixes to Factory's Droids Article-specific behavioural hunt — Phishing Campaign Leveraging the NPM Ecosystem Article-specific behavioural hunt — CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Article-specific behavioural hunt — Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack Article-specific behavioural hunt — npm Supply Chain Attack via Open Source maintainer compromise Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Article-specific behavioural hunt — Cursor IDE Malware Extension Compromise in $500k Crypto Heist [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Article-specific behavioural hunt — Security Testing for Single-Page Applications (SPAs) Article-specific behavioural hunt — CVE-2025-29927 Authorization Bypass in Next.js Middleware Article-specific behavioural hunt — Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Article-specific behavioural hunt — Can Snyk Detect JWT Security Issues? Article-specific behavioural hunt — Solving Security Challenges with Snyk Code and Symbolic AI Article-specific behavioural hunt — CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability Article-specific behavioural hunt — Creating SBOMs with the Snyk CLI Article-specific behavioural hunt — CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Article-specific behavioural hunt — Ultralytics AI Pwn Request Supply Chain Attack Article-specific behavioural hunt — Lottie Player npm package compromised for crypto wallet theft Article-specific behavioural hunt — The mysterious supply chain concern of string-width-cjs npm package Article-specific behavioural hunt — Proactive AppSec continuous vulnerability management for developers and security Article-specific behavioural hunt — Promise queues and batching concurrent tasks in Deno Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Article-specific behavioural hunt — Want to avoid a data breach? Employ secrets detection Article-specific behavioural hunt — CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability Article-specific behavioural hunt — Vulnerabilities in NodeJS C/C++ add-on extensions Article-specific behavioural hunt — A denial of service Regex breaks FastAPI security Article-specific behavioural hunt — 10 Dimensions of Python Static Analysis Article-specific behavioural hunt — Polyfill supply chain attack embeds malware in JavaScript CDN assets Article-specific behavioural hunt — Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk Article-specific behavioural hunt — Essential Node.js backend examples for developers in 2024 Article-specific behavioural hunt — 10 modern Node.js runtime features to start using in 2024 Article-specific behavioural hunt — CISA KEV: CVE-2024-4978 — Justice AV Solutions (JAVS) Viewer Installer Embedded Article-specific behavioural hunt — Fastify plugins as building blocks for a backend Node.js API Article-specific behavioural hunt — Preventing broken access control in express Node.js applications Article-specific behavioural hunt — Symmetric vs. asymmetric encryption: Practical Python examples Article-specific behavioural hunt — Building an npm package compatible with ESM and CJS in 2024 Article-specific behavioural hunt — Nine Docker pro tips for Node.js developers Article-specific behavioural hunt — Exploiting HTTP/2 CONTINUATION frames for DoS attacks Article-specific behavioural hunt — GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok Article-specific behavioural hunt — CISA KEV: CVE-2024-21338 — Microsoft Windows Kernel Exposed IOCTL with Insuffici Article-specific behavioural hunt — 5 Node.js security code snippets every backend developer should know Article-specific behavioural hunt — Preventing server-side request forgery in Node.js applications Article-specific behavioural hunt — Preventing SQL injection attacks in Node.js Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Article-specific behavioural hunt — Build and deploy a Node.js security scanning API to Platformatic Cloud Article-specific behavioural hunt — Command injection in Python: examples and prevention Article-specific behavioural hunt — Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE? Article-specific behavioural hunt — Code injection in Python: examples and prevention Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages Article-specific behavioural hunt — Exploring WebExtension security vulnerabilities in React Developer Tools and Vue Article-specific behavioural hunt — File encryption in Python: An in-depth exploration of symmetric and asymmetric t Article-specific behavioural hunt — Dependency injection in Python Article-specific behavioural hunt — The art of conditional rendering: Tips and tricks for React and Next.js develope Article-specific behavioural hunt — Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & Article-specific behavioural hunt — Installing and managing Java on macOS Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Article-specific behavioural hunt — Modern VS Code extension development tutorial: Building a secure extension Article-specific behavioural hunt — Security implications of cross-origin resource sharing (CORS) in Node.js Article-specific behavioural hunt — A guide to input validation with Spring Boot Article-specific behavioural hunt — Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison Article-specific behavioural hunt — Using JLink to create smaller Docker images for your Spring Boot Java applicatio Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Article-specific behavioural hunt — Mitigating DOM clobbering attacks in JavaScript Article-specific behavioural hunt — Implementing TLS in Kubernetes Article-specific behavioural hunt — Finding and fixing insecure direct object references in Python Article-specific behavioural hunt — Swift deserialization security primer Article-specific behavioural hunt — XS leaks: What they are and how to avoid them Article-specific behavioural hunt — Building a security-conscious CI/CD pipeline Article-specific behavioural hunt — The importance of verifying webhook signatures Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Article-specific behavioural hunt — The SecurityManager is getting removed in Java: What that means for you Article-specific behavioural hunt — Ethical Hacking: Top Tools Article-specific behavioural hunt — Setting up the Docker image scan GitHub Action Article-specific behavioural hunt — Secure JavaScript URL validation Article-specific behavioural hunt — Security implications of HTTP response headers Article-specific behavioural hunt — Preventing insecure deserialization in Node.js Article-specific behavioural hunt — Timing out synchronous functions with regex Article-specific behavioural hunt — Avoiding mass assignment vulnerabilities in Node.js Article-specific behavioural hunt — The Docker project turns 10! Looking back at a decade of containers Article-specific behavioural hunt — Comparing Node.js web frameworks: Which is most secure? Article-specific behavioural hunt — Mitigating path traversal vulns in Java with Snyk Code Article-specific behavioural hunt — Node.js multithreading with worker threads: pros and cons Article-specific behavioural hunt — The security concerns of a JavaScript sandbox with the Node.js VM module Article-specific behavioural hunt — Building Vue 3 components with Tailwind CSS Article-specific behavioural hunt — CISA KEV: CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows Denial-o Article-specific behavioural hunt — CSPRNG: Random algorithms need security too! Article-specific behavioural hunt — Adding security to Nuxt 3 [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Article-specific behavioural hunt — You should be using HTTP Strict Transport Security (HSTS) headers in your Node.j Article-specific behavioural hunt — 5 "no experience needed" tips for building secure applications Article-specific behavioural hunt — Azure Bicep security fundamentals Article-specific behavioural hunt — Dependency injection in JavaScript Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Treasure Trove Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: Moongoose Article-specific behavioural hunt — Fetch the Flag CTF 2022 writeup: File Explorer Article-specific behavioural hunt — NPM security: preventing supply chain attacks Article-specific behavioural hunt — Secure Python URL validation Article-specific behavioural hunt — Ruby on Rails Docker for local development environment Article-specific behavioural hunt — New OpenSSL critical vulnerability: What you need to know Article-specific behavioural hunt — Node.js multithreading with worker threads series: worker_threads tutorial Article-specific behavioural hunt — Improving code quality with linting in Python Article-specific behavioural hunt — Choosing the best Node.js Docker image Article-specific behavioural hunt — The npm faker package and the unexpected demise of open source libraries Article-specific behavioural hunt — Solve Hack the Box and other CTF challenges with Snyk Article-specific behavioural hunt — Building a secure API with gRPC Article-specific behavioural hunt — Rediscovering argument injection when using VCS tools — git and mercurial Article-specific behavioural hunt — The dangers of assert in Python Article-specific behavioural hunt — Ruby gem installations can expose you to lockfile injection attacks Article-specific behavioural hunt — Snyk finds PyPi malware that steals Discord and Roblox credential and payment in Article-specific behavioural hunt — Controlling your server with a reverse shell attack Article-specific behavioural hunt — Securing PHP containers Article-specific behavioural hunt — Slidev 101: Coding presentations with Markdown Article-specific behavioural hunt — Safer together: Snyk and CISPA collaborate for the greater good Article-specific behavioural hunt — CISA KEV: CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerabil Article-specific behavioural hunt — Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confu Article-specific behavioural hunt — CISA KEV: CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — 3 Jedi-inspired lessons to level up your JavaScript security Article-specific behavioural hunt — Building Docker images in Kubernetes Article-specific behavioural hunt — Targeted npm dependency confusion attack caught red-handed Article-specific behavioural hunt — Generating fake security data with Python and faker-security Article-specific behavioural hunt — Modernizing SAST rules maintenance to catch vulnerabilities faster Article-specific behavioural hunt — Improving GraphQL security with static analysis and Snyk Code Article-specific behavioural hunt — CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vul Article-specific behavioural hunt — Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit Article-specific behavioural hunt — CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution V Article-specific behavioural hunt — Exploring 3 types of directory traversal vulnerabilities in C/C++ Article-specific behavioural hunt — Building a secure GraphQL API with Node.js Article-specific behavioural hunt — CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vu Article-specific behavioural hunt — CISA KEV: CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2011-2005 — Microsoft Ancillary Function Driver (afd.sys) Improper Article-specific behavioural hunt — CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow V Article-specific behavioural hunt — CISA KEV: CVE-2014-6332 — Microsoft Windows Object Linking & Embedding (OLE) Aut Article-specific behavioural hunt — Alert: peacenotwar module sabotages npm developers in the node-ipc package to pr Article-specific behavioural hunt — Build a software bill of materials (SBOM) for open source supply chain security Article-specific behavioural hunt — "Dirty Pipe" Linux vulnerability and your containerized applications (CVE-2022-0 Article-specific behavioural hunt — Celebrating amazing open source innovation from Ukraine Article-specific behavioural hunt — CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnera Article-specific behavioural hunt — CISA KEV: CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerab Article-specific behavioural hunt — CISA KEV: CVE-2013-0640 — Adobe Reader and Acrobat Memory Corruption Vulnerabili Article-specific behavioural hunt — CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulner Article-specific behavioural hunt — Visibly invisible malicious Node.js packages: When configuration niche meets inv Article-specific behavioural hunt — Join The Big Fix: a 24-hour livestream dedicated to fixing security vulnerabilit Article-specific behavioural hunt — Case study: Python RCE vulnerability in Celery Article-specific behavioural hunt — Automating Terraform security in Scalr deployments with Regula [Tutorial] Article-specific behavioural hunt — CISA KEV: CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability Article-specific behavioural hunt — Using Pulumi to automate the Snyk Kubernetes integration for containers Article-specific behavioural hunt — CISA KEV: CVE-2021-21315 — System Information Library for Node.JS Command Inject Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Article-specific behavioural hunt — Open source maintainer pulls the plug on npm packages colors and faker, now what Article-specific behavioural hunt — Log4Shell in a nutshell (for non-developers & non-Java developers) Article-specific behavioural hunt — Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17 Article-specific behavioural hunt — Scanning ARM templates for misconfigurations with the Snyk CLI Article-specific behavioural hunt — Exploring extensions of dependency confusion attacks via npm package aliasing Article-specific behavioural hunt — JavaScript type confusion: Bypassed input validation (and how to remediate) Article-specific behavioural hunt — CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Article-specific behavioural hunt — CISA KEV: CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2020-0601 — Microsoft Windows CryptoAPI Spoofing Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization Article-specific behavioural hunt — CISA KEV: CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cr Article-specific behavioural hunt — Snyk Code CLI support now in public beta Article-specific behavioural hunt — A (soft) introduction to Python dependency management Article-specific behavioural hunt — Detect and prevent dependency confusion attacks on npm to maintain supply chain Article-specific behavioural hunt — The 8 best IntelliJ plugins for improving your coding experience Article-specific behavioural hunt — Plugins to put Node.js application security and observability in your IDE Article-specific behavioural hunt — Building Java container images using Jib Article-specific behavioural hunt — Use Snyk security policies to prioritize fixes more efficiently Article-specific behavioural hunt — Better Ruby Gemfile security: A step-by-step guide using Snyk Article-specific behavioural hunt — Getting started with Snyk for secure Python development Article-specific behavioural hunt — Four steps for hardening Amazon EKS security Article-specific behavioural hunt — Managing Node.js Docker images in GitHub Packages using GitHub Actions Article-specific behavioural hunt — Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging Article-specific behavioural hunt — Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extens Article-specific behavioural hunt — Snyk takes on responsibility for Node.js ecosystem vulnerability disclosure prog Article-specific behavioural hunt — SuiteCRM: PHAR deserialization vulnerability to code execution Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Article-specific behavioural hunt — Why developer-first SAST tools are the future of code security Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Article-specific behavioural hunt — Docker Hub authentication: Is 2021 the year you enable 2FA on Docker Hub? Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Article-specific behavioural hunt — AWS vulnerability scanning using the Snyk integration Article-specific behavioural hunt — What makes Verdaccio a successful project? Article-specific behavioural hunt — Docker for Node.js developers: 5 things you need to know not to fail your securi Article-specific behavioural hunt — What is typosquatting and how typosquatting attacks are responsible for maliciou Article-specific behavioural hunt — Securing your Kubernetes application development with Snyk and Tilt Article-specific behavioural hunt — What makes Fastify a successful project? Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Article-specific behavioural hunt — Kernel privilege escalation: how Kubernetes container isolation impacts privileg Article-specific behavioural hunt — 10 git aliases for a faster and productive git workflow Article-specific behavioural hunt — Command injection: how it works, what are the risks, and how to prevent it Article-specific behavioural hunt — DevSecOps tools for open source projects in JavaScript and Node.js Article-specific behavioural hunt — Container image formats under the hood Article-specific behavioural hunt — RPM Package Manager: RPM package security scanning with Snyk Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Article-specific behavioural hunt — From zero to security hero: test your GitHub projects for known vulnerabilities Article-specific behavioural hunt — GitHub Actions to securely publish npm packages Article-specific behavioural hunt — Node.js security: lessons from the Node.js Security Working Group in triaging vu Article-specific behavioural hunt — Privileged Docker containers—do you really need them? Article-specific behavioural hunt — Regular Expression Denial of Service (REDoS) in UAParser.js Article-specific behavioural hunt — SourMint malicious SDK research write up Article-specific behavioural hunt — JHipster security scanning with Snyk Article-specific behavioural hunt — SourMint malicious SDK research writeup Article-specific behavioural hunt — Breaking out of message brokers Article-specific behavioural hunt — Demystifying HTTP request smuggling Article-specific behavioural hunt — Regular Expression Denial-of-Service in websocket-extensions Article-specific behavioural hunt — Checking Helm Charts for security misconfigurations Article-specific behavioural hunt — Why do organizations trust Snyk to win the open source security battle? Article-specific behavioural hunt — Using Snyk to implement end-to-end DevSecOps on Microsoft Azure Article-specific behavioural hunt — Why did is-promise happen and what can we learn from it Article-specific behavioural hunt — Snyk vulnerability disclosure program: what’s going on behind the scenes? Article-specific behavioural hunt — Yarn 2 plugins - an introduction Article-specific behavioural hunt — VS Code extension: building auto CI/CD with GitHub Actions Article-specific behavioural hunt — Yarn 2 — the future of package managers for JavaScript? Article-specific behavioural hunt — March in review: State of Open Source Security survey, All.The.Talks virtual con Article-specific behavioural hunt — Using UBI images to minimize container vulnerabilities Article-specific behavioural hunt — Creating an automated cloud infrastructure testing tool with Terraform and PyTes Article-specific behavioural hunt — Exploring the minimist prototype pollution security vulnerability Article-specific behavioural hunt — The State of Open Source Security Survey - 2020 Article-specific behavioural hunt — What is a backdoor? Let’s build one with Node.js Article-specific behavioural hunt — Fastify Node.js framework improves JSON security thanks to a security report Article-specific behavioural hunt — Node.js release fixes a critical HTTP security vulnerability Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Article-specific behavioural hunt — See Snyk and GitHub in action at GitHub Universe Article-specific behavioural hunt — Angular vs React: the security risk of indirect dependencies Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Article-specific behavioural hunt — JavaScript frameworks security report 2019 Article-specific behavioural hunt — A Snyk peek into Node.js and npm’s state of open source security report 2019 Article-specific behavioural hunt — Why npm lockfiles can be a security blindspot for injecting malicious modules Article-specific behavioural hunt — Sequelize ORM npm library found vulnerable to SQL Injection attacks Article-specific behavioural hunt — Mastering Node.js version management and npm registry sources like a pro Article-specific behavioural hunt — A year-old dormant malicious remote code execution vulnerability discovered in W Article-specific behavioural hunt — Staying ahead of security vulnerabilities with security patches Article-specific behavioural hunt — Snyk research team discovers severe prototype pollution security vulnerabilities Article-specific behavioural hunt — Serverless is great, but what about the security of my AWS Lambda functions and Article-specific behavioural hunt — npm passes the 1 millionth package milestone! What can we learn? Article-specific behavioural hunt — Scoring security vulnerabilities 101: Introducing CVSS for CVEs Article-specific behavioural hunt — A Denial of Service vulnerability discovered in the Axios JavaScript package - a Article-specific behavioural hunt — Add a SECURITY.md file to your Azure Repos Article-specific behavioural hunt — Azure Repos enriched with DevSecOps capabilities Article-specific behavioural hunt — The top two most popular Docker base images each have over 500 vulnerabilities Article-specific behavioural hunt — Take actions to improve security in your Docker images Article-specific behavioural hunt — After three years of silence, a new jQuery prototype pollution vulnerability eme Article-specific behavioural hunt — Securing Bitbucket Cloud with Snyk Article-specific behavioural hunt — Top ten most popular docker images each contain at least 30 vulnerabilities Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Article-specific behavioural hunt — Open source maintainers want to be secure, but 70% lack skills Article-specific behavioural hunt — Snyking in - Directory traversal vulnerability exploit in the st package Article-specific behavioural hunt — Scanning Docker images for key binaries - going beyond package managers Article-specific behavioural hunt — How even quick Node.js async functions can block the Event-Loop Article-specific behavioural hunt — Severe security vulnerability in Bower’s zip archive extraction Article-specific behavioural hunt — Snyk CLI drops support for Node.js 4 (Argon) Article-specific behavioural hunt — Snyk - Your Next Career Move! Article-specific behavioural hunt — 2018 Year in Review Article-specific behavioural hunt — Codefresh + Snyk = ship fast and securely Article-specific behavioural hunt — Faster & improved tests for JavaScript lockfile based projects Article-specific behavioural hunt — A post-mortem of the malicious event-stream backdoor Article-specific behavioural hunt — The most common vulnerabilities in Maven Central and npm Article-specific behavioural hunt — JavaScript and Node.js Security – The Common Pitfalls Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Article-specific behavioural hunt — Python Mocking 101: Fake it before you make it Article-specific behavioural hunt — Where do security patches come from? Article-specific behavioural hunt — npm Shrinkwrap reloaded: Locking npm Deps with Package-Lock and Yarn.Lock Article-specific behavioural hunt — Bower is dead, long live npm. And Yarn. And webpack. Article-specific behavioural hunt — 77% of 433,000 sites use vulnerable JavaScript libraries Article-specific behavioural hunt — Open source vulnerabilities tripped Equifax, how can you defend yourself? Article-specific behavioural hunt — Snyk and Atlassian, Sitting in a Tree Article-specific behavioural hunt — Bitbucket Server Integration in Beta Article-specific behavioural hunt — Serverless Security implications—from infra to OWASP Article-specific behavioural hunt — Maven support is here! Article-specific behavioural hunt — Continuously secure all apps with unlimited Snyk projects Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Article-specific behavioural hunt — Regular Expression Denial of Service (ReDoS) and Catastrophic Backtracking Article-specific behavioural hunt — Differences in version handling between RubyGems and npm Article-specific behavioural hunt — Launching serverless Snyk Article-specific behavioural hunt — Yarn is Micro Secure Article-specific behavioural hunt — Launching "The Secure Developer" Podcast Article-specific behavioural hunt — Threat modelling For Node.js applications Article-specific behavioural hunt — Using ES2015 Proxy for fun and profit Article-specific behavioural hunt — Enriching bitHound with Snyk Article-specific behavioural hunt — Architecting a Serverless web application in AWS Article-specific behavioural hunt — Mitigating ImageMagick vulnerabilities in Node.js Article-specific behavioural hunt — Free vulnerability testing and monitoring for public GitHub projects Article-specific behavioural hunt — Exploiting Buffer Article-specific behavioural hunt — Using Node.js event loop for timing attacks Article-specific behavioural hunt — Keeping your open source credentials closed Article-specific behavioural hunt — Launching SnykArticles citing this technique (575)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Don’t swing at everything art-106
crit [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimited input art-136
crit Begun, the Patch Wars have art-150
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153
crit [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-enabled user art-188
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
crit [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Injection art-257
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
med Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira art-470
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-753
med Creating SBOMs with the Snyk CLI art-1081
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1102
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1230
high Defense in Depth art-1391
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1483
med File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques art-1484
high Dependency injection in Python art-1517
crit Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133) art-1522
med Implementing TLS in Kubernetes art-1623
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
med Adding security to Nuxt 3 art-1858
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1874
crit Secure Python URL validation art-1937
high Building a secure API with gRPC art-2043
high The dangers of assert in Python art-2062
high Securing PHP containers art-2082
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2203
crit CISA KEV: CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vulnerability art-2324
crit CISA KEV: CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability art-2332
crit CISA KEV: CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vulnerability art-2367
crit CISA KEV: CVE-2010-4398 — Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability art-2386
crit CISA KEV: CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnerability art-2564
crit CISA KEV: CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulnerability art-2590
crit CISA KEV: CVE-2019-15752 — Docker Desktop Community Edition Privilege Escalation Vulnerability art-2852
high Detect and prevent dependency confusion attacks on npm to maintain supply chain security art-3088
high Developer driven workflows: Dockerfile image scanning, prioritization, and remediation art-3190
med Python Poetry package manager and security integration with software composition analysis tool art-3260
high Node.js security: lessons from the Node.js Security Working Group in triaging vulnerabilities art-3267
crit Breaking out of message brokers art-3322
high After three years of silence, a new jQuery prototype pollution vulnerability emerges once again art-3541
high Snyk - Your Next Career Move! art-3575
high 2018 Year in Review art-3577
crit XSS Attacks: The Next Wave art-3641
high Maven support is here! art-3647
med Launching serverless Snyk art-3666
high Yarn is Micro Secure art-3668
med Enriching bitHound with Snyk art-3676
high Exploiting Buffer art-3687
med Launching Snyk art-3692