logo

Datadog Security Labs

ID: ac3b20b4-fc8f-5eaf-8f8b-3b269b43bea4

STIX ID: identity--ac3b20b4-fc8f-5eaf-8f8b-3b269b43bea4

Feed Type: rss

Earliest post: 2023-02-23

Latest post: 2026-05-28

Latest cloud security research, threat-hunting, vulnerability analyses and detection-engineering guidance — focused on emerging threats, supply-chain risks, misconfigurations, and real-world attack trends.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents2026-05-28TrueTrue
Unpatchable Vulnerabilities of Kubernetes: CVE-2021-257402026-05-21TrueTrue
Backdoored Cemu release linked to TanStack and Mistral supply chain campaign2026-05-14TrueTrue
Backdoored node-ipc npm releases steal developer credentials through DNS queries2026-05-14TrueTrue
Shai-Hulud Goes Open Source2026-05-13TrueTrue
Malicious Coding Agent Skills and the Risk of Dynamic Context2026-05-11TrueTrue
The case for dependency cooldowns in a post-axios world2026-04-16TrueTrue
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-85622026-04-09TrueTrue
Compromised axios npm package delivers cross-platform RAT2026-03-31TrueTrue
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-85612026-03-27TrueTrue
LiteLLM compromised on PyPI: Tracing the March 2026 TeamPCP supply chain campaign2026-03-24TrueTrue
Uncovering agent logging gaps in Copilot Studio2026-03-10TrueTrue
Behind the console: Active phishing campaign targeting AWS console credentials2026-03-09TrueTrue
Hook, line, and vault: A technical deep dive into the 1Phish kit2026-02-27TrueTrue
Kubernetes project issues warning on Ingress NGINX retirement2026-02-19TrueTrue
Tech impersonators: ClickFix and MacOS infostealers2026-02-10TrueTrue
Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious2026-02-04TrueTrue
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows2026-01-27TrueTrue
Introducing IDE-SHEPHERD: Your shield against threat actors lurking in your IDE2026-01-26TrueTrue
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-85542026-01-14TrueTrue
Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users2025-12-10TrueTrue
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js2025-12-04TrueTrue
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know2025-11-25TrueTrue
MUT-4831: Trojanized npm packages deliver Vidar infostealer malware2025-11-06TrueTrue
A runtime security approach to detecting supply chain attacks2025-11-05TrueTrue
Datadog threat roundup: Top insights for Q3 20252025-10-31TrueTrue
Learnings from recent npm supply chain compromises2025-10-30TrueTrue
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing2025-10-20TrueTrue
CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions2025-08-26TrueTrue
MCP vulnerability case study: SQL injection in the Postgres MCP server2025-08-21TrueTrue
Datadog threat roundup: Top insights for Q2 20252025-08-14TrueTrue
Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker 2025-07-21TrueTrue
I SPy: Escalating to Entra ID's Global Admin with a first-party app2025-07-16TrueTrue
CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems2025-07-10TrueTrue
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions2025-05-21TrueTrue
Tales from the cloud trenches: The Attacker doth persist too much, methinks2025-05-13TrueTrue
RedisRaider: Weaponizing misconfigured Redis to mine cryptocurrency at scale2025-05-07TrueTrue
Datadog threat roundup: Top insights for Q1 20252025-04-17TrueTrue
Understanding CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability2025-03-28TrueTrue
The 'IngressNightmare' vulnerabilities in the Kubernetes Ingress NGINX Controller: Overview, detection, and remediation2025-03-25TrueTrue
Creating immutable users through a bug in Entra ID restricted administrative units2025-03-25TrueTrue
whoAMI: A cloud image name confusion attack2025-02-12TrueTrue
Datadog threat roundup: top insights for Q4 20242025-01-24TrueTrue
Getting a taste of your own medicine: Threat actor MUT-1244 targets offensive actors, leaking hundreds of thousands of credentials2024-12-13TrueTrue
Tales from the cloud trenches: Unwanted visitor2024-12-11TrueTrue
MUT-8694: An NPM and PyPI Malicious Campaign Targeting Windows Users2024-11-22TrueTrue
Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview2024-10-24TrueTrue
Remote execution exploit chain in CUPS: Overview, detection, and remediation2024-09-27TrueTrue
Threat Actors leverage Docker Swarm and Kubernetes to mine cryptocurrency at scale2024-09-23TrueTrue
Hidden in Plain Sight: Abusing Entra ID Administrative Units for Sticky Persistence2024-09-16TrueTrue

1–50 of 71