Datadog threat roundup: top insights for Q4 2024
ID: 4988c00a-5394-5154-b4da-2d92ef55778a
STIX ID: report--4988c00a-5394-5154-b4da-2d92ef55778a
Feed Name: Datadog Security Labs
Datadog's Q4 2024 Threat Roundup outlines active and evolving threats: malicious npm/PyPI supply-chain packages (pre/post-install scripts and setuptools overwrites) distributing droppers and infostealers, campaigns by actors including DPRK-linked Tenacious Pungsan and MUT-8694/MUT-1244, large credential exfiltration (~390,000 credentials), and an increase in cloud control-plane abuse—notably AWS Bedrock LLMjacking and SES compromise—highlighting the need for stronger access-key hygiene, package vetting, and targeted detection engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
