logo

Datadog threat roundup: Top insights for Q2 2025

ID: 6e28f058-5b47-584b-8490-518df0ffe281

STIX ID: report--6e28f058-5b47-584b-8490-518df0ffe281

Feed Name: Datadog Security Labs

Threat Score
78/100

Date Published: 2025-08-14

Date Updated: 2026-04-27

...
...

Datadog Security Research Q2 2025 roundup details active, multi-vector threats: supply-chain compromises (malicious VS Code extensions and obfuscated NPM packages/typosquats) distributing info-stealers and cryptominers, Mimo Linux malware expanding to Magento with rootkit and memory-only execution techniques, and a novel cloud-native persistence technique using API Gateway + Lambda to auto-create IAM users for durable access. The report highlights platform-agnostic attacker tradecraft affecting developer ecosystems, container and serverless infrastructure, and recommends auditing cron jobs, /etc/ld.so.preload, memory-backed execution artifacts, and cloud IAM roles and API Gateway/Lambda configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.