Sign in

Christophe Tafani-Dereeper

@christophetd.fr
1.5K followers 120 following 91 posts

Cloud and container security • Security research and open source at Datadog 🇨🇭🇫🇷 christophetd.fr

PostsRepliesMedia
Christophe Tafani-Dereeper @christophetd.fr · 24/09/2026
Had lots of fun finding this vulnerability and writing an (hopefully) educational write-up!
022
Christophe Tafani-Dereeper @christophetd.fr · 10/07/2026
Interesting backdoor in an npm package. Analyzing the timezone in git commit metadata shows this is likely a compromised maintainer account
000
Christophe Tafani-Dereeper @christophetd.fr · 26/06/2026
Happy to have contributed to that release!
010
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 24/06/2026
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond securitylabs.datadoghq.com/articles/beh...
securitylabs.datadoghq.com
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond | Datadog Security Labs
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
001
Christophe Tafani-Dereeper @christophetd.fr · 10/06/2026
My Claude credits today, seeing me try Fable 5
static.klipy.com
Melting Chocolate Bunny with Googly Eyes
Alt: melting claude credits
010
Christophe Tafani-Dereeper @christophetd.fr · 05/06/2026
github.com/jqwik-team/j... 🤔
github.com
Added message for AI coding agents. · jqwik-team/jqwik@9dddcb5
000
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 02/06/2026
Freshly out on the Datadog Engineering blog! From single pull requests to full software packages: Detecting malicious code at scale www.datadoghq.com/blog/enginee...
datadoghq.com
Scaling malicious code detection from pull requests to the software supply chain | Datadog
Datadog scaled malicious code detection from pull requests to dependency packages using stacked LLM evaluations and agentic investigation.
021
Christophe Tafani-Dereeper @christophetd.fr · 31/03/2026
I wrote up an analysis of the Axios compromise: securitylabs.datadoghq.com/articles/axi... Crazy how while researchers were filing issues to report the compromise, the attacker was deleting them in real time using the maintainer's GitHub access!
033
Christophe Tafani-Dereeper @christophetd.fr · 25/03/2026
Yesterday, a threat actor compromised 2 versions of the LiteLLM Python package (40k stars, 3M+ weekly downloads). The malicious versions had 120k downloads before being taken down Full write-up: securitylabs.datadoghq.com/articles/lit... Timeline (h/t @ramimac.me): ramimac.me/trivy-teampcp/
011
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 11/03/2026
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos www.datadoghq.com/blog/enginee...
datadoghq.com
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos | Datadog
Learn how Datadog detected and resolved issues from hackerbot-claw, an AI-powered automated attack campaign.
072
Christophe Tafani-Dereeper @christophetd.fr · 09/03/2026
Fresh and active AWS phishing campaign with 3 main domains: cloud-recovery[.]us cloud-recovery[.]net aws[.]cloud-recovery[.]us ... with hands-on-keyboard activity 20 minutes after credentials are submitted
052
Reposted by Christophe Tafani-Dereeper
nolimitsecu.bsky.social @nolimitsecu.bsky.social · 09/03/2026
#Podcast #Cybersécurité Épisode #534 consacré au ver "Shai-Hulud", avec @christophetd.fr www.nolimitsecu.fr/shai-hulud/
nolimitsecu.fr
Shai-Hulud - NoLimitSecu
Episode #534 consacré à « Shai-Hulud » Avec Christophe Tafani-Dereeper Références : Shai-Hulud:  https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/ https://github.com/DataDog/indicat...
064
Christophe Tafani-Dereeper @christophetd.fr · 12/02/2026
I asked Claude (Opus 4.6) and Codex (GPT-5.3) to each generate a simple LinkedList implementation in Java. Then I asked Claude to pick the better one. No hesitation: "The Codex version is better" 🤔 gist.github.com/christophetd...
The Codex version is better. The tail pointer is the defining difference — it shows a stronger understanding of linked list design. O(1)
   append is the whole reason you'd use a linked list over an array in many scenarios, and the Claude version gets that wrong. The Codex
  version is also cleaner structurally (shared nodeAt helper, no redundant initializations).
070
Christophe Tafani-Dereeper @christophetd.fr · 26/01/2026
If you're using VSCode or Cursor, this is a pretty solid extension to have in your toolbox!
000
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 09/01/2026
Decoding the GitHub recommendations for npm maintainers securitylabs.datadoghq.com/articles/dec... by @phrawzty.com
securitylabs.datadoghq.com
Decoding the GitHub recommendations for npm maintainers | Datadog Security Labs
This blog post explores the rationale and implementation behind GitHub's security recommendations for npm maintainers following numerous high-profile supply-chain incidents. It details how hardening p...
003
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 10/12/2025
Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users securitylabs.datadoghq.com/articles/inv...
022
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 04/12/2025
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js securitylabs.datadoghq.com/articles/cve...
164
Christophe Tafani-Dereeper @christophetd.fr · 01/12/2025
"Building an npm worm" (2016) contolini.com/building-an-...
contolini.com
Building an npm worm
Building an npm virus via self-replicating lifecycle scripts.
030
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 26/11/2025
A few days ago, a new piece of malware started spreading in npm, compromising and backdooring hundreds of legitimate npm packages and GitHub users. Read the analysis from our security research team: securitylabs.datadoghq.com/articles/sha...
065
Christophe Tafani-Dereeper @christophetd.fr · 08/10/2025
If you're in cloud security, do have a look at this piece of research I've been working on! Feedback / thoughts welcome
061
Reposted by Christophe Tafani-Dereeper
Metalhearf @metalhearf.fr · 25/09/2025
The EU is advancing legislation requiring all messaging platforms to scan private messages, even in encrypted apps like Signal/WhatsApp/Telegram. 600+ security researchers oppose ChatControl for being technically flawed. Learn more about it 👉 metalhearf.fr/posts/chatco... #ChatControl #privacy
metalhearf.fr
ChatControl wants to scan all your private messages
The EU is pushing legislation that would scan all our private messages, even in encrypted apps.
152
Christophe Tafani-Dereeper @christophetd.fr · 15/09/2025
If you're into cloud security, fwd:cloudsec Europe is now live. Schedule: fwdcloudsec.org/conference/e...
fwdcloudsec.org
Schedule | fwd:cloudsec Europe 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
041
Reposted by Christophe Tafani-Dereeper
Rory McCune @mccune.org.uk · 21/08/2025
I did a bit more looking into the upcoming bitnami deprecation. The images are still getting millions of pulls a week, so depending on exactly what tags vanish next week, there could be a lot of broken deploys on the 28th! raesene.github.io/blog/2025/08...
raesene.github.io
Bitnami Deprecation
054
Christophe Tafani-Dereeper @christophetd.fr · 10/08/2025
@micahflee.com thank you for the amazing and inspiring defcon talk
010
Christophe Tafani-Dereeper @christophetd.fr · 29/07/2025
I arbitrarily picked a list of 50 talks I'm most excited about that are happening next week at DEF CON / Black Hat / BSides LV / The Diana Initiative. I'll also add recordings/slides to this list when they become available!
022
Christophe Tafani-Dereeper @christophetd.fr · 28/07/2025
Getting ready for DEF CON next week! ✅ Slides ✅ Demos ✅ Custom shirt designed for the occasion
020
Christophe Tafani-Dereeper @christophetd.fr · 18/07/2025
Looks like the maintainer of a number of highly-popular npm packages was phished through npnjs[.]com, and his access used to publish malicious versions of their packages x.com/JounQin/stat... www.linkedin.com/feed/update/... github.com/prettier/esl...
155
Christophe Tafani-Dereeper @christophetd.fr · 23/06/2025
Stratus Red Team AWS attack techniques are now mapped to the Threat Technique Catalog for AWS Stratus Red Team AWS attack techniques: stratus-red-team.cloud/attack-techn... Threat Technique Catalog by AWS: aws-samples.github.io/threat-techn...
072
Christophe Tafani-Dereeper @christophetd.fr · 23/06/2025
The MCP spec has been updated to include security best practices • Confused deputy • Token passthrough • Session hijacking modelcontextprotocol.io/specificatio...
modelcontextprotocol.io
Security Best Practices - Model Context Protocol
043
Christophe Tafani-Dereeper @christophetd.fr · 10/06/2025
Solid way to start the week
1281
Christophe Tafani-Dereeper @christophetd.fr · 15/05/2025
👀
010
Christophe Tafani-Dereeper @christophetd.fr · 08/05/2025
If you're a cloud practitioner based in Europe, definitely submit to fwd:cloudsec Berlin happening in September! We're actively seeking submissions from first time speakers and non-security folks. In that case, you can submit by May 30th and get initial feedback on your submission!
163
Reposted by Christophe Tafani-Dereeper
fwd:cloudsec @fwdcloudsec.org · 20/04/2025
Ticket sales for fwd:cloudsec Europe 2025 goes live on April 22nd, first batch at 9 AM CET and a second batch at 7PM CET. Tickets are sold through Swoogo, link at fwdcloudsec.org/conference/e... ..
fwdcloudsec.org
fwd:cloudsec Europe 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
165
Reposted by Christophe Tafani-Dereeper
Jenna McLaughlin @jennamclaughlin.bsky.social · 18/04/2025
My story breaking this news exclusively was 7K+ words and had almost all of this in it, and more: www.npr.org/2025/04/15/n...
npr.org
A whistleblower's disclosure details how DOGE may have taken sensitive labor data
A whistleblower tells Congress and NPR that DOGE may have taken sensitive labor data and hid its tracks. "None of that ... information should ever leave the agency," said a former NLRB official.
8945221979
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 27/03/2025
The March edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... • New MITRE ATT&CK coverage matrix in Stratus Red Team • Compromised GitHub actions • Malicious Maven packages • Exploitation of SSRF vulnerabilities on the rise • ... and more
securitylabs.datadoghq.com
Malicious Maven packages, SSRFs strike again, and stealing cloud credentials from web applications | Datadog Security Labs
This month’s digest has a little bit of everything—cloud threats, supply chain attacks, and a reminder that yes, attackers are still exploiting SSRFs.
022
Christophe Tafani-Dereeper @christophetd.fr · 24/03/2025
Looking forward to it! ☁️🇪🇺🇩🇪
000
Reposted by Christophe Tafani-Dereeper
Wietze @wietzebeukema.nl · 24/03/2025
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi...
13619
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 27/02/2025
The February edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... featuring @sethsec.bsky.social, @mccune.org.uk, @karimscloud.bsky.social, @jcfarris.bsky.social, and more
securitylabs.datadoghq.com
The whoAMI name confusion attack, modern phishing tactics, and K8s network security fundamentals | Datadog Security Labs
This February edition of the Datadog Security Digest dives into the
052
Reposted by Christophe Tafani-Dereeper
fwd:cloudsec @fwdcloudsec.org · 26/02/2025
Regular tickets sold out quickly, but Personal Supporter tickets are still available! Speakers get a ticket, so consider submitting a talk idea to the CFP. Closes April 11. Scholarship is open: fwdcloudsec.org/conference/n...
fwdcloudsec.org
Scholarships | NA 2025 | fwd:cloudsec
The fwd:cloudsec scholarship is our way of granting students & people wanting to make a career change with a passion for cloud security an opportunity to attend fwd:cloudsec, network with our attendee...
043
Christophe Tafani-Dereeper @christophetd.fr · 25/02/2025
Si vous êtes sur Paris et avez de l'expérience avec la sécurité de la chaîne d'approvisionement logicielle (supply chain security), Datadog a un poste dans mon équipe qui devrait vous intéresser ! careers.datadoghq.com/detail/66012... N'hésitez pas à me DM si vous avez des questions.
careers.datadoghq.com
Senior Security Advocate - Supply-Chain Security | Datadog Careers
We're building a platform that engineers love to use. Join us, and help usher in the future.
041
Christophe Tafani-Dereeper @christophetd.fr · 24/02/2025
@anssi-fr.bsky.social Il serait bien d'utiliser votre nom de domaine officiel comme nom d'utilisateur Bluesky (bsky.social/about/blog/4...), autrement il est impossible de savoir s'il s'agit d'un compte légitime Idem pour @cert-fr.bsky.social
010
Christophe Tafani-Dereeper @christophetd.fr · 24/02/2025
L'ANSSI vient de sortir un rapport sur la menace dans les environnements cloud, en Français : www.cert.ssi.gouv.fr/uploads/CERT... Au programme : • Menaces ciblant les fournisseurs • Menaces ciblant les utilisateurs finaux • L'usage que les attaquants font du cloud @anssi-fr.bsky.social
031
Christophe Tafani-Dereeper @christophetd.fr · 21/02/2025
A refreshing perspective. Anyone has good resources on Western APTs? I remember reading from a French group that's likely state-sponsored (coucou la DGSE) but that's about it citizenlab.ca/2015/03/morg...
010
Christophe Tafani-Dereeper @christophetd.fr · 19/02/2025
@dirkjanm.io Do you have any Europe-based training planned in the coming months? (besides the Insomnihack one I will unfortunately be unable to attend - such a shame as I live in Lausanne)
000
Reposted by Christophe Tafani-Dereeper
Insomni'hack @1ns0mn1h4ck.bsky.social · 11/02/2025
📢 Christophe Tafani-Dereeper will present "Code to Cloud: Exploiting Modern Web Applications to Breach Cloud Environments" at Insomni’hack 2025! 📖 Check the full lineup and get your ticket: insomnihack.ch/talks/code-t... #INSO25 #Cybersecurity #EthicalHacking #Switzerland
022
Christophe Tafani-Dereeper @christophetd.fr · 14/02/2025
Device code phishing strikes again www.volexity.com/blog/2025/02...
volexity.com
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
Starting in mid-January 2025, Volexity identified several social-engineering and spear-phishing campaigns by Russian threat actors aimed at compromising Microsoft 365 (M365) accounts. These attack cam...
033
Christophe Tafani-Dereeper @christophetd.fr · 12/02/2025
Outstanding research by my awesome colleague @sethsec.bsky.social, along with an open-source to scan for suspicious AMIs in your own AWS account securitylabs.datadoghq.com/articles/who... github.com/DataDog/whoA...
031
Reposted by Christophe Tafani-Dereeper
Emanuel Maiberg @emanuelmaiberg.bsky.social · 27/01/2025
DeepSeek mania is driving the AI world crazy. Is the bubble popping? are we now slaves to Chinese AI? is Nvidia over? don't think so, no, and probably not www.404media.co/deepseek-man...
404media.co
DeepSeek Mania Shakes AI Industry to Its Core
/// Why a relatively unknown Chinese-developed AI model has turned the AI industry on its head.
1421550
Reposted by Christophe Tafani-Dereeper
Datadog Security Labs @securitylabs.datadoghq.com · 27/01/2025
The January edition of the Datadog Security Digest newsletter is out! securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
Threat Actor Publishing Fake GitHub PoCs, Effective Remote Work Habits, and a Methodology for Migrating Off IMDSv1 | Datadog Security Labs
In our first 2025 edition, read about a threat actor Datadog uncovered, tips for better remote work, and how to stay away from IMDSv1 in AWS.
072
Christophe Tafani-Dereeper @christophetd.fr · 23/01/2025
Outstanding write-up from @zlz.bsky.social (as always) samcurry.net/hacking-subaru • Enumeration • Account takeover via vulnerable password reset feature • 2FA bypass as it was implemented only as an UI limitation (not server-side)
samcurry.net
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State...
061