Sign in

Nick Frichette

@frichetten.com
1.6K followers 245 following 372 posts

Staff Security Researcher @datadoghq | DEF CON/Black Hat USA main stage speaker | he/him | OSCP OSWE | I turned hacking AWS into a career | Tweets are my own | Created hackingthe.cloud

PostsRepliesMedia
Nick Frichette @frichetten.com · 03/08/2026
Malicious hooks and skills get most of the attention when we talk about attacks against coding agents. Attackers have other options. In this article, we cover two ways a trusted project can execute code before the first prompt. securitylabs.datadoghq.com/articles/cod...
securitylabs.datadoghq.com
Before the first prompt: Code execution paths in trusted coding-agent projects | Datadog Security Labs
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.
110
Nick Frichette @frichetten.com · 16/07/2026
It’s amazing to think there was a time when I considered some vulnerability classes too tedious to manually validate, test, and report. Now I can encode the workflow as a skill, run it against a dataset of endpoints I've gathered, and get back findings.
020
Nick Frichette @frichetten.com · 10/07/2026
Hotel Wi-Fi broke my Tailscale peer relay, so I wrote up how I tracked down the blocked UDP path and made the setup more resilient. If you use peer relays, this may save you a headache. frichetten.com/blog/how-hot...
frichetten.com
How Hotel Wi-Fi Broke My Tailscale Peer Relay
How to setup Tailscale peer relays to listen on multiple ports.
083
Nick Frichette @frichetten.com · 09/06/2026
I’m so excited to share what we’ve been working on: AI Guard for Coding Agents. Months ago Datadog Security Research, saw the risk posed to coding agents like Claude, Cursor, Codex and more. We knew we needed a solution to help secure these important agentic tools.
441
Nick Frichette @frichetten.com · 02/06/2026
@fwdcloudsec.org has been incredibly inspiring. So many talented researchers, so much great work, and the energy here made me want to go chase down some AWS ideas I've been sitting on. Love this community.
020
Nick Frichette @frichetten.com · 01/06/2026
Good morning fwd:cloudsec!! The best cloud security conference on earth is happening today and tomorrow! Didn’t manage to get a ticket? Join remotely! All talks are live-streamed to the official YouTube channel.
030
Nick Frichette @frichetten.com · 27/05/2026
Interested in attending @fwdcloudsec.org but bummed you didn’t get a ticket? There are a few for sale from people who couldn’t make it last minute. Check out the Cloud Security Forum Slack to get yours and attend the best cloud security conference on earth.
010
Nick Frichette @frichetten.com · 27/05/2026
Looks like the latest version of Codex has a required review/trust system for hooks. This is a great way to protect developers as threat actors have started to abuse hooks more and more.
041
Nick Frichette @frichetten.com · 20/05/2026
A malicious VS Code extension was reportedly enough to compromise a GitHub employee device and expose internal repositories. That should make every security team ask: What’s running inside our developers’ IDEs? github.com/DataDog/IDE-...
github.com
GitHub - DataDog/IDE-SHEPHERD-extension: A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE
A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE - DataDog/IDE-SHEPHERD-extension
140
Nick Frichette @frichetten.com · 12/05/2026
Malicious skills are evolving, and attackers are finding ways to execute them before model-level defenses even activate. In the first post of our new series, I’ll show you how dynamic context in coding agents can introduce new supply chain risks: securitylabs.datadoghq.com/articles/mal...
securitylabs.datadoghq.com
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
Learn how malicious Claude Code skills can abuse dynamic context commands to execute before model-level prompt injection defenses can intervene.
041
Nick Frichette @frichetten.com · 11/05/2026
It’s been a long time since a research target called to me this loudly. claude.com/blog/claude-...
claude.com
Introducing the Claude Platform on AWS | Claude
The Claude Platform on AWS is now generally available, offering a new way for AWS customers to access the full set of Claude platform features with AWS authentication, billing, and commitment retireme...
130
Nick Frichette @frichetten.com · 06/05/2026
If you’re worried about coding agent security and are only focused on malicious skills, you’re missing like 80% of the total attack surface.
140
Nick Frichette @frichetten.com · 05/05/2026
Bummer, it looks like Anthropic removed the ability to DoS their models with the magic string. This was a fun technique that had some security ramifications where you could kill an inference session. It was fun while it lasted!
182
Nick Frichette @frichetten.com · 17/03/2026
New on Hacking the Cloud! Raajhesh Kannaa Chidambaram covers Daniel Grzelak's research on how AWS error messages can reveal publicly exposed resources, without needing access! This article covers how to use them for enumeration and detection. hackingthe.cloud/aws/enumerat...
hackingthe.cloud
Detect Public Resource Exposure via Session Policy Error Messages - Hacking The Cloud
Use session policy denials and verbose IAM error messages to determine if AWS resources have public resource-based policies.
020
Nick Frichette @frichetten.com · 11/03/2026
Researchers have been warning about this for years. Compromise a developer laptop → steal tokens → pivot to cloud. In many orgs that path ends with AWS admin in minutes. thehackernews.com/2026/03/unc6...
thehackernews.com
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours
UNC6426 used stolen GitHub tokens from the 2025 nx npm breach to gain AWS admin access in under 72 hours, enabling data theft and cloud destruction.
0118
Nick Frichette @frichetten.com · 10/03/2026
Datadog Security Research continues to push the boundaries of modern cloud security—including AI security! @siigil.bsky.social shares her finding on logging gaps affecting Copilot Studio, allowing adversaries to evade detection. securitylabs.datadoghq.com/articles/cop...
securitylabs.datadoghq.com
Uncovering agent logging gaps in Copilot Studio | Datadog Security Labs
During research, we sometimes encounter scenarios that remind us that it's a good idea to trust but verify. In September 2025, we noticed that certain Microsoft Copilot Studio agent settings did not l...
010
Nick Frichette @frichetten.com · 06/03/2026
Datadog 🤝 Okta: "The enhanced logic developed by Datadog’s own Security Research team during this collaboration has been contributed back to the public Okta Security Detection Catalog, ensuring that the broader security community benefits from this joint research" sec.okta.com/articles/202...
sec.okta.com
Datadog and Okta Combine for New Customer Detections
Comprehensive monitoring of identity activity is crucial to the security of any organization. A compromised identity can lead to widespread data breaches and
030
Nick Frichette @frichetten.com · 04/03/2026
"permitted a single ECS task role "read access to every secret in the account, including the production Redshift master credential."" There is a lot going on with this (even if not all of it can be believed). Properly scoping IAM is critical! www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
LexisNexis confirms data breach as hackers leak stolen files
American data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business information.
010
Nick Frichette @frichetten.com · 04/03/2026
😬
020
Nick Frichette @frichetten.com · 25/02/2026
I get the appeal of “human-in-the-loop” for AI safeguards. But humans have been getting socially engineered for millennia. That’s not exactly a hard security boundary 😬
130
Nick Frichette @frichetten.com · 24/02/2026
Sometimes I miss Jia Tan.
001
Nick Frichette @frichetten.com · 20/02/2026
Hey wake up! New offensive AWS meta just dropped! Thanks to Daniel Grzelak, we now have an effective oracle for determining if resources are publicly exposed without leaving logs. (As an offsec person) LFG!!! www.plerion.com/blog/dont-ex...
plerion.com
Don’t expose yourself in public — let AWS error messages do it for you
AWS now reveals public permissions in error messages. Learn how a deny-all session policy exposes which actions would succeed safely.
022
Nick Frichette @frichetten.com · 17/02/2026
If anyone is interested, I built a framework to use Claude Code or Codex to act as a virtual DM for DND. State is stored on the filesystem and persists between sessions. I think Opus 4.6 is the ideal model for this but Codex works too. github.com/Frichetten/D...
github.com
GitHub - Frichetten/Dungeons-and-Agents: Make Codex or Claude Code act as a virtual dungeon master for DND 5e.
Make Codex or Claude Code act as a virtual dungeon master for DND 5e. - Frichetten/Dungeons-and-Agents
020
Nick Frichette @frichetten.com · 13/02/2026
Professional communication
020
Nick Frichette @frichetten.com · 10/02/2026
New on Hacking the Cloud! A look at how a familiar container escape pattern shows up in GCP Cloud Workstations. We trace a path from a container to service account. If you’re using Cloud Workstations, this is a useful model to keep in mind. hackingthe.cloud/gcp/exploita...
hackingthe.cloud
GCP Cloud Workstations Privilege Escalation - Hacking The Cloud
Break out of a Cloud Workstations container through an exposed Docker socket, then access project credentials from instance metadata.
000
Nick Frichette @frichetten.com · 09/02/2026
Just got my ticket to @fwdcloudsec.org! Looking forward to the best cloud security conference in the world!
020
Nick Frichette @frichetten.com · 03/02/2026
If you’re putting AI agents anywhere near prod, this is worth a read. We built AI Guard to help teams monitor prompts, tool calls, and model behavior in real systems, identifying and blocking AI threats in real time. More here: www.datadoghq.com/blog/ai-guard/
datadoghq.com
Protect agentic AI applications with Datadog AI Guard | Datadog
Learn how Datadog AI Guard evaluates prompts, responses, and tool calls in real time to help you defend agentic AI applications against emerging threats.
022
Nick Frichette @frichetten.com · 02/02/2026
New on Hacking the Cloud: Ben Stevens documents a new method for extracting IAM creds from an AWS Console session. Useful for post-exploitation and evasion tradecraft. I've been meaning to cover this for years. Glad it’s finally live: hackingthe.cloud/aws/post_exp...
hackingthe.cloud
Get IAM Credentials from a Console Session - Hacking The Cloud
Convert access to the AWS Console into IAM credentials.
040
Nick Frichette @frichetten.com · 30/01/2026
As AI agents get more autonomous, prompt injection will shift from “ignore all previous instructions” to “add a task to the backlog to X.” Once the payload crosses a trust boundary and lands in Jira, it’s no longer a prompt, it’s just another task. A task that makes me admin :D
241
Nick Frichette @frichetten.com · 28/01/2026
Houses are bullshit
130
Nick Frichette @frichetten.com · 27/01/2026
Want a clear analysis of the latest OpenSSL CMS/PKCS#12 vulnerabilities and their real-world impact? Our post explains the conditions required for exploitation and how to evaluate practical risk in your environment. securitylabs.datadoghq.com/articles/ope...
securitylabs.datadoghq.com
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows | Datadog Security Labs
A deep dive into OpenSSL’s January 2026 CMS and PKCS#12 vulnerabilities, including a pre-auth stack overflow and a PKCS#12 parsing bug.
051
Nick Frichette @frichetten.com · 26/01/2026
AI workloads are landing in the same AWS/Azure/GCP accounts we’ve been breaking into (and defending) for years. It's time for Hacking the Cloud to catch up. We're announcing a call for research! Share your AI and LLM sec research with thousands of readers hackingthe.cloud/blog/call_fo...
hackingthe.cloud
Call for research: AI and LLM security - Hacking The Cloud
Hacking the Cloud is opening the door to AI and LLM security research.
121
Nick Frichette @frichetten.com · 26/01/2026
IDEs are the new browser: massive attack surface, privileged access to various things, and lots of “just trust it.” Today the Security Research Team at Datadog dropped IDE-SHEPHERD: a tool that watches extensions at runtime and blocks dangerous behavior. securitylabs.datadoghq.com/articles/ide...
securitylabs.datadoghq.com
Introducing IDE-SHEPHERD: Your shield against threat actors lurking in your IDE | Datadog Security Labs
IDE-SHEPHERD is an open-source IDE security extension that provides real-time monitoring and protection for VS Code and Cursor. It intercepts malicious process executions, monitors network activity, a...
031
Nick Frichette @frichetten.com · 26/01/2026
I'm skeptical of the claim that 1,000 Clawdbot instances are publicly facing on the internet. If you look at the Shodan output, most of those boxes don't have port 18789 exposed (default Clawdbot port). The references to 18789 are from mDNS. Take this one for example:
030
Nick Frichette @frichetten.com · 24/01/2026
Trying out clawdbot! And I'll live tweet my experiences setting it up and using it. It's been all of my timeline and doing cool things. (see @ajs.bsky.social's post below). I'm running this on an Ubuntu VM managed through KVM with 6 cores and 16 gigs of ram. aaronstuyvenberg.com/posts/clawd-...
aaronstuyvenberg.com
Clawdbot bought me a car
Outsourcing the painful aspects of a car purchase to AI was refreshingly nice, and sold me on the vision of Clawdbot
200
Nick Frichette @frichetten.com · 21/01/2026
Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details: hackingthe.cloud/ai-llm/explo...
hackingthe.cloud
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud
How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.
0101
Nick Frichette @frichetten.com · 19/01/2026
We are on the verge of the commoditization of exploitation. Every vuln will functionally have a public PoC available because attackers can generate them in minutes. The advantage will increasingly belong to organizations that can detect, respond, and contain fast. sean.heelan.io/2026/01/18/o...
sean.heelan.io
On the Coming Industrialisation of Exploit Generation with LLMs
Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…
052
Nick Frichette @frichetten.com · 15/01/2026
Very cool research on a CodeBuild misconfiguration which could have had significant consequences. I’m a bit disappointed that there wasn’t more done to secure the supply chain after the Q Developer incident. www.wiz.io/blog/wiz-res...
wiz.io
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
032
Nick Frichette @frichetten.com · 14/01/2026
We’re hiring! Join the Datadog Security Research team as a Senior Security Researcher specializing in GenAI and help shape the future of AI security! careers.datadoghq.com/detail/75146...
careers.datadoghq.com
Senior Security Researcher - GenAI | Datadog Careers
We're building a platform that engineers love to use. Join us, and help usher in the future.
111
Nick Frichette @frichetten.com · 12/01/2026
Fiber internet is breaking my brain. Streaming 4K video from my home server to my phone over the internet. It doesn’t even stutter. Insane.
040
Nick Frichette @frichetten.com · 05/01/2026
The 2025 Hacking the Cloud: Year in Review is out! We take a look at the growing tide of software supply chain attacks, discuss the most critical cloud vuln discovered to date, and share some stats for the site! hackingthe.cloud/blog/2025_wr...
hackingthe.cloud
2025 Hacking the Cloud: Year in Review - Hacking The Cloud
An end of year summary for Hacking the Cloud in 2025.
052
Nick Frichette @frichetten.com · 18/12/2025
New on @hackingthe.cloud, did you know that attackers can prevent you from kicking them out of your environment in certain situations? Eduard Agavriloae shares his research on how attackers can nullify containment attempts! hackingthe.cloud/aws/post_exp...
hackingthe.cloud
IAM Persistence through Eventual Consistency - Hacking The Cloud
Abuse IAM's eventual consistency to maintain persistence against incident response containment.
061
Nick Frichette @frichetten.com · 16/12/2025
I’m running behind on PRs, DMs, the Hacking the cloud EoY report, etc. I will catch up in time, I’m just trying to rest and heal this horrible fever.
120
Nick Frichette @frichetten.com · 03/12/2025
Currently backed myself into a corner by ignoring my own advice: When researching vulns in a cloud service, learn how the service works BEFORE you start hunting. Do it in the reverse order and you’ll end up with a vuln you can’t tie to real impact, because you never learned how harm could occur.
051
Nick Frichette @frichetten.com · 24/11/2025
If you’re messing with the AWS console in Burp Suite and getting some weird errors when trying to HEAD S3 buckets, go into your proxy listener settings and turn OFF HTTP/2 support. I was baffled for a bit trying to get a service to work and that solved it.
130
Nick Frichette @frichetten.com · 02/10/2025
Ah yes, the alloy known as '<span class="no-text-formatting">white gold</span>'
060
Nick Frichette @frichetten.com · 01/10/2025
Today in weird things family members say about technology, this is “the weird internet frisbee”.
1101
Nick Frichette @frichetten.com · 29/09/2025
New on @hackingthe.cloud! A great post by Federico Lucini on bypassing AWS Network Firewall egress filtering! hackingthe.cloud/aws/post_exp...
hackingthe.cloud
AWS Network Firewall Egress Filtering Bypass - Hacking The Cloud
Bypass AWS Network Firewall Egress Filtering using SNI spoofing and Host Header manipulation.
063
Nick Frichette @frichetten.com · 23/09/2025
Are you interested in pushing the boundaries of Gen AI security? Do you want to join an accomplished team of researchers, software engineers, and hackers? Join us! careers.datadoghq.com/detail/71207...
careers.datadoghq.com
Senior Security Researcher - GenAI | Datadog Careers
We're building a platform that engineers love to use. Join us, and help usher in the future.
111
Nick Frichette @frichetten.com · 22/09/2025
Shout out to @flekyy90.bsky.social for not one, but two new articles on Hacking the Cloud! If you're interesting in learning more persistence methods definitely check them out! hackingthe.cloud/aws/post_exp...
hackingthe.cloud
AWS CodeBuild GitHub Runner Persistence - Hacking The Cloud
Abusing the CodeBuild managed GitHub Actions runner integration to obtain long‑term access to an AWS environment.
160