Sign in

Eslam Salem

@netcodex.bsky.social
326 followers 57 following 37 posts

Manager, security research @ Datadog | he/him | Chess lover | Blackhat speaker | ex Sqreen.io, Shieldfy.io | my website: eslam.io

PostsRepliesMedia
Eslam Salem @netcodex.bsky.social · 13/08/2026
Read my take about how we should as a manager think about team performance and priorities in the AI era eslamsalem.substack.com/p/01-buildin... #leadership #security
eslamsalem.substack.com
🗞️ #01 - Building is cheap now but judgment is not, eBPF vs API runtime telemetry, Inside OpenAI/HuggingFace Incident
In this issue: Code shipping velocity in the AI era moving the bottleneck not removing it, a quick breakdown of eBPF vs. API-based runtime telemetry, and three high-signal security reads.
100
Eslam Salem @netcodex.bsky.social · 09/07/2026
New in Datadog Security Labs 🚨🚨: @\injectivelabs/sdk-ts v1.20.21 shipped with a backdoor disguised as "telemetry." It hooked key derivation and sent raw seed phrases + private keys. Full breakdown + IOCs: securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor
securitylabs.datadoghq.com
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor | Datadog Security Labs
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.
000
Eslam Salem @netcodex.bsky.social · 26/11/2025
It was an interesting 72 hours tracking down the second wave of Shai Hulud campaign. It's more sophisticated and aggressive than the first one. We published all what we know about it here securitylabs.datadoghq.com/articles/sha... #npm #shaihulud #malware
securitylabs.datadoghq.com
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know | Datadog Security Labs
Learn more about the Shai-Hulud 2.0 npm worm.
030
Eslam Salem @netcodex.bsky.social · 06/11/2025
Our team tracked down a malicious campaign in NPM deploying Vidar stealer. This is the first time we see Vidar stealer distributed via supply chain attack. securitylabs.datadoghq.com/articles/mut... #npm #malware #supplychainattack
securitylabs.datadoghq.com
MUT-4831: Trojanized npm packages deliver Vidar infostealer malware | Datadog Security Labs
Analysis of a threat actor campaign targeting Windows users with Vidar infostealer malware via malicious npm packages
030
Eslam Salem @netcodex.bsky.social · 13/09/2025
I'm in love with claude code. The way it handles code writing and automates bash tasks is amazing and so convenient to me. if you are an experienced developer, know what you are doing, the tasks that usually take Weeks. You will be able to do it in Hours 🤯🤯 #claudecode #ai
121
Eslam Salem @netcodex.bsky.social · 17/06/2025
Q for developers. Do you love/hate mandatory security training? And why? #security #training #developers
000
Eslam Salem @netcodex.bsky.social · 21/05/2025
🚨 The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions! Deep dive analysis in this obfuscated campaign including (PowerShell & VBS scripts, PE malware, Malicious browser extensions even stegomalware) Enjoy reading securitylabs.datadoghq.com/articles/mut...
securitylabs.datadoghq.com
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions
022
Eslam Salem @netcodex.bsky.social · 21/05/2025
Pretty interesting threat campaign have been discovered by our research team. We will be disclosing it in couple of hours , stay tuned 😉 #threats #malicious #security_research #datadog
010
Eslam Salem @netcodex.bsky.social · 15/05/2025
Recognizing employees for a job well done is just as important as giving constructive feedback when they underperform. Balance builds growth. #Leadership #Feedback
000
Eslam Salem @netcodex.bsky.social · 14/05/2025
I don't like threat actors attribution that much because in most cases it's wrong and so easily to be forged. We still should cluster campaigns but there is no "high confidence" attribution IMHO.
000
Eslam Salem @netcodex.bsky.social · 24/04/2025
Nice work for using AI to create POC by analysis the patch diff platformsecurity.com/blog/CVE-202...
platformsecurity.com
How I Used AI to Create a Working Exploit for CVE-2025-32433 Before Public PoCs Existed
A step-by-step walkthrough of how I leveraged AI to analyze, understand, and exploit the Erlang SSH pre-authentication vulnerability (CVE-2025-32433) without any existing public proof of concept. Lear...
000
Reposted by Eslam Salem
Tib3rius @tib3rius.bsky.social · 16/04/2025
I have been told there will be a special announcement at 10am CET (that's 4am EDT btw) regarding this. I will release the info I have at that time also. Thank you for the support.
3317
Eslam Salem @netcodex.bsky.social · 15/04/2025
Any idea what will happen to the CVE program after MITRE x.com/0xTib3rius/s...
x.com
000
Reposted by Eslam Salem
Rory McCune @mccune.org.uk · 04/04/2025
It’s the tutorial room at #kubecon where we’ll be hacking up a storm in just over 30 minutes!
Picture of the tutorial room in Kubecon eu 2025
1181
Eslam Salem @netcodex.bsky.social · 01/04/2025
Interesting to see secret leaks in git still one the biggest threats in SDLC. github.blog/security/app...
github.blog
GitHub found 39M secret leaks in 2024. Here's what we're doing to help
Every minute, GitHub blocks several secrets with push protection—but secret leaks still remain one of the most common causes of security incidents. Learn how GitHub is making it easier to protect your...
011
Eslam Salem @netcodex.bsky.social · 31/03/2025
I think it's time for me to start digging into AI and LLMs. I'm not sure where to start, any advice?
010
Reposted by Eslam Salem
Rory McCune @mccune.org.uk · 27/03/2025
It's amazing how important one Phrack article from 27 years ago has been for web application security. Covering what we now call SQL Injection and SSRF (amongst other things) problems we're still trying to handle today laid out in a couple of paragraphs phrack.org/issues/54/8#...
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
26213
Eslam Salem @netcodex.bsky.social · 28/03/2025
This time we analyzed the Next.js middleware bypass vulnerability (CVE-2025-29927). Also included IP/UA trying to exploit this in the wild. securitylabs.datadoghq.com/articles/nex...
securitylabs.datadoghq.com
Understanding CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability | Datadog Security Labs
Learn how the Next.js middleware authorization bypass vulnerability works, and how to detect and remediate it.
031
Eslam Salem @netcodex.bsky.social · 25/03/2025
Our analysis and takeaways for IngressNightmare - Several vulnerabilities in the Kubernetes Ingress NGINX Controller. Enjoy! securitylabs.datadoghq.com/articles/ing...
securitylabs.datadoghq.com
The
Learn how the Kubernetes Ingress NGINX Controller vulnerabilities work, how to detect and remediate them.
000
Eslam Salem @netcodex.bsky.social · 16/12/2024
I love it when some people tells me that's is your limit, this is your ceiling. This is when I feel fire within me reignite!
010
Eslam Salem @netcodex.bsky.social · 09/12/2024
Amazing presentation about supply chain security and the amazing work we do by our leaders @techy.detectionengineering.net (Director of research) and Andrewkrug (Manager of advocacy) youtu.be/1b0RIi19qrw?...
youtu.be
AWS re:Invent 2024 - Beyond just observing, protecting your whole software supply chain (SEC406)
YouTube video by AWS Events
020
Eslam Salem @netcodex.bsky.social · 06/12/2024
Supply chain firewall in action github.com/DataDog/supp...
010
Eslam Salem @netcodex.bsky.social · 06/12/2024
We are happy to introduce our latest tool "Supply Chain Firewall" 🎉 by @ikretz.bsky.social The tool detects & prevents installation of malicious packages in local development environment. Read more securitylabs.datadoghq.com/articles/int... And give it a try github.com/DataDog/supp...
securitylabs.datadoghq.com
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs
Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages
0117
Reposted by Eslam Salem
Christophe Tafani-Dereeper @christophetd.fr · 05/12/2024
Supply-chain attack in the ultralytics PyPI package: github.com/ultralytics/... An attacker opened a pull request and pushed a commit with a malicious name, leading to CI code injection. They then backdoored versions 8.3.41 and 8.3.42 with code downloading a second-stage binary from GitHub
153
Reposted by Eslam Salem
Nick Frichette @frichetten.com · 05/12/2024
Common reasoning is that SMS 2FA is bad due to the risk of SIM swapping. It’s also bad if the telecommunications networks are hostile 😬 www.forbes.com/sites/zakdof...
forbes.com
FBI Warns iPhone And Android Users—Stop Sending Texts
US officials urge citizens to use encrypted messaging and calls wherever they can—here’s what you need to know.
1103
Eslam Salem @netcodex.bsky.social · 04/12/2024
Awesome, Stratus Red Team v2.20.0 is now available 🎉
001
Eslam Salem @netcodex.bsky.social · 03/12/2024
My Blackhat MEA arsenal presentation: "Detect Malicious Packages with Guarddog" drive.google.com/file/d/11SAN...
044
Eslam Salem @netcodex.bsky.social · 28/11/2024
Looks good, I will give it a try this weekend
020
Reposted by Eslam Salem
Zakir Durumeric @zakird.com · 27/11/2024
We released Censeye today, an open source CLI tool that makes it dramatically easier to pivot and find related assets when threat hunting on Censys instead of manually checking for potential identifying characteristics like an SSH host key. github.com/Censys-Resea...
22814
Eslam Salem @netcodex.bsky.social · 26/11/2024
They try to explain the crazy world of today's security acronyms, good luck with that 😀 #BHMEA24
000
Eslam Salem @netcodex.bsky.social · 26/11/2024
They are taking it seriously this year with hacking infrastructure #BHMEA24
010
Eslam Salem @netcodex.bsky.social · 26/11/2024
Simple way to bypass tradition WAFs in SSRF attack scenarios where you want to call IMDSv1 by @frichetten.com and @hackingthe.cloud
210
Eslam Salem @netcodex.bsky.social · 26/11/2024
On my way to #blackhatmea, come and say hi if you are around 😉
010
Reposted by Eslam Salem
Tom Stacey @t0xodile.com · 25/10/2024
Excited to release my latest research. Exploiting CORS can be a tricky in modern web apps, but there are still critical cases out there if you know what to look for. If you want to learn more about CORS exploitation, the research is available at
outpost24.com
Exploiting trust: Weaponizing permissive CORS configurations
Find out whether you’re underestimating Cross-Origin Resource Sharing (CORS) vulnerabilities in our latest research.
0194
Eslam Salem @netcodex.bsky.social · 25/11/2024
I'll prefer a customer yelling at me over a non-engaged customer every time.
100
Eslam Salem @netcodex.bsky.social · 23/11/2024
blogs.microsoft.com/on-the-issue... Microsoft crime center has seized 240 domains related to DIY phishing kit "ONNX" it's associated with egyptian threat actor. The identity uncovered by the Egyptian company Darkatlas darkatlas.io/blog/identit...
blogs.microsoft.com
Targeting the cybercrime supply chain
Microsoft’s Digital Crimes Unit (DCU) has seized 256 fraudulent websites linked to ‘MRxC0DER’, who sold phishing kits under the brand names ‘ONNX’ and ‘Caffeine’. This takedown disrupts a significant ...
000
Eslam Salem @netcodex.bsky.social · 22/11/2024
Check out the latest supply chain threat detected by Datadog Security Research
020
Eslam Salem @netcodex.bsky.social · 22/11/2024
I will be presenting Guarddog github.com/datadog/guar... at Blackhat MEA next week. If you will be there come and say Hi
github.com
GitHub - DataDog/guarddog: :snake: GuardDog is a CLI tool to Identify malicious PyPI and npm packages
:snake: :mag: GuardDog is a CLI tool to Identify malicious PyPI and npm packages - GitHub - DataDog/guarddog: :snake: GuardDog is a CLI tool to Identify malicious PyPI and npm packages
061
Eslam Salem @netcodex.bsky.social · 22/11/2024
First post @bsky.app, so good so far 👌
110