Sign in

Datadog Security Labs

@securitylabs.datadoghq.com
628 followers 36 following 71 posts

Read our Security Labs blog: securitylabs.datadoghq.com Subscribe to our monthly newsletter: securitylabs.datadoghq.com/newslett…

PostsRepliesMedia
Datadog Security Labs @securitylabs.datadoghq.com · 24/09/2026
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) securitylabs.datadoghq.com/articles/ope...
securitylabs.datadoghq.com
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security Labs
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines.
000
Datadog Security Labs @securitylabs.datadoghq.com · 16/09/2026
Mapping out your unknown: A threat hunter’s guide to GitHub securitylabs.datadoghq.com/articles/map...
securitylabs.datadoghq.com
Mapping out your unknown: A threat hunter’s guide to GitHub | Datadog Security Labs
In this post, we walk through different threats to GitHub and how to detect them.
020
Datadog Security Labs @securitylabs.datadoghq.com · 04/08/2026
An npm worm has spread, compromising hundreds of popular npm packages to spread malware. Read our analysis and the list of compromised packages: securitylabs.datadoghq.com/articles/npm...
securitylabs.datadoghq.com
Worm compromises hundreds of popular npm packages | Datadog Security Labs
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware.
012
Datadog Security Labs @securitylabs.datadoghq.com · 14/07/2026
Compromised AsyncAPI npm packages: inside a CI supply-chain attack securitylabs.datadoghq.com/articles/com...
securitylabs.datadoghq.com
Compromised AsyncAPI npm packages: inside a CI supply-chain attack | Datadog Security Labs
On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolde...
000
Datadog Security Labs @securitylabs.datadoghq.com · 10/07/2026
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor securitylabs.datadoghq.com/articles/not...
securitylabs.datadoghq.com
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor | Datadog Security Labs
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.
000
Datadog Security Labs @securitylabs.datadoghq.com · 08/07/2026
Coordinated GitHub API enumeration and access token abuse securitylabs.datadoghq.com/articles/coo...
securitylabs.datadoghq.com
Coordinated GitHub API enumeration and access token abuse | Datadog Security Labs
Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning ...
000
Datadog Security Labs @securitylabs.datadoghq.com · 26/06/2026
Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more securitylabs.datadoghq.com/articles/gua...
000
Datadog Security Labs @securitylabs.datadoghq.com · 24/06/2026
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond securitylabs.datadoghq.com/articles/beh...
securitylabs.datadoghq.com
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond | Datadog Security Labs
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
001
Reposted by Datadog Security Labs
Hacking the Cloud @hackingthe.cloud · 17/06/2026
One Entra Agent ID blueprint can authenticate every agent identity tied to it. If that blueprint credential leaks, the blast radius can span agents, users, permissions, and even tenants. securitylabs.datadoghq.com/articles/age...
001
Datadog Security Labs @securitylabs.datadoghq.com · 24/06/2026
Mapping out your unknown: A threat hunter’s guide to Salesforce securitylabs.datadoghq.com/articles/map...
securitylabs.datadoghq.com
Mapping out your unknown: A threat hunter’s guide to Salesforce | Datadog Security Labs
In this post, we walk through different threats to Salesforce and how to detect them.
000
Datadog Security Labs @securitylabs.datadoghq.com · 23/06/2026
Detecting the Klue supply chain attack in Salesforce instances securitylabs.datadoghq.com/articles/det...
securitylabs.datadoghq.com
Detecting the Klue supply chain attack in Salesforce instances | Datadog Security Labs
We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.
010
Datadog Security Labs @securitylabs.datadoghq.com · 18/06/2026
Entra Agent ID: Inside a cross-tenant agent compromise securitylabs.datadoghq.com/articles/age... by @siigil.bsky.social
securitylabs.datadoghq.com
Entra Agent ID: Inside a cross-tenant agent compromise | Datadog Security Labs
Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard...
000
Datadog Security Labs @securitylabs.datadoghq.com · 17/06/2026
Holding blobs for ransom: Four methods for Azure Storage ransomware securitylabs.datadoghq.com/articles/azu...
securitylabs.datadoghq.com
Holding blobs for ransom: Four methods for Azure Storage ransomware | Datadog Security Labs
This post explores four vectors for threat actors to abuse Azure Storage to maliciously encrypt victim blobs, including step-by-step explanations and event codes for detection.
010
Datadog Security Labs @securitylabs.datadoghq.com · 11/06/2026
Entra Agent ID: The blueprint blast radius securitylabs.datadoghq.com/articles/age... by @siigil.bsky.social
securitylabs.datadoghq.com
Entra Agent ID: The blueprint blast radius | Datadog Security Labs
Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) t...
020
Datadog Security Labs @securitylabs.datadoghq.com · 02/06/2026
Freshly out on the Datadog Engineering blog! From single pull requests to full software packages: Detecting malicious code at scale www.datadoghq.com/blog/enginee...
datadoghq.com
Scaling malicious code detection from pull requests to the software supply chain | Datadog
Datadog scaled malicious code detection from pull requests to dependency packages using stacked LLM evaluations and agentic investigation.
021
Datadog Security Labs @securitylabs.datadoghq.com · 01/06/2026
The May edition of the Datadog Security Digest is out, with some great content from the community on cloud security, AI security and supply chain security! securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
Malicious AI skills, compromised npm packages, and 100+ intentionally vulnerable AWS environments | Datadog Security Labs
This month's edition covers supply-chain attacks on npm packages and GitHub repositories, the release of Pathfinding Labs (100+ intentionally vulnerable AWS environments), and research on malicious AI...
062
Datadog Security Labs @securitylabs.datadoghq.com · 13/05/2026
IDE-Shepherd is now on the VS Code Marketplace and Open VSX. Real-time protection against malicious extensions and supply chain attacks in VS Code and Cursor. github.com/DataDog/IDE-...
github.com
GitHub - DataDog/IDE-SHEPHERD-extension: A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE
A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE - DataDog/IDE-SHEPHERD-extension
021
Datadog Security Labs @securitylabs.datadoghq.com · 31/03/2026
Compromised axios npm package delivers cross-platform RAT securitylabs.datadoghq.com/articles/axi...
securitylabs.datadoghq.com
Compromised axios npm package delivers cross-platform RAT | Datadog Security Labs
An attacker hijacked an axios maintainer's npm account to publish malicious releases that deliver a cross-platform RAT.
044
Datadog Security Labs @securitylabs.datadoghq.com · 25/03/2026
LiteLLM compromised on PyPI: Tracing the March 2026 TeamPCP supply chain campaign securitylabs.datadoghq.com/articles/lit...
022
Datadog Security Labs @securitylabs.datadoghq.com · 11/03/2026
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos www.datadoghq.com/blog/enginee...
datadoghq.com
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos | Datadog
Learn how Datadog detected and resolved issues from hackerbot-claw, an AI-powered automated attack campaign.
072
Datadog Security Labs @securitylabs.datadoghq.com · 09/03/2026
Behind the console: Active phishing campaign targeting AWS console credentials securitylabs.datadoghq.com/articles/beh...
securitylabs.datadoghq.com
Behind the console: Active phishing campaign targeting AWS console credentials | Datadog Security Labs
Datadog Security Research identified an active adversary-in-the-middle (AiTM) phishing campaign targeting AWS Console credentials via typosquatted domains that mimic AWS infrastructure.
020
Datadog Security Labs @securitylabs.datadoghq.com · 27/02/2026
Hook, line, and vault: A technical deep dive into the 1Phish kit targeting 1Password users securitylabs.datadoghq.com/articles/hoo...
securitylabs.datadoghq.com
Hook, line, and vault: A technical deep dive into the 1Phish kit | Datadog Security Labs
We analyze the evolution of the 1Phish phishing kit from a basic credential harvester into an MFA-aware, multi-stage phishing kit targeting 1Password users.
011
Datadog Security Labs @securitylabs.datadoghq.com · 11/02/2026
Tech impersonators: ClickFix and MacOS infostealers securitylabs.datadoghq.com/articles/tec...
010
Datadog Security Labs @securitylabs.datadoghq.com · 10/02/2026
Tech impersonators: ClickFix and MacOS infostealers securitylabs.datadoghq.com/articles/tec...
securitylabs.datadoghq.com
Tech impersonators: ClickFix and MacOS infostealers | Datadog Security Labs
Datadog identified an active campaign employing fake GitHub repositories impersonating software companies and leveraging the ClickFix initial access technique to deliver macOS infostealers.
021
Datadog Security Labs @securitylabs.datadoghq.com · 26/01/2026
IDE-SHEPHERD is a new open source project to identify malicious VSCode and Cursor extensions at runtime Announcement: securitylabs.datadoghq.com/articles/ide... GitHub: github.com/DataDog/IDE-...
securitylabs.datadoghq.com
Introducing IDE-SHEPHERD: Your shield against threat actors lurking in your IDE | Datadog Security Labs
IDE-SHEPHERD is an open-source IDE security extension that provides real-time monitoring and protection for VS Code and Cursor. It intercepts malicious process executions, monitors network activity, a...
011
Datadog Security Labs @securitylabs.datadoghq.com · 09/01/2026
Decoding the GitHub recommendations for npm maintainers securitylabs.datadoghq.com/articles/dec... by @phrawzty.com
securitylabs.datadoghq.com
Decoding the GitHub recommendations for npm maintainers | Datadog Security Labs
This blog post explores the rationale and implementation behind GitHub's security recommendations for npm maintainers following numerous high-profile supply-chain incidents. It details how hardening p...
003
Datadog Security Labs @securitylabs.datadoghq.com · 17/12/2025
Introducing Pathfinding.cloud, a library of privilege escalation paths in AWS securitylabs.datadoghq.com/articles/int... by @sethsec.bsky.social
063
Datadog Security Labs @securitylabs.datadoghq.com · 10/12/2025
Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users securitylabs.datadoghq.com/articles/inv...
022
Datadog Security Labs @securitylabs.datadoghq.com · 04/12/2025
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js securitylabs.datadoghq.com/articles/cve...
164
Datadog Security Labs @securitylabs.datadoghq.com · 26/11/2025
The November Datadog Security Digest is out! • A 2025 look at real-world Kubernetes version adoption by @mccune.org.uk • Datadog threat roundup: Top insights for Q3 2025 • Analyzing network traffic from coding agents ... and more! securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
2025 threat reports, Kubernetes version adoption, and how attackers use AI | Datadog Security Labs
This edition covers 2025 threat reports, Kubernetes version adoption, and how attackers use AI
042
Datadog Security Labs @securitylabs.datadoghq.com · 26/11/2025
A few days ago, a new piece of malware started spreading in npm, compromising and backdooring hundreds of legitimate npm packages and GitHub users. Read the analysis from our security research team: securitylabs.datadoghq.com/articles/sha...
065
Datadog Security Labs @securitylabs.datadoghq.com · 06/11/2025
MUT-4831: Trojanized npm packages deliver Vidar infostealer malware securitylabs.datadoghq.com/articles/mut...
securitylabs.datadoghq.com
MUT-4831: Trojanized npm packages deliver Vidar infostealer malware | Datadog Security Labs
Analysis of a threat actor campaign targeting Windows users with Vidar infostealer malware via malicious npm packages
010
Datadog Security Labs @securitylabs.datadoghq.com · 05/11/2025
A runtime security approach to detecting supply chain attacks securitylabs.datadoghq.com/articles/sup... by Lorenzo Susini, Detection Engineer
securitylabs.datadoghq.com
A runtime security approach to detecting supply chain attacks | Datadog Security Labs
Detecting software supply chain attacks through runtime security.
120
Datadog Security Labs @securitylabs.datadoghq.com · 03/11/2025
Datadog threat roundup: Top insights for Q3 2025 securitylabs.datadoghq.com/articles/202...
securitylabs.datadoghq.com
Datadog threat roundup: Top insights for Q3 2025 | Datadog Security Labs
Threat insights from Datadog Security Labs for Q3 2025.
010
Datadog Security Labs @securitylabs.datadoghq.com · 30/10/2025
Learnings from recent npm supply chain compromises securitylabs.datadoghq.com/articles/lea...
securitylabs.datadoghq.com
Learnings from recent npm supply chain compromises | Datadog Security Labs
A look at recent npm supply chain compromises and how we can learn from them to better prepare for future incidents.
030
Datadog Security Labs @securitylabs.datadoghq.com · 30/10/2025
The October edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
The State of Cloud Security, MCP Risks, and Azure vulnerabilities | Datadog Security Labs
This edition covers The State of Cloud Security, MCP Risks, and Azure vulnerabilities
020
Datadog Security Labs @securitylabs.datadoghq.com · 28/10/2025
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing securitylabs.datadoghq.com/articles/cop... by @siigil.bsky.social
securitylabs.datadoghq.com
CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing | Datadog Security Labs
Copilot Studio links look benign, but they can host content to redirect users to arbitrary URLs. In this post, we document a method by which a Copilot Studio agent's login settings can redirect a user...
032
Datadog Security Labs @securitylabs.datadoghq.com · 08/10/2025
Our State of Cloud Security 2025 study is out! www.datadoghq.com/state-of-clo... • On AWS, 40% of organizations leverage data perimeters • 11% of Google Cloud GKE and 23% of Google Cloud VMs are overprivileged • On Azure, 1.3% of storage containers are public, 58% proactively block public access
datadoghq.com
State of Cloud Security | Datadog
For our 2025 report, we analyzed AWS, Google Cloud, and Azure data from thousands of organizations to understand the latest trends in cloud security posture.
184
Datadog Security Labs @securitylabs.datadoghq.com · 02/10/2025
The September edition of the Datadog Security Digest is out: securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
npm supply chain attacks, Amazon Bedrock security, and MCP vulnerabilities | Datadog Security Labs
This edition covers three major supply chain attacks targeting npm, two MCP security vulnerabilities, and multiple posts related to the Amazon Bedrock service.
000
Datadog Security Labs @securitylabs.datadoghq.com · 05/09/2025
In case you missed it, the August edition of the Datadog Security Digest went out last week! securitylabs.datadoghq.com/newsletters/...
securitylabs.datadoghq.com
Q2 threat report, prompt injection, and fwd:cloudsec Europe | Datadog Security Labs
This edition covers Datadog's Q2 threat report, new cloud security research, AI security vulnerabilities, application security findings, and upcoming community events
010
Datadog Security Labs @securitylabs.datadoghq.com · 26/08/2025
CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions (patched) securitylabs.datadoghq.com/articles/cla... Zander Mackie
securitylabs.datadoghq.com
CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions | Datadog Security Labs
A critical vulnerability in older versions of the Claude Code for Visual Studio Code (VS Code) and other IDE extensions allowed malicious websites to connect to unauthenticated local WebSocket servers...
010
Datadog Security Labs @securitylabs.datadoghq.com · 21/08/2025
MCP vulnerability case study: SQL injection in the Postgres MCP server. Comes with a full reproducible proof-of-concept securitylabs.datadoghq.com/articles/mcp... by Santiago Mola
securitylabs.datadoghq.com
MCP vulnerability case study: SQL injection in the Postgres MCP server | Datadog Security Labs
Learn how vulnerability in Anthropic's reference Postgres MCP server allowed us to bypass teh read-only restriction and execute arbitrary SQL statements.
012
Datadog Security Labs @securitylabs.datadoghq.com · 20/08/2025
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer by @frichetten.com securitylabs.datadoghq.com/articles/enu...
securitylabs.datadoghq.com
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
054
Datadog Security Labs @securitylabs.datadoghq.com · 31/07/2025
The July edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... • Cloud image investigator by @sethsec.bsky.social • Our top picks for Black Hat / DEF CON • A benchmark for LLM coding accuracy and security • Malicious Homebrew installation campaign .. and more
securitylabs.datadoghq.com
Preparing for Hacker Summer Camp and a new cloud image investigator | Datadog Security Labs
This month’s digest covers Hacker Summer Camp prep, a new cloud image investigator, and supply-chain vulnerabilities associated with the Open VSX Registry.
062
Datadog Security Labs @securitylabs.datadoghq.com · 29/07/2025
Datadog guide to Hacker Summer Camp 2025, amd the top 50 talks we're excited about securitylabs.datadoghq.com/articles/hac...
securitylabs.datadoghq.com
Datadog guide to Hacker Summer Camp 2025 | Datadog Security Labs
Get ready to take on Hacker Summer Camp with our guide on planning, prepping, and schedules for Datadog events.
010
Datadog Security Labs @securitylabs.datadoghq.com · 21/07/2025
Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker securitylabs.datadoghq.com/articles/bey...
securitylabs.datadoghq.com
Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker | Datadog Security Labs
This post reports on activity from the 'Mimo' threat actor.
021
Datadog Security Labs @securitylabs.datadoghq.com · 16/07/2025
I SPy: Escalating to Entra ID's Global Admin with a first-party app securitylabs.datadoghq.com/articles/i-s... by @siigil.bsky.social
securitylabs.datadoghq.com
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
021
Datadog Security Labs @securitylabs.datadoghq.com · 15/07/2025
Kubernetes security fundamentals, part 7: Public Key Infrastructure (PKI) securitylabs.datadoghq.com/articles/kub... by @mccune.org.uk
securitylabs.datadoghq.com
Kubernetes security fundamentals: PKI | Datadog Security Labs
A look at how PKI configuration in Kubernetes clusters works
061
Datadog Security Labs @securitylabs.datadoghq.com · 11/07/2025
CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems securitylabs.datadoghq.com/articles/git...
securitylabs.datadoghq.com
CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems | Datadog Security Labs
Learn more about the emerging vulnerability affecting Git.
33724
Reposted by Datadog Security Labs
Christophe Tafani-Dereeper @christophetd.fr · 23/06/2025
Stratus Red Team AWS attack techniques are now mapped to the Threat Technique Catalog for AWS Stratus Red Team AWS attack techniques: stratus-red-team.cloud/attack-techn... Threat Technique Catalog by AWS: aws-samples.github.io/threat-techn...
072