Jul 14, 2026
external
Compromised AsyncAPI npm Packages: Inside a CI Supply-Chain Attack
Attackers exploited a vulnerable GitHub Actions workflow to hijack AsyncAPI's release bot credentials, injecting malicious code into packages with 3M+ weekly downloads to steal cloud and registry tokens.
Datadog Security Labs →
supply-chainnodejscloud
Jul 9, 2026
external
Not-So-Anonymous Telemetry: The @injectivelabs/sdk-ts Backdoor
A backdoored npm package captured cryptocurrency private keys and seed phrases by intercepting wallet initialization functions and exfiltrating data disguised as legitimate telemetry.
Datadog Security Labs →
supply-chainmalwarenodejs
Dec 4, 2025
external
CVE-2025-55182 (React2Shell): RCE in React Server Components and Next.js
Analysis of a CVSS 10/10 unauthenticated RCE stemming from server-side prototype pollution in React Server Components and Next.js, with active exploitation observed in the wild.
Datadog Security Labs →
cvercenodejsweb
May 21, 2025
external
MUT-9332: Malicious VS Code Extensions Targeting Solidity Developers
Three obfuscated VS Code extensions targeting Solidity developers on Windows, attributed to threat cluster MUT-9332, deploying credential stealers and browser malware via multi-stage infection chains.
Datadog Security Labs →
threat-researchsupply-chainmalware
Mar 28, 2025
external
CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability
Deep-dive into the critical Next.js middleware flaw that lets attackers bypass authorization via the internal x-middleware-subrequest header, affecting versions 12.x through 15.x.
Datadog Security Labs →
cvenodejswebpentesting
Aug 20, 2024
external
The Gift That Keeps on Giving: A New Opportunistic Log4j Campaign
Tracking an active Log4Shell exploitation campaign delivering XMRig cryptominer payloads via obfuscated LDAP requests, with multi-stage persistence via systemd and cron.
Datadog Security Labs →
threat-researchlog4jmalware
Jul 1, 2024
external
RegreSSHion (CVE-2024-6387): Overview, Detection, and Remediation
Analysis of the critical pre-authentication RCE in OpenSSH caused by a race condition in the signal handler, and how to detect and remediate it.
Datadog Security Labs →
cverceopenssh
Oct 13, 2023
external
The Confluence CVE-2023-22515 Vulnerability: Overview, Detection, and Remediation
Deep-dive into the critical privilege escalation flaw in Atlassian Confluence, with detection logic and step-by-step remediation.
Datadog Security Labs →
confluencecvecloud
Nov 1, 2022
external
The OpenSSL Punycode Vulnerability (CVE-2022-3602): Overview, Detection, Exploitation
Analysis of the most anticipated OpenSSL vulnerability of 2022.
Datadog Security Labs →
opensslcvecryptography
Jun 7, 2022
external
The Confluence RCE Vulnerability (CVE-2022-26134): Overview, Detection, and Remediation
Analysis of the critical Confluence RCE that was actively exploited in the wild.
Datadog Security Labs →
confluencercecve
Apr 1, 2022
external
The Spring4Shell Vulnerability: Overview, Detection, and Remediation
Complete breakdown of Spring4Shell — one of the most hyped vulnerabilities of 2022.
Datadog Security Labs →
javaspringrcecve
Mar 12, 2021
Blog
The Insecure Node.js vm Module
Why the Node.js vm module is not a security boundary and how attackers escape it.
Read more → →
nodejssandbox-escapevm
Feb 20, 2017
Blog
Practical Exploitation of Error Based Sql Injection

Hi everybody I don’t post much write-ups online because most of the work done privately and under NDA.

But this time i decided to publish this (anonymously …

Read more → →
SQL-InjectionPentesting