The one about AI guardrails, container escapes, and supply-chain trust
This edition covers AI guardrails, container escape risks, cloud credential exposure, and supply-chain trust failures across npm and Python ecosystems.
View newsletterGet the latest insights from the cloud security community and Security Labs posts, delivered to your inbox monthly. No spam.
This edition covers AI guardrails, container escape risks, cloud credential exposure, and supply-chain trust failures across npm and Python ecosystems.
View newsletterThis edition covers some new developments in cloud security using Firecracker microVMs, some ideas for using LLMs for security work, and hopeful signs in the supply chain security world.
View newsletterThis edition covers autonomous offensive security agents tested against intentionally vulnerable cloud environments, impactful application security bugs affecting Instagram and GitHub, and links to fwd:cloudsec North America 2026 talk recordings.
View newsletterThis month's edition covers supply-chain attacks on npm packages and GitHub repositories, the release of Pathfinding Labs (100+ intentionally vulnerable AWS environments), and research on malicious AI coding agent skills.
View newsletterThis edition covers the axios compromise, two deep dives into unpatchable Kubernetes vulnerabilities, and all things AI security.
View newsletterThis edition covers a major supply chain campaign by TeamPCP, agentic browser hijacking, prompt injection in the wild, MCP tool poisoning, a self-replicating npm worm, and a CVSS 10.0 RCE in n8n.
View newsletterThis edition covers the launch of the state of DevSecOps report, a set of new AI vulnerabilities and an interesting Kubernetes vulnerability
View newsletterThis edition covers the launch of an AWS IAM privilege escalation knowledge base, a prompt injection knowledge base, and multiple exciting vulnerable disclosure write-ups.
View newsletterThis edition covers Shai-Hulud 2.0 and a RCE vulnerability in React
View newsletterThis edition covers 2025 threat reports, Kubernetes version adoption, and how attackers use AI
View newsletterThis edition covers The State of Cloud Security, MCP Risks, and Azure vulnerabilities
View newsletterThis edition covers three major supply chain attacks targeting npm, two MCP security vulnerabilities, and multiple posts related to the Amazon Bedrock service.
View newsletterThis edition covers Datadog's Q2 threat report, new cloud security research, AI security vulnerabilities, application security findings, and upcoming community events
View newsletterThis month’s digest covers Hacker Summer Camp prep, a new cloud image investigator, and supply-chain vulnerabilities associated with the Open VSX Registry.
View newsletterThis month's digest covers attackers targeting cloud environments and developers, a smart way to abuse Dependabot, and exciting upcoming talks at fwd:cloudsec North America.
View newsletterThe state of DevSecOps, MCP risks, and raiding Redis—here is what you need to know.
View newsletterLLMs, leaks, and exploits - From AI threats to GitHub attacks, here is what you need to know
View newsletterThis month’s digest has a little bit of everything—cloud threats, supply chain attacks, and a reminder that yes, attackers are still exploiting SSRFs.
View newsletterThis February edition of the Datadog Security Digest dives into the "whoAMI" attack, modern phishing tactics, and Kubernetes security. It features a threat roundup for the end of 2024 and details on spotting malicious Entra ID applications.
View newsletterIn our first 2025 edition, read about a threat actor Datadog uncovered, tips for better remote work, and how to stay away from IMDSv1 in AWS.
View newsletterIn the November edition, read about Google Cloud Trends, DPRK npm Threats, & Privilege Escalation Walkthroughs, and more.
View newsletterIn this October edition, read about our State of Cloud Security research, default service accounts in Google Cloud, and more.
View newsletterIn this September edition, read about fwd:cloudsec Europe, malicious Python packages, and a new platform in Stratus Red Team.
View newsletterWe had a great time in Las Vegas meeting and interacting with the community. Several of our Datadogs presented at BlackHat, DEFCON, and BSides Las Vegas. Here are a few highlights...
View newsletter