RCE in OpenCode, threat hunting guides, and lots of AI security

Welcome to the September 2026 edition of the Datadog Security Digest!


We hope you enjoy catching up on the latest in cloud security! This edition covers a remote code execution vulnerability in OpenCode, threat hunting, and AI seeping into all areas of security.


This newsletter was created by a real person, not a machine. Your curator of the month is Kennedy Toomey.

Discovering and exploiting a remote code execution vulnerability in OpenCode

We discovered and reported a remote code execution vulnerability in OpenCode. OpenCode has since fixed it. The post analyzes the vulnerability, the impact, and how we found it (hint: it involves cross-origin requests).

Datadog Security Labs

Mapping out your unknown: A threat hunter's guide to GitHub

In the second post of this threat hunting series, Julie Agnes Sparks and Juvenal Araujo detail how to query audit logs for threat actor behavior in GitHub environments. They describe common GitHub attack tactics, the queries that detect each one, and how to build detections from them.

Password spraying campaign targets AWS root user accounts across 150+ organizations

Martin McCloskey details how Datadog Security Research identified a password spraying campaign targeting AWS root user accounts. The post lists campaign identifiers and the queries that reveal whether you're affected.

N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

Datadog Security Research built on German Fernandez's research on N4D Mesh Controller, an active Linux malware campaign that leaves MCP servers vulnerable. Zander Mackie details the attack flow, new discoveries, and where to start your threat hunt.

AI security

Power leak: Amazon Kiro IDE prompt injection enables data exfiltration

Mindgard found a data exfiltration vulnerability in Amazon Kiro IDE, an agentic coding service. The post outlines how they discovered the vulnerability and Amazon's response.

Most neoclouds struggle with security

After analyzing multiple neocloud providers, researchers found widespread security weaknesses that bad design choices make worse. The post includes proof-of-concept exploits, specific examples, and suggested fixes.

Agents gone wild: An AI-orchestrated global campaign against PaperCut NG/MF

GreyNoise observed hundreds of AI agents using three different attack paths to compromise at least 440 instances of PaperCut NG/MF. The campaign shows how AI can accelerate the speed and spread of attacks.

Google Cloud's AI risk and resilience report 2026

This Mandiant special report highlights how resilience is changing in the AI era. The report details how adversaries use AI, offers insights for offensive and defensive security teams, and suggests ways to better secure infrastructure.

Supply chain security

OpenClaw went viral. Meet the maintainers building and securing it.

As the fastest growing GitHub project ever, OpenClaw's maintainers keep security top of mind amid rising supply chain attacks. This post covers how they manage everything from the influx of pull requests to supply chain risks.

OpenAI agents carried out an undisclosed cyber-attack on RubyGems

Thousands of packages were uploaded to RubyGems, hundreds of which were malicious. Researchers found that an OpenAI agent swarm used RubyGem's automatic build system to achieve remote code execution (RCE).

We wanted to use Baseten for inference. We ended up with admin access to Baseten GitHub repos

Alex Schapiro from Strix details how they discovered a GitHub personal access token in the build history of a public Baseten container image, which had admin access to Baseten's main repository. Baseten rotated the token quickly after disclosure, but Strix recommends checking your old images to make sure something similar doesn't happen to you.

Community events and talks

Video recordings for fwd:cloudsec Europe are available

On September 7th and 8th, the third edition of fwd:cloudsec Europe took place in London. From Datadog, Tim Gonda delivered "Cloud Security Is Dead. Long Live Infrastructure Security.", while Jules Denardou and Daniel Henkel talked about "What Could Possibly Go Wrong? Running untrusted code in the cloud."