<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
  <channel>
    <title>Datadog Security Labs</title>
    <link rel="self">https://securitylabs.datadoghq.com/rss/feed.xml</link>
    <link>https://securitylabs.datadoghq.com</link>
    <description>Datadog Security Labs is the place to read blog content about security research and tooling published by Datadog for the community.</description>
    <pubDate>2026-08-04T00:00:00Z</pubDate>
    <item>
      <title>Worm compromises hundreds of popular npm packages</title>
      <link>
    https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/</link>
      <pubDate>2026-08-04T00:00:00Z</pubDate>
      <description>On August 4, 2026, several popular npm packages, including &#39;keyv&#39;, were compromised to deliver malware.</description>
    </item>
    <item>
      <title>Before the first prompt: Code execution paths in trusted coding-agent projects</title>
      <link>
    https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt/</link>
      <pubDate>2026-08-03T00:00:00Z</pubDate>
      <description>Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.</description>
    </item>
    <item>
      <title>Detection primitives for eBPF rootkits</title>
      <link>
    https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/</link>
      <pubDate>2026-07-27T00:00:00Z</pubDate>
      <description>We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act.</description>
    </item>
    <item>
      <title>Compromised AsyncAPI npm packages: inside a CI supply-chain attack</title>
      <link>
    https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packages/</link>
      <pubDate>2026-07-14T00:00:00Z</pubDate>
      <description>On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you&#39;re affected.</description>
    </item>
    <item>
      <title>Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor</title>
      <link>
    https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/</link>
      <pubDate>2026-07-09T00:00:00Z</pubDate>
      <description>A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.</description>
    </item>
    <item>
      <title>Coordinated GitHub API enumeration and access token abuse</title>
      <link>
    https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/</link>
      <pubDate>2026-07-08T00:00:00Z</pubDate>
      <description>Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories.</description>
    </item>
    <item>
      <title>Entra Agent ID: Protect, detect, respond</title>
      <link>
    https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/</link>
      <pubDate>2026-07-06T00:00:00Z</pubDate>
      <description>This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.</description>
    </item>
    <item>
      <title>Backdoors &amp; Breaches: New scenarios and adaptations</title>
      <link>
    https://securitylabs.datadoghq.com/articles/backdoors-and-breaches-new-scenarios/</link>
      <pubDate>2026-07-01T00:00:00Z</pubDate>
      <description>Sharing new scenarios and adaptations to play the Datadog expansion pack of Backdoors &amp; Breaches.</description>
    </item>
    <item>
      <title>Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more</title>
      <link>
    https://securitylabs.datadoghq.com/articles/guarddog-3-0-release/</link>
      <pubDate>2026-06-26T00:00:00Z</pubDate>
      <description>Release of GuardDog 3.0, an open-source tool to identify malicious packages, featuring a new YARA-based rules engine, a risk scoring engine, and built-in sandboxing.</description>
    </item>
    <item>
      <title>Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond</title>
      <link>
    https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/</link>
      <pubDate>2026-06-24T00:00:00Z</pubDate>
      <description>Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.</description>
    </item>
    <item>
      <title>Detecting the Klue supply chain attack in Salesforce instances</title>
      <link>
    https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/</link>
      <pubDate>2026-06-22T00:00:00Z</pubDate>
      <description>We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.</description>
    </item>
    <item>
      <title>Entra Agent ID: Inside a cross-tenant agent compromise</title>
      <link>
    https://securitylabs.datadoghq.com/articles/agent-id-inside-agent-compromise/</link>
      <pubDate>2026-06-18T00:00:00Z</pubDate>
      <description>Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard, since an attacker with control over an agent blueprint can authenticate as any agent associated with that blueprint.</description>
    </item>
    <item>
      <title>Mapping out your unknown: A threat hunter’s guide to Salesforce</title>
      <link>
    https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-salesforce/</link>
      <pubDate>2026-06-16T00:00:00Z</pubDate>
      <description>In this post, we walk through different threats to Salesforce and how to detect them.</description>
    </item>
    <item>
      <title>Holding blobs for ransom: Four methods for Azure Storage ransomware</title>
      <link>
    https://securitylabs.datadoghq.com/articles/azure-blob-storage-ransomware-four-methods/</link>
      <pubDate>2026-06-15T00:00:00Z</pubDate>
      <description>This post explores four vectors for threat actors to abuse Azure Storage to maliciously encrypt victim blobs, including step-by-step explanations and event codes for detection.</description>
    </item>
    <item>
      <title>Entra Agent ID: The blueprint blast radius</title>
      <link>
    https://securitylabs.datadoghq.com/articles/agent-id-blueprint-blast-radius/</link>
      <pubDate>2026-06-11T00:00:00Z</pubDate>
      <description>Entra Agent ID is an extension of Entra&#39;s application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent.</description>
    </item>
    <item>
      <title>The case for GitHub Actions security after recent supply chain attacks</title>
      <link>
    https://securitylabs.datadoghq.com/articles/case-for-github-actions-security/</link>
      <pubDate>2026-06-02T00:00:00Z</pubDate>
      <description>GitHub Actions workflows are vulnerable to pwn requests, script injection, and compromised credentials. Here&#39;s what&#39;s going wrong and what&#39;s changing.</description>
    </item>
    <item>
      <title>From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents</title>
      <link>
    https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents/</link>
      <pubDate>2026-05-28T00:00:00Z</pubDate>
      <description>CVE-2026-31431 (Copy Fail) lets any unprivileged user corrupt the Linux page cache via AF_ALG sockets to escalate privileges. This post covers the exploit mechanics and how Datadog Security Research used coding agents to ship a detection content pack in a single session.</description>
    </item>
    <item>
      <title>Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740</title>
      <link>
    https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/</link>
      <pubDate>2026-05-21T00:00:00Z</pubDate>
      <description>A look at how Kubernetes CVE-2021-25740 allows users with EndpointSlice access to redirect traffic via shared ingress and load balancer services.</description>
    </item>
    <item>
      <title>Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments</title>
      <link>
    https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs/</link>
      <pubDate>2026-05-18T00:00:00Z</pubDate>
      <description>Introducing Pathfinding Labs, a collection of intentionally vulnerable AWS environments for red teamers and blue teamers to deploy, exploit, and use for detection validation.</description>
    </item>
    <item>
      <title>Backdoored node-ipc npm releases steal developer credentials through DNS queries</title>
      <link>
    https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/</link>
      <pubDate>2026-05-14T00:00:00Z</pubDate>
      <description>An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.</description>
    </item>
    <item>
      <title>Backdoored Cemu release linked to TanStack and Mistral supply chain campaign</title>
      <link>
    https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/</link>
      <pubDate>2026-05-14T00:00:00Z</pubDate>
      <description>We investigate how a coordinated supply chain campaign that compromised npm and PyPI packages also backdoored the official Cemu Nintendo Wii U emulator GitHub release, reaching nearly 20,000 Linux users.</description>
    </item>
    <item>
      <title>Shai-Hulud Goes Open Source</title>
      <link>
    https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/</link>
      <pubDate>2026-05-13T00:00:00Z</pubDate>
      <description>A static analysis of the open-sourced Shai-Hulud offensive framework attributed to TeamPCP, covering its credential harvesting, supply chain poisoning, and exfiltration capabilities.</description>
    </item>
    <item>
      <title>Malicious Coding Agent Skills and the Risk of Dynamic Context</title>
      <link>
    https://securitylabs.datadoghq.com/articles/malicious-skills-supply-chain-risks-in-coding-agents-with-dynamic-context/</link>
      <pubDate>2026-05-11T00:00:00Z</pubDate>
      <description>Learn how malicious Claude Code skills can abuse dynamic context commands to execute before model-level prompt injection defenses can intervene.</description>
    </item>
    <item>
      <title>Kubernetes security fundamentals: Secrets</title>
      <link>
    https://securitylabs.datadoghq.com/articles/kubernetes-security-fundamentals-part-8/</link>
      <pubDate>2026-05-08T00:00:00Z</pubDate>
      <description>A look at how to secure Kubernetes secrets</description>
    </item>
    <item>
      <title>The case for dependency cooldowns in a post-axios world</title>
      <link>
    https://securitylabs.datadoghq.com/articles/dependency-cooldowns/</link>
      <pubDate>2026-04-16T00:00:00Z</pubDate>
      <description>Understanding npm and the importance of dependency cooldowns.</description>
    </item>
    <item>
      <title>Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562</title>
      <link>
    https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8562/</link>
      <pubDate>2026-04-09T00:00:00Z</pubDate>
      <description>A look at how Kubernetes CVE-2020-8562 allows attackers to bypass API server proxy protections using DNS rebinding</description>
    </item>
    <item>
      <title>Compromised axios npm package delivers cross-platform RAT</title>
      <link>
    https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/</link>
      <pubDate>2026-03-31T00:00:00Z</pubDate>
      <description>An attacker hijacked an axios maintainer&#39;s npm account to publish malicious releases that deliver a cross-platform RAT.</description>
    </item>
    <item>
      <title>Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561</title>
      <link>
    https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/</link>
      <pubDate>2026-03-27T00:00:00Z</pubDate>
      <description>A look at how Kubernetes CVE-2020-8561 works</description>
    </item>
    <item>
      <title>LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</title>
      <link>
    https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/</link>
      <pubDate>2026-03-24T00:00:00Z</pubDate>
      <description>On March 24 and 27, 2026, malicious PyPI releases of LiteLLM and Telnyx were published as part of the TeamPCP supply chain campaign. We trace the full campaign from Trivy through npm, Checkmarx, and into PyPI.</description>
    </item>
    <item>
      <title>Uncovering agent logging gaps in Copilot Studio</title>
      <link>
    https://securitylabs.datadoghq.com/articles/copilot-studio-logging-gaps/</link>
      <pubDate>2026-03-10T00:00:00Z</pubDate>
      <description>During research, we sometimes encounter scenarios that remind us that it&#39;s a good idea to trust but verify. In September 2025, we noticed that certain Microsoft Copilot Studio agent settings did not log certain administrative actions related to sharing, authentication, logging, and publication of Copilot Studio agents.</description>
    </item>
  </channel>
</rss>
