# Credential theft

Published articles for Credential theft.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

DevFeed: [CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks](<https://devfeed.tech/articles/crowdstrike-extends-endpoint-security-to-stop-software-supply-chain-attacks-8305.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks/>)

Author: Anne Aarness - Chris Prall

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [codex](<https://devfeed.tech/tags/codex.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [endpoint-security-xdr](<https://devfeed.tech/tags/endpoint-security-xdr.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-packages](<https://devfeed.tech/tags/open-source-packages.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article describes CrowdStrike's Real-Time Supply Chain Attack Protection, embedded in the Falcon sensor, which detects and blocks malicious open-source packages before their code executes on enterprise endpoints. It explains how AI-assisted and agentic applications have expanded software supply chain risk beyond developer workstations to endpoints across the organization.

### Source excerpt

Real-Time Supply Chain Attack Protection, embedded into the Falcon sensor, blocks malicious open-source packages at download to protect the endpoint.

## Android malware creates a hidden copy of your banking app

DevFeed: [Android malware creates a hidden copy of your banking app](<https://devfeed.tech/articles/android-malware-creates-a-hidden-copy-of-your-banking-app-8435.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app>)

Author: Pieter Arntz

Published: 2026-09-11T12:14:55Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [app](<https://devfeed.tech/tags/app.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [profile](<https://devfeed.tech/tags/profile.md>), [security](<https://devfeed.tech/tags/security.md>), [transactions](<https://devfeed.tech/tags/transactions.md>)

### AI overview

Gigabud is an Android banking Trojan that creates a work profile and clones a banking app so operators can conduct fraudulent transactions separately from malware detected in the personal profile.

### Source excerpt

The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## How WhatsApp Implemented Passkey Authentication for Faster, Phishing-Resistant Sign-In

DevFeed: [How WhatsApp Implemented Passkey Authentication for Faster, Phishing-Resistant Sign-In](<https://devfeed.tech/articles/how-whatsapp-upgraded-to-secure-seamless-sign-in-for-1-billion-users-with-passkeys-22699.md>)

Original publisher: [Read original article](<http://android-developers.googleblog.com/2026/08/whatsapp-passkeys-secure-sign-in.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-27T17:00:00Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-3.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Android](<https://devfeed.tech/topics/android.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [developer](<https://devfeed.tech/tags/developer.md>), [google](<https://devfeed.tech/tags/google.md>), [meta](<https://devfeed.tech/tags/meta.md>), [sign-in](<https://devfeed.tech/tags/sign-in.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

The article describes how WhatsApp implemented passkey-based authentication to provide faster sign-ins and reduce phishing and credential-theft risks. It explains the use of public-private key cryptography, biometric or screen-lock authentication, and Android's Credential Manager API.

### Source excerpt

Posted by Niharika Arora, Senior Developer Relations Engineer, Tracy Agyemang, Product Marketing Manager, Google and Mayank Manuja, Android Engineer, Meta WhatsApp is the world's largest messaging platform, serving billions of users globally. It is the default communication tool for people across diverse regions, connecting users through private, reliable, and secure messaging. "What excites me most is the sheer scale of WhatsApp's impact. Even a small improvement to WhatsApp touches billions of users worldwide," says Mayank Manuja, an Android Engineer on the WhatsApp Registration and Access team who led the design and implementation of passkey-based authentication for WhatsApp. Building for an audience of this magnitude requires navigating a vast range of network conditions, device capabilities, and levels of digital literacy. Recognizing the potential early, WhatsApp committed to adopting passkeys in 2023, becoming one of the first major consumer apps to integrate the technology. By implementing passkeys, WhatsApp aimed to provide a fast, phishing-resistant option that significantly reduces user friction while providing robust protection against account takeovers and credential theft. A user creating a passkey on WhatsApp for faster, more secure sign-ins. The Decision to Adopt Passkeys For WhatsApp, offering multiple access methods is key to making it easier for users to stay connected and regain access when needed. Passkeys offer users a streamlined, one-tap login experience that eliminates phishing risks and functions reliably even in regions where OTP message delivery can be inconsistent. Underneath, passkeys leverage public-private key cryptography to replace manual entry with biometric or screen lock authentication. This workflow drastically improves sign-in speeds by reducing the process to a single tap via a unified, bottom-sheet interface that keeps users engaged within the app's context. The benefits are twofold: passkeys offer users a streamlined login e

## How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys

DevFeed: [How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys](<https://devfeed.tech/articles/how-whatsapp-upgraded-to-secure-seamless-sign-in-for-1-billion-users-with-passkeys-4242.md>)

Original publisher: [Read original article](<https://android-developers.googleblog.com/2026/08/whatsapp-passkeys-secure-sign-in.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-27T17:00:00Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog.md>), [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-2.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Android](<https://devfeed.tech/topics/android.md>), [App](<https://devfeed.tech/topics/app.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scale](<https://devfeed.tech/tags/scale.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

WhatsApp's adoption of passkeys provides a fast, phishing-resistant sign-in method for its large global user base. The article explains how passkeys use public-private key cryptography with biometric or screen-lock authentication, reduce reliance on inconsistent SMS OTP delivery, and simplify implementation through Android's Credential Manager API.

### Source excerpt

Posted by Niharika Arora, Senior Developer Relations Engineer, Tracy Agyemang, Product Marketing Manager, Google and Mayank Manuja, Android Engineer, Meta WhatsApp is the world's largest messaging platform, serving billions of users globally. It is the default communication tool for people across diverse regions, connecting users through private, reliable, and secure messaging. "What excites me most is the sheer scale of WhatsApp's impact. Even a small improvement to WhatsApp touches billions of users worldwide," says Mayank Manuja, an Android Engineer on the WhatsApp Registration and Access team who led the design and implementation of passkey-based authentication for WhatsApp. Building for an audience of this magnitude requires navigating a vast range of network conditions, device capabilities, and levels of digital literacy. Recognizing the potential early, WhatsApp committed to adopting passkeys in 2023, becoming one of the first major consumer apps to integrate the technology. By implementing passkeys, WhatsApp aimed to provide a fast, phishing-resistant option that significantly reduces user friction while providing robust protection against account takeovers and credential theft. A user creating a passkey on WhatsApp for faster, more secure sign-ins. The Decision to Adopt Passkeys For WhatsApp, offering multiple access methods is key to making it easier for users to stay connected and regain access when needed. Passkeys offer users a streamlined, one-tap login experience that eliminates phishing risks and functions reliably even in regions where OTP message delivery can be inconsistent. Underneath, passkeys leverage public-private key cryptography to replace manual entry with biometric or screen lock authentication. This workflow drastically improves sign-in speeds by reducing the process to a single tap via a unified, bottom-sheet interface that keeps users engaged within the app's context. The benefits are twofold: passkeys offer users a streamlined login e

## Identity Abuse Through Trusted Communication Channels

DevFeed: [Identity Abuse Through Trusted Communication Channels](<https://devfeed.tech/articles/identity-abuse-through-trusted-communication-channels-7750.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/communication-channel-identity-risks/>)

Author: Bill Batchelor

Published: 2026-08-20T10:00:25Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-theft](<https://devfeed.tech/tags/identity-theft.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-software](<https://devfeed.tech/tags/remote-access-software.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Unit 42 examines how attackers abuse trusted enterprise communication and collaboration platforms for identity phishing, impersonation, credential theft, malware delivery and social engineering. The article describes how compromised identities can make malicious activity appear legitimate within authenticated collaboration sessions and offers recommendations for detecting and defending against these attacks.

### Source excerpt

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

## N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

DevFeed: [N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it](<https://devfeed.tech/articles/n4d-mesh-controller-new-infrastructure-a-upx-packed-agent-labeled-go-titan-and-how-to-hunt-for-it-8293.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/>)

Author: Zander Mackie

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [c2](<https://devfeed.tech/tags/c2.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [go](<https://devfeed.tech/tags/go.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [persistence](<https://devfeed.tech/tags/persistence.md>)

### AI overview

Datadog Security Research analyzes an active N4D Mesh Controller malware campaign targeting exposed MCP servers and other internet-facing services. The article documents a newer UPX-packed go-titan loader-to-agent chain, rotated infrastructure, Linux persistence mechanisms, automated MCP tool discovery and command execution, and broad scanning across databases, container platforms, application servers, and AI infrastructure.

### Source excerpt

Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.

## Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

DevFeed: [Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)](<https://devfeed.tech/articles/threat-brief-mitigating-large-scale-credential-attacks-updated-august-18-7754.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/large-scale-credential-attacks/>)

Author: Unit 42

Published: 2026-08-18T19:05:33Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [password spraying](<https://devfeed.tech/topics/password-spraying.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [credential-based-attacks](<https://devfeed.tech/tags/credential-based-attacks.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [general](<https://devfeed.tech/tags/general.md>), [high-profile-threats](<https://devfeed.tech/tags/high-profile-threats.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [thehatman](<https://devfeed.tech/tags/thehatman.md>)

### AI overview

This threat brief examines large-scale credential attacks, including password spraying campaigns and claimed credential theft from Microsoft Entra tenants. It provides guidance for identifying suspicious login activity, auditing remote access logs, and hardening internet-exposed edge devices.

### Source excerpt

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.

## Inside the Modern SOC: The Identity Front Door

DevFeed: [Inside the Modern SOC: The Identity Front Door](<https://devfeed.tech/articles/inside-the-modern-soc-the-identity-front-door-7759.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/soc-identity-front-door/>)

Author: Sharon Maydar

Published: 2026-08-07T23:00:01Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [inside-the-modern-soc](<https://devfeed.tech/tags/inside-the-modern-soc.md>), [insights](<https://devfeed.tech/tags/insights.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [soc](<https://devfeed.tech/tags/soc.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [unit-42-incident-response-report](<https://devfeed.tech/tags/unit-42-incident-response-report.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines identity-based initial access, including credential theft, MFA manipulation, session hijacking, phishing, and social engineering. It describes how attackers expand access through persistence, privilege escalation, and lateral movement, challenging SOC teams to correlate signals across environments.

### Source excerpt

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.

## Deep Dive into SASL PLAIN and SCRAM in Kafka: Login Modules and Config Hot-Reload

DevFeed: [Deep Dive into SASL PLAIN and SCRAM in Kafka: Login Modules and Config Hot-Reload](<https://devfeed.tech/articles/deep-dive-into-sasl-plain-and-scram-in-kafka-login-modules-and-config-hot-reload-11553.md>)

Original publisher: [Read original article](<https://www.confluent.io/blog/kafka-authentication-sasl-plain-scram-config-hot-reload/>)

Author: Pratul Yadav

Published: 2026-07-06T09:43:40Z

Content type: article

Language: en

Sources: [Confluent: Data in motion](<https://devfeed.tech/sources/confluent-data-in-motion.md>)

Topics: [Kafka](<https://devfeed.tech/topics/kafka.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [config](<https://devfeed.tech/tags/config.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [confluent-platform](<https://devfeed.tech/tags/confluent-platform.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [kafka](<https://devfeed.tech/tags/kafka.md>), [operational](<https://devfeed.tech/tags/operational.md>), [password](<https://devfeed.tech/tags/password.md>), [production](<https://devfeed.tech/tags/production.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This article explains Kafka authentication with SASL PLAIN and SASL SCRAM, focusing on login modules, credential storage, and configuration hot-reload. It compares their security and operational characteristics and describes how hot-reload enables credential changes without restarting brokers.

### Source excerpt

Deep Dive into SASL PLAIN and SCRAM in Kafka: Login Modules and Config Hot-Reload

## Laravel Lang Supply Chain Advisory

DevFeed: [Laravel Lang Supply Chain Advisory](<https://devfeed.tech/articles/laravel-lang-supply-chain-advisory-7997.md>)

Original publisher: [Read original article](<https://snyk.io/blog/laravel-lang-supply-chain-advisory/>)

Author: Brian Clark

Published: 2026-05-23T16:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [PHP](<https://devfeed.tech/topics/php.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article examines a Laravel Lang supply-chain attack in which hundreds of historical Packagist releases for four community-maintained Laravel localization libraries were republished with malicious code. The injected Composer hook executes on PHP requests, downloads a second stage, and runs a credential stealer targeting cloud keys, Kubernetes and Vault secrets, CI/CD tokens, SSH material, environment files, browser data, password-manager vaults, crypto wallets, and messaging tokens.

### Source excerpt

Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.

## Malicious node-ipc versions published to npm in suspected maintainer account compromise

DevFeed: [Malicious node-ipc versions published to npm in suspected maintainer account compromise](<https://devfeed.tech/articles/malicious-node-ipc-versions-published-to-npm-in-suspected-maintainer-account-compromise-8010.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-node-ipc-versions-published-npm/>)

Author: Brian Vermeer

Published: 2026-05-15T00:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [incident](<https://devfeed.tech/topics/incident.md>), [releases](<https://devfeed.tech/topics/releases.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [releases](<https://devfeed.tech/tags/releases.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Multiple malicious node-ipc versions were published to npm with an obfuscated credential-stealing payload in the CommonJS bundle. The article describes a suspected maintainer-account compromise and advises affected teams to treat exposed secrets as potentially compromised and remediate vulnerable dependency paths.

### Source excerpt

On May 14, 2026, multiple malicious versions of the popular npm package node-ipc were published to the npm registry. Current public reporting identifies node...

## PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

DevFeed: [PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale](<https://devfeed.tech/articles/pcpjack-cloud-worm-evicts-teampcp-and-steals-credentials-at-scale-8311.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/>)

Author: Alex Delamotte

Published: 2026-05-07T10:00:17Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [pcpjack](<https://devfeed.tech/topics/pcpjack.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [MongoDB](<https://devfeed.tech/topics/mongodb.md>), [Redis](<https://devfeed.tech/topics/redis.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [database](<https://devfeed.tech/tags/database.md>), [docker](<https://devfeed.tech/tags/docker.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pcpjack](<https://devfeed.tech/tags/pcpjack.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [redis](<https://devfeed.tech/tags/redis.md>), [security](<https://devfeed.tech/tags/security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

SentinelLABS describes PCPJack as a credential-theft framework that spreads across exposed cloud infrastructure, removes TeamPCP-related artifacts, harvests credentials from cloud, container, developer, productivity, and financial services, and exfiltrates the data. The framework targets services including Docker, Kubernetes, Redis, MongoDB, and vulnerable web applications, with suspected monetization through fraud, spam, extortion, or resale of stolen access rather than cryptomining.

### Source excerpt

Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.

## Chainguard customers safe from new npm worm and xinference supply chain attack

DevFeed: [Chainguard customers safe from new npm worm and xinference supply chain attack](<https://devfeed.tech/articles/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack-12939.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack>)

Published: 2026-04-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Library](<https://devfeed.tech/topics/library.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-malware](<https://devfeed.tech/tags/chainguard-malware.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [github](<https://devfeed.tech/tags/github.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pypi-malware](<https://devfeed.tech/tags/pypi-malware.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [worm](<https://devfeed.tech/tags/worm.md>), [xinference](<https://devfeed.tech/tags/xinference.md>)

### AI overview

The article reports npm and PyPI malware attacks affecting 25 packages with more than 60,000 combined monthly downloads. It explains that Chainguard customers were protected because Chainguard builds from verifiable source code and rejects packages that rely on install-time scripts.

### Source excerpt

New npm and PyPI malware hit many popular packages. Chainguard customers stayed protected by blocking install scripts and rebuilding only verified source code.

## Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

DevFeed: [Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise](<https://devfeed.tech/articles/snyk-finds-prompt-injection-in-36-1467-malicious-payloads-in-a-toxicskills-study-of-agent-skills-supply-chain-compromise-8218.md>)

Original publisher: [Read original article](<https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's ToxicSkills audit examined 3,984 AI agent skills and found that 36.82% had at least one security flaw. The research identified malware, credential theft, prompt injection, exposed secrets, backdoors, and data exfiltration affecting users of OpenClaw, Claude Code, and Cursor.

### Source excerpt

Snyk's ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

## Breaking the Static Key Habit: Modernizing Ceph RGW S3 Security with STS

DevFeed: [Breaking the Static Key Habit: Modernizing Ceph RGW S3 Security with STS](<https://devfeed.tech/articles/breaking-the-static-key-habit-modernizing-ceph-rgw-s3-security-with-sts-12327.md>)

Original publisher: [Read original article](<https://ceph.io/en/news/blog/2025/rgw-modernizing-sts/>)

Author: Daniel Alexander Parkes, Anthony D'Atri

Published: 2025-12-18T00:00:00Z

Content type: tutorial

Language: en

Sources: [Ceph Blog](<https://devfeed.tech/sources/ceph-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [app](<https://devfeed.tech/tags/app.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [ceph](<https://devfeed.tech/tags/ceph.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [en-article](<https://devfeed.tech/tags/en-article.md>), [en-blog-post](<https://devfeed.tech/tags/en-blog-post.md>), [github](<https://devfeed.tech/tags/github.md>), [rgw](<https://devfeed.tech/tags/rgw.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how to replace long-lived S3 credentials in Ceph Object Gateway (RGW) applications with temporary credentials issued through Security Token Service (STS). It uses the Uber breach to illustrate how stolen static keys can enable persistent unauthorized access, and discusses credentials stored in configuration files, scripts, and CI/CD variables.

### Source excerpt

Introduction: The USD 148 Million Lesson ¶ In late 2016, Uber learned that intruders had accessed a trove of personal data stored in an Amazon S3 bucket. The entry point was painfully mundane: attackers accessed Uber's source code on GitHub using stolen credentials, found an AWS credential, and used it to access Uber's data. That single, long-lived credential exposed data on roughly 57 million users and 600,000 drivers. The breach was bad; the duration risk was worse. Static access keys do not expire. Once leaked, they remain active until someone notices, locates every instance in use, and rotates them. That makes credential theft uniquely dangerous in cloud and S3-style storage, because an attacker can repeatedly return, automate access, and quietly expand their footprint. Uber ultimately agreed to a $148 million multistate settlement related to how the incident was handled and disclosed. The exact dollar figure is not the main lesson, though. The lesson is this: a single static key can turn a small mistake into a durable breach. If you are running the Ceph Object Gateway (RGW), you face the same dynamic: S3 credentials in an application configuration file config.yaml, embedded in scripts, or stored in CI/CD variables. Each one is a long-lived credential that, once copied, can be used from anywhere the S3 endpoint is reachable. This post shows you how to eliminate static credentials using Security Token Service (STS) with temporary credentials that expire automatically. By the end, you'll understand how to implement the same security model that prevented these breaches from being even worse, and how to adapt it for Ceph RGW. The Static Credential Problem ¶ Let's take a look at some examples of how most applications access S3 storage today: # app-config.yaml (application config file) s3: endpoint: https://s3.example.com access_key: AKIA1234567890ABCDEF secret_key: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY bucket: production-data Or with the credentials embedded direc

## ECS on EC2: Covering Gaps in IMDS Hardening

DevFeed: [ECS on EC2: Covering Gaps in IMDS Hardening](<https://devfeed.tech/articles/ecs-on-ec2-covering-gaps-in-imds-hardening-29187.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2025/10/02/ecs-on-ec2-covering-gaps-in-imds-hardening/>)

Published: 2025-10-02T18:18:59Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Amazon Elastic Container Service](<https://devfeed.tech/topics/amazon-elastic-container-service.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [containers](<https://devfeed.tech/tags/containers.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [ecs](<https://devfeed.tech/tags/ecs.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article examines security gaps in Amazon ECS workloads running on EC2, focusing on task isolation and restricting access to the EC2 Instance Metadata Service. It discusses how weak isolation can expose credentials and sensitive data and outlines the need for more comprehensive hardening guidance.

### Source excerpt

Introduction # AWS ECS is a widely-adopted service across industries. To illustrate the scale and ubiquity of this service, over 2.4 billion Amazon Elastic Container Service tasks are launched every week (source) and over 65% of all new AWS containers customers use Amazon ECS (source). There are two primary launch types for ECS: Fargate and EC2. The choice between them depends on factors like cost, performance, operational overhead, and the variability of your workload.

## Rolling out Santa without freezing productivity: Tips from securing Figma's fleet

DevFeed: [Rolling out Santa without freezing productivity: Tips from securing Figma's fleet](<https://devfeed.tech/articles/rolling-out-santa-without-freezing-productivity-tips-from-securing-figma-s-fleet-10031.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/rolling-out-santa-without-freezing-productivity/>)

Author: Aaron Osborne

Published: 2025-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [App](<https://devfeed.tech/topics/app.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Script](<https://devfeed.tech/topics/script.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [browser](<https://devfeed.tech/tags/browser.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [santa](<https://devfeed.tech/tags/santa.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Figma describes rolling out Santa, an open-source binary authorization tool, across its employees' macOS laptops to improve endpoint security without disrupting productivity. The article covers monitoring-based ruleset development, user self-service for unblocking, file access authorization for browser cookies, and a staged rollout.

### Source excerpt

We scaled Santa, an open-source binary authorization tool, across all Figmates' laptops to boost endpoint security while keeping workflows seamless. Here's how we tackled the challenges and ensured a smooth rollout.

## How I gained commit access to Homebrew in 30 minutes

DevFeed: [How I gained commit access to Homebrew in 30 minutes](<https://devfeed.tech/articles/how-i-gained-commit-access-to-homebrew-in-30-minutes-31927.md>)

Original publisher: [Read original article](<http://engineering.remind.com/how-I-gained-commit-access-to-homebrew/>)

Author: Remind

Published: 2018-08-07T00:00:00Z

Content type: article

Language: en

Sources: [Remind](<https://devfeed.tech/sources/remind.md>)

Topics: [Homebrew](<https://devfeed.tech/topics/homebrew.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Environment Variables](<https://devfeed.tech/topics/environment-variables.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [GitHub API](<https://devfeed.tech/topics/github-api.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [curl](<https://devfeed.tech/tags/curl.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [github](<https://devfeed.tech/tags/github.md>), [homebrew](<https://devfeed.tech/tags/homebrew.md>), [incident](<https://devfeed.tech/tags/incident.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [npm](<https://devfeed.tech/tags/npm.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [rubygems](<https://devfeed.tech/tags/rubygems.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

A security researcher describes gaining commit access to Homebrew repositories through a GitHub API token exposed in a publicly accessible Jenkins environment. The access was tested and then reported to Homebrew maintainers, highlighting risks to package-manager infrastructure and software supply chains.

### Source excerpt

This issue was publicly disclosed on the Homebrew blog at https://brew.sh/2018/08/05/security-incident-disclosure/ Since the recent NPM, RubyGems, and Gentoo incidents, I've become increasingly interested, and concerned, with the potential for package managers to be used in supply chain attacks to distribute malicious software. Specifically with how the maintainers and infrastructure of these projects can be targeted as an attack vector. On Jun 31st, I went in with the intention of seeing if I could gain access to Homebrew's GitHub repositories. About 30 minutes later, I made my first commit to Homebrew/homebrew-core. Let's get leaky My initial strategy going in was based on credential theft; find if there were any credentials leaked by members of the Homebrew GitHub org. An OSSINT tool from Michael Henriksen called gitrob makes automating this search really easy. I ran it across the Homebrew organization, but ultimately didn't come up with anything interesting. Next, I took a look at previously disclosed issues on https://hackerone.com/Homebrew. From there, I found that Homebrew runs a Jenkins instance that's (intentionally) publicly exposed at https://jenkins.brew.sh. After some digging, I noticed something interesting; builds in the "Homebrew Bottles" project were making authenticated pushes to the BrewTestBot/homebrew-core repo: This got me thinking, "where are the credentials stored?". I noticed the "Environment Variables" link on the left, which led to an exposed GitHub API token: I tested it locally to see what scopes the token had: $ curl https://api.github.com/user/repos -u $GITHUB_API_TOKEN:x-oauth-basic | jq '.[] | {repo: .full_name, permissions: .permissions}' { "repo": "BrewTestBot/homebrew-core", "permissions": { "admin": true, "push": true, "pull": true } } { "repo": "Homebrew/brew", "permissions": { "admin": false, "push": true, "pull": true } } { "repo": "Homebrew/formulae.brew.sh", "permissions": { "admin": false, "push": true, "pull": true } } { "

## ReactOS Website Migrated to New Login System and Upgraded Components

DevFeed: [ReactOS Website Migrated to New Login System and Upgraded Components](<https://devfeed.tech/articles/website-upgraded-33256.md>)

Original publisher: [Read original article](<https://reactos.org/project-news/website-upgraded/>)

Published: 2018-07-04T00:00:00Z

Content type: release

Language: en

Sources: [Front Page on ReactOS Website](<https://devfeed.tech/sources/front-page-on-reactos-website.md>)

Topics: [ReactOS](<https://devfeed.tech/topics/reactos.md>), [Website](<https://devfeed.tech/topics/website.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Database](<https://devfeed.tech/topics/database.md>), [hashing](<https://devfeed.tech/topics/hashing.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [jira](<https://devfeed.tech/topics/jira.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [change](<https://devfeed.tech/tags/change.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [database](<https://devfeed.tech/tags/database.md>), [free](<https://devfeed.tech/tags/free.md>), [hashing](<https://devfeed.tech/tags/hashing.md>), [jira](<https://devfeed.tech/tags/jira.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [password](<https://devfeed.tech/tags/password.md>), [react](<https://devfeed.tech/tags/react.md>), [reactos](<https://devfeed.tech/tags/reactos.md>), [service](<https://devfeed.tech/tags/service.md>), [website](<https://devfeed.tech/tags/website.md>), [win32](<https://devfeed.tech/tags/win32.md>), [winapi](<https://devfeed.tech/tags/winapi.md>)

### AI overview

The ReactOS Website was migrated to a new login system, its components were upgraded, and its user database was moved and cleaned of unused accounts. The article advises users to change their passwords and notes that some newer accounts may require a password reset.

### Source excerpt

Today, the ReactOS Website has been migrated to a new Login system and all components have been upgraded to their latest versions. In the course of that, the user database has also been moved and cleaned from accounts that have never been used. Such large migrations hardly go without issues, so if you notice anything wrong, please report a bug in our JIRA bugtracker. You are also advised to change your password in the Self-Service, even if it's just to the same one.