# Credential theft

Credential theft is the act of stealing authentication data so an attacker can access accounts or systems while impersonating a legitimate user.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

DevFeed: [N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it](<https://devfeed.tech/articles/n4d-mesh-controller-new-infrastructure-a-upx-packed-agent-labeled-go-titan-and-how-to-hunt-for-it-8293.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/>)

Author: Zander Mackie

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [c2](<https://devfeed.tech/tags/c2.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [go](<https://devfeed.tech/tags/go.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [persistence](<https://devfeed.tech/tags/persistence.md>)

### AI overview

Datadog Security Research analyzes an active N4D Mesh Controller malware campaign targeting exposed MCP servers and other internet-facing services. The article documents a newer UPX-packed go-titan loader-to-agent chain, rotated infrastructure, Linux persistence mechanisms, automated MCP tool discovery and command execution, and broad scanning across databases, container platforms, application servers, and AI infrastructure.

### Source excerpt

Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.

## Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

DevFeed: [Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)](<https://devfeed.tech/articles/threat-brief-mitigating-large-scale-credential-attacks-updated-august-18-7754.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/large-scale-credential-attacks/>)

Author: Unit 42

Published: 2026-08-18T19:05:33Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [password spraying](<https://devfeed.tech/topics/password-spraying.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [credential-based-attacks](<https://devfeed.tech/tags/credential-based-attacks.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [general](<https://devfeed.tech/tags/general.md>), [high-profile-threats](<https://devfeed.tech/tags/high-profile-threats.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [thehatman](<https://devfeed.tech/tags/thehatman.md>)

### AI overview

This threat brief examines large-scale credential attacks, including password spraying campaigns and claimed credential theft from Microsoft Entra tenants. It provides guidance for identifying suspicious login activity, auditing remote access logs, and hardening internet-exposed edge devices.

### Source excerpt

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.

## Laravel Lang Supply Chain Advisory

DevFeed: [Laravel Lang Supply Chain Advisory](<https://devfeed.tech/articles/laravel-lang-supply-chain-advisory-7997.md>)

Original publisher: [Read original article](<https://snyk.io/blog/laravel-lang-supply-chain-advisory/>)

Author: Brian Clark

Published: 2026-05-23T16:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [PHP](<https://devfeed.tech/topics/php.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article examines a Laravel Lang supply-chain attack in which hundreds of historical Packagist releases for four community-maintained Laravel localization libraries were republished with malicious code. The injected Composer hook executes on PHP requests, downloads a second stage, and runs a credential stealer targeting cloud keys, Kubernetes and Vault secrets, CI/CD tokens, SSH material, environment files, browser data, password-manager vaults, crypto wallets, and messaging tokens.

### Source excerpt

Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.

## PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

DevFeed: [PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale](<https://devfeed.tech/articles/pcpjack-cloud-worm-evicts-teampcp-and-steals-credentials-at-scale-8311.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/>)

Author: Alex Delamotte

Published: 2026-05-07T10:00:17Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [pcpjack](<https://devfeed.tech/topics/pcpjack.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [MongoDB](<https://devfeed.tech/topics/mongodb.md>), [Redis](<https://devfeed.tech/topics/redis.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [database](<https://devfeed.tech/tags/database.md>), [docker](<https://devfeed.tech/tags/docker.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pcpjack](<https://devfeed.tech/tags/pcpjack.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [redis](<https://devfeed.tech/tags/redis.md>), [security](<https://devfeed.tech/tags/security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

SentinelLABS describes PCPJack as a credential-theft framework that spreads across exposed cloud infrastructure, removes TeamPCP-related artifacts, harvests credentials from cloud, container, developer, productivity, and financial services, and exfiltrates the data. The framework targets services including Docker, Kubernetes, Redis, MongoDB, and vulnerable web applications, with suspected monetization through fraud, spam, extortion, or resale of stolen access rather than cryptomining.

### Source excerpt

Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.

## Chainguard customers safe from new npm worm and xinference supply chain attack

DevFeed: [Chainguard customers safe from new npm worm and xinference supply chain attack](<https://devfeed.tech/articles/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack-12939.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack>)

Published: 2026-04-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Library](<https://devfeed.tech/topics/library.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-malware](<https://devfeed.tech/tags/chainguard-malware.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [github](<https://devfeed.tech/tags/github.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pypi-malware](<https://devfeed.tech/tags/pypi-malware.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [worm](<https://devfeed.tech/tags/worm.md>), [xinference](<https://devfeed.tech/tags/xinference.md>)

### AI overview

The article reports npm and PyPI malware attacks affecting 25 packages with more than 60,000 combined monthly downloads. It explains that Chainguard customers were protected because Chainguard builds from verifiable source code and rejects packages that rely on install-time scripts.

### Source excerpt

New npm and PyPI malware hit many popular packages. Chainguard customers stayed protected by blocking install scripts and rebuilding only verified source code.

## Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

DevFeed: [Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise](<https://devfeed.tech/articles/snyk-finds-prompt-injection-in-36-1467-malicious-payloads-in-a-toxicskills-study-of-agent-skills-supply-chain-compromise-8218.md>)

Original publisher: [Read original article](<https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's ToxicSkills audit examined 3,984 AI agent skills and found that 36.82% had at least one security flaw. The research identified malware, credential theft, prompt injection, exposed secrets, backdoors, and data exfiltration affecting users of OpenClaw, Claude Code, and Cursor.

### Source excerpt

Snyk's ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

## Breaking the Static Key Habit: Modernizing Ceph RGW S3 Security with STS

DevFeed: [Breaking the Static Key Habit: Modernizing Ceph RGW S3 Security with STS](<https://devfeed.tech/articles/breaking-the-static-key-habit-modernizing-ceph-rgw-s3-security-with-sts-12327.md>)

Original publisher: [Read original article](<https://ceph.io/en/news/blog/2025/rgw-modernizing-sts/>)

Author: Daniel Alexander Parkes, Anthony D'Atri

Published: 2025-12-18T00:00:00Z

Content type: tutorial

Language: en

Sources: [Ceph Blog](<https://devfeed.tech/sources/ceph-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [app](<https://devfeed.tech/tags/app.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [ceph](<https://devfeed.tech/tags/ceph.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [en-article](<https://devfeed.tech/tags/en-article.md>), [en-blog-post](<https://devfeed.tech/tags/en-blog-post.md>), [github](<https://devfeed.tech/tags/github.md>), [rgw](<https://devfeed.tech/tags/rgw.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how to replace long-lived S3 credentials in Ceph Object Gateway (RGW) applications with temporary credentials issued through Security Token Service (STS). It uses the Uber breach to illustrate how stolen static keys can enable persistent unauthorized access, and discusses credentials stored in configuration files, scripts, and CI/CD variables.

### Source excerpt

Introduction: The USD 148 Million Lesson ¶ In late 2016, Uber learned that intruders had accessed a trove of personal data stored in an Amazon S3 bucket. The entry point was painfully mundane: attackers accessed Uber's source code on GitHub using stolen credentials, found an AWS credential, and used it to access Uber's data. That single, long-lived credential exposed data on roughly 57 million users and 600,000 drivers. The breach was bad; the duration risk was worse. Static access keys do not expire. Once leaked, they remain active until someone notices, locates every instance in use, and rotates them. That makes credential theft uniquely dangerous in cloud and S3-style storage, because an attacker can repeatedly return, automate access, and quietly expand their footprint. Uber ultimately agreed to a $148 million multistate settlement related to how the incident was handled and disclosed. The exact dollar figure is not the main lesson, though. The lesson is this: a single static key can turn a small mistake into a durable breach. If you are running the Ceph Object Gateway (RGW), you face the same dynamic: S3 credentials in an application configuration file config.yaml, embedded in scripts, or stored in CI/CD variables. Each one is a long-lived credential that, once copied, can be used from anywhere the S3 endpoint is reachable. This post shows you how to eliminate static credentials using Security Token Service (STS) with temporary credentials that expire automatically. By the end, you'll understand how to implement the same security model that prevented these breaches from being even worse, and how to adapt it for Ceph RGW. The Static Credential Problem ¶ Let's take a look at some examples of how most applications access S3 storage today: # app-config.yaml (application config file) s3: endpoint: https://s3.example.com access_key: AKIA1234567890ABCDEF secret_key: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY bucket: production-data Or with the credentials embedded direc

## ECS on EC2: Covering Gaps in IMDS Hardening

DevFeed: [ECS on EC2: Covering Gaps in IMDS Hardening](<https://devfeed.tech/articles/ecs-on-ec2-covering-gaps-in-imds-hardening-29187.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2025/10/02/ecs-on-ec2-covering-gaps-in-imds-hardening/>)

Published: 2025-10-02T18:18:59Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Amazon Elastic Container Service](<https://devfeed.tech/topics/amazon-elastic-container-service.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [containers](<https://devfeed.tech/tags/containers.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [ecs](<https://devfeed.tech/tags/ecs.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article examines security gaps in Amazon ECS workloads running on EC2, focusing on task isolation and restricting access to the EC2 Instance Metadata Service. It discusses how weak isolation can expose credentials and sensitive data and outlines the need for more comprehensive hardening guidance.

### Source excerpt

Introduction # AWS ECS is a widely-adopted service across industries. To illustrate the scale and ubiquity of this service, over 2.4 billion Amazon Elastic Container Service tasks are launched every week (source) and over 65% of all new AWS containers customers use Amazon ECS (source). There are two primary launch types for ECS: Fargate and EC2. The choice between them depends on factors like cost, performance, operational overhead, and the variability of your workload.

## Rolling out Santa without freezing productivity: Tips from securing Figma's fleet

DevFeed: [Rolling out Santa without freezing productivity: Tips from securing Figma's fleet](<https://devfeed.tech/articles/rolling-out-santa-without-freezing-productivity-tips-from-securing-figma-s-fleet-10031.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/rolling-out-santa-without-freezing-productivity/>)

Author: Aaron Osborne

Published: 2025-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [App](<https://devfeed.tech/topics/app.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Script](<https://devfeed.tech/topics/script.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [browser](<https://devfeed.tech/tags/browser.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [santa](<https://devfeed.tech/tags/santa.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Figma describes rolling out Santa, an open-source binary authorization tool, across its employees' macOS laptops to improve endpoint security without disrupting productivity. The article covers monitoring-based ruleset development, user self-service for unblocking, file access authorization for browser cookies, and a staged rollout.

### Source excerpt

We scaled Santa, an open-source binary authorization tool, across all Figmates' laptops to boost endpoint security while keeping workflows seamless. Here's how we tackled the challenges and ensured a smooth rollout.