Universal Vulnerability Intelligence (UVI)
Real-time multi-source threat consensus across 111 synchronized global feeds, active zero-days, and supply chain malware.
Total Consolidated Threats
11,090
๐จ 1,695+ Zero-Daysโข๐ป 5,307 Workstationโข๐ก๏ธ 9,203 Non-CVEโข๐ก 107 Informational
Triage Methodology:
Layout:
Showing page 1 of 222 (11,090 matched advisories out of 11,090 total)
| Identifier | Threat & Target Summary | Date / Ageโ | Exploitation Reality |
|---|---|---|---|
UVI-2021-44228 CVE-2021-44228CVE-2021-45046 | Apache Log4j2 JNDI Message Lookup Remote Code Execution (Log4Shell) Unauthenticated remote code execution via recursive JNDI resolution in log messages across enterprise Java applications. ๐ฆ Apache Log4j2.0-beta9 - 2.14.1(fix: 2.17.1) CWE-502: Deserialization of Untrusted Data๐ก 3 feed signals๐ป Direct Build Impact | 2021-12-10โฑ๏ธ4y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2024-3094 CVE-2024-3094 | XZ Utils / Liblzma Upstream Supply Chain Backdoor in sshd Authentication Critical malicious backdoor inserted into xz-utils liblzma enabling unauthorized authentication bypass in OpenSSH daemon. ๐ฆ xz-utils / liblzma5.6.0 - 5.6.1(fix: 5.6.1-r1 / 5.4.6 LTS)๐ฆ OpenSSH Daemon (via libsystemd)Fedora 40, Rawhide, Debian Sid(fix: Reverted to 5.4.x) CWE-506: Embedded Malicious Code๐ก 4 feed signals๐ป Direct Build Impact | 2024-03-29โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-27982 CVE-2024-27982 | Node.js Child Process Windows Batch File Command Injection (BatBadBut) Improper argument escaping in child_process.spawn on Windows permits arbitrary shell command execution via batch files (.bat/.cmd). ๐ฆ Node.js (Windows)<18.20.2, <20.12.2, <21.7.2(fix: 20.12.2 LTS) CWE-78: Improper Neutralization of Special Elements used in an OS Command๐ก 3 feed signals๐ป Direct Build Impact | 2024-04-10โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-21626 CVE-2024-21626 | runc Leaked Host File Descriptor Host Root Filesystem Overwrite Container Breakout Vulnerability in runc allows malicious container images or exec sessions to overwrite host binaries and achieve full host breakout. ๐ฆ runc / Docker / Containerd<=1.1.11(fix: 1.1.12) CWE-403: Exposure of File Descriptor to Unintended Control Sphere๐ก 3 feed signals๐ป Direct Build Impact | 2024-01-31โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-24576 CVE-2024-24576 | Rust std::process Command Argument Injection on Windows (BatBadBut) Improper command-line argument escaping in Rust standard library on Windows enables arbitrary command execution. ๐ฆ Rust Standard Library (Windows)<1.77.2(fix: 1.77.2) CWE-78: Improper Neutralization of Special Elements used in an OS Command๐ก 2 feed signals๐ป Direct Build Impact | 2024-04-09โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-6387 CVE-2024-6387 | OpenSSH Server RegreSSHion Pre-Authentication Remote Code Execution Signal handler race condition in OpenSSH daemon permits unauthenticated remote code execution as root on glibc Linux systems. ๐ฆ OpenSSH sshd (Linux glibc)8.5p1 - 9.7p1(fix: 9.8p1) CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization๐ก 2 feed signals๐ป Direct Build Impact | 2024-07-01โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2024-38063 CVE-2024-38063 | Windows TCP/IP Stack IPv6 Packet Processing Remote Code Execution Zero-click remote code execution in Windows TCP/IP kernel stack triggered by specially crafted IPv6 packets. ๐ฆ Microsoft Windows TCP/IP Stack (tcpip.sys)Windows 10, 11, Server 2016-2022(fix: August 2024 Patch Tuesday) CWE-191: Integer Underflow (Wrap or Confusion)๐ก 2 feed signals๐ป Direct Build Impact | 2024-08-13โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2023-44487 CVE-2023-44487 | HTTP/2 Rapid Reset Stream Multiplexing Distributed Denial of Service Flaw in HTTP/2 protocol stream cancellation permits unprecedented distributed denial of service volumetric attacks. ๐ฆ HTTP/2 Protocol Implementations (Envoy, NGINX, Go, Apache)All HTTP/2 implementations prior to Oct 2023(fix: Vendor updates) CWE-400: Uncontrolled Resource Consumption๐ก 2 feed signals | 2023-10-10โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2023-38545 CVE-2023-38545 | libcurl SOCKS5 Hostname Resolution Heap Buffer Overflow Heap-based buffer overflow in libcurl during SOCKS5 proxy handshake permits arbitrary code execution or crash. ๐ฆ libcurl / curl command line7.69.0 - 8.3.0(fix: 8.4.0) CWE-122: Heap-based Buffer Overflow๐ก 2 feed signals๐ป Direct Build Impact | 2023-10-11โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-32002 CVE-2024-32002CVE-2024-32004 | Git Client Recursive Clone Remote Code Execution via Malicious Submodules Vulnerability in Git client allows arbitrary code execution during 'git clone --recursive' on case-insensitive filesystems (Windows/macOS). ๐ฆ Git Core Client<2.45.1, <2.44.1, <2.43.4(fix: 2.45.1) CWE-178: Improper Handling of Case Sensitivity๐ก 3 feed signals๐ป Direct Build Impact | 2024-05-14โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2023-4863 CVE-2023-4863CVE-2023-5129 | libwebp Lossless Image Decoding Heap Buffer Overflow Zero-Day Actively exploited heap buffer overflow in libwebp library enables remote code execution when rendering malicious WebP images. ๐ฆ libwebp / Electron / Chromium<1.3.2(fix: 1.3.2) CWE-122: Heap-based Buffer Overflow๐ก 2 feed signals๐ป Direct Build Impact | 2023-09-12โฑ๏ธ3y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2022-22963 CVE-2022-22965 | Spring Cloud Function & Framework SpEL ClassLoader Remote Code Execution (Spring4Shell) Unauthenticated remote code execution in Spring Framework via class binding on Java 9+ runtimes. ๐ฆ Spring Framework5.3.0 - 5.3.17, 5.2.0 - 5.2.19(fix: 5.3.18) CWE-94: Improper Control of Generation of Code ('Code Injection')๐ก 2 feed signals๐ป Direct Build Impact | 2022-03-31โฑ๏ธ4y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2023-5044 CVE-2023-5044 | Kubernetes Ingress-Nginx Incomplete Annotation Validation Arbitrary Code Injection Improper input sanitization in ingress-nginx annotations allows arbitrary code execution and cluster credential theft. ๐ฆ Kubernetes ingress-nginx<1.9.0(fix: 1.9.0) CWE-94: Code Injection๐ก 2 feed signals๐ป Direct Build Impact | 2023-10-25โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2024-4291 CVE-2024-4291 | Large-Scale PyPI and npm Package Typosquatting Credential Exfiltration Campaign Automated distribution of over 300 trojanized open-source packages executing postinstall scripts to steal SSH keys and AWS secrets. ๐ฆ Multiple PyPI & npm typosquats300+ packages(fix: Yanked / Quarantined) CWE-506: Embedded Malicious Code๐ก 3 feed signals๐ป Direct Build Impact | 2024-05-08โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2023-4911 CVE-2023-4911 | glibc Dynamic Loader Buffer Overflow via GLIBC_TUNABLES (Looney Tunables) Local privilege escalation to root in GNU C library dynamic loader triggered by crafted GLIBC_TUNABLES environment variable. ๐ฆ GNU C Library (glibc)2.34 - 2.38(fix: 2.38-r1) CWE-122: Heap-based Buffer Overflow๐ก 2 feed signals๐ป Direct Build Impact | 2023-10-03โฑ๏ธ2y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2023-36742 CVE-2023-36742 | Visual Studio Code / Electron Workspace Trust Command Injection Bypass Bypass of Workspace Trust security boundary permits arbitrary code execution upon opening untrusted git repositories. ๐ฆ Visual Studio Code<1.83.1(fix: 1.83.1) CWE-94: Code Injection๐ก 2 feed signals๐ป Direct Build Impact | 2023-09-12โฑ๏ธ3y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-23897 CVE-2024-23897 | Jenkins Core CLI args4j Arbitrary File Read and Remote Code Execution Unauthenticated arbitrary file read on Jenkins controllers via args4j @ file expansion feature leading to full server takeover. ๐ฆ Jenkins Core<=2.441, LTS <=2.426.2(fix: 2.442 / LTS 2.426.3) CWE-22: Improper Limitation of a Pathname to a Restricted Directory๐ก 2 feed signals๐ป Direct Build Impact | 2024-01-24โฑ๏ธ2y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2024-21624 CVE-2024-21624 | Docker Desktop Windows and macOS Host File Overwrite Vulnerability Symlink traversal vulnerability in Docker Desktop container mount synchronization allows host filesystem write. ๐ฆ Docker Desktop (Windows/macOS)<4.27.0(fix: 4.27.0) CWE-59: Improper Link Resolution Before File Access๐ก 2 feed signals๐ป Direct Build Impact | 2024-02-01โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2021-3156 CVE-2021-3156 | Sudo Heap-Based Buffer Overflow Local Root Privilege Escalation (Baron Samedit) Heap buffer overflow in Sudo allows any local user to obtain root privileges without authentication. ๐ฆ Sudo1.8.2 - 1.8.31p2, 1.9.0 - 1.9.5p1(fix: 1.9.5p2) CWE-122: Heap-based Buffer Overflow๐ก 2 feed signals๐ป Direct Build Impact | 2021-01-26โฑ๏ธ5y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2024-1597 CVE-2024-1597 | PostgreSQL pg_dump and pg_dumpall SQL Injection and Command Execution Improper quoting in pg_dump when dumping databases containing object names with newlines permits code execution. ๐ฆ PostgreSQL pg_dump<16.2, <15.6, <14.11(fix: 16.2) CWE-89: SQL Injection๐ก 1 feed signal๐ป Direct Build Impact | 2024-02-08โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2022-37868 CVE-2022-37868CVE-2022-3602 | OpenSSL X.509 Certificate Name Constraint Punycode Buffer Overflow Buffer overflow in OpenSSL during certificate verification when parsing email addresses containing Punycode characters. ๐ฆ OpenSSL3.0.0 - 3.0.6(fix: 3.0.7) CWE-120: Buffer Copy without Checking Size of Input๐ก 1 feed signal๐ป Direct Build Impact | 2022-11-01โฑ๏ธ3y ago | ๐ป TOOLCHAIN THREAT |
UVI-2014-0160 CVE-2014-0160 | OpenSSL TLS Heartbeat Extension Memory Information Disclosure (Heartbleed) Catastrophic missing bounds check in OpenSSL Heartbeat extension enables unauthenticated remote memory dumping. ๐ฆ OpenSSL1.0.1 - 1.0.1f(fix: 1.0.1g) CWE-125: Out-of-bounds Read๐ก 2 feed signals | 2014-04-07โฑ๏ธ12y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2017-0144 CVE-2017-0144 | Microsoft Windows SMBv1 Server Remote Code Execution (EternalBlue / WannaCry) Zero-click remote code execution in Windows SMBv1 server protocol exploited by WannaCry and NotPetya worms. ๐ฆ Microsoft Windows SMBv1Windows 7, 8.1, 10, Server 2008-2016(fix: MS17-010 Update) CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer๐ก 2 feed signals๐ป Direct Build Impact | 2017-03-14โฑ๏ธ9y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2020-10148 CVE-2020-10148 | SolarWinds Orion Platform SUNBURST Supply Chain DLL Backdoor Trojanized SolarWinds.Orion.Core.BusinessLayer.dll injected into official build releases by nation-state actors. ๐ฆ SolarWinds Orion Platform2019.4 HF 5 - 2020.2.1(fix: 2020.2.1 HF 2) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2020-12-14โฑ๏ธ5y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2018-20834 CVE-2018-20834 | npm Event-Stream Flatmap-Stream Social Engineering Supply Chain Attack Legitimate maintainer social engineered into transferring npm package ownership to attacker who injected Bitcoin wallet stealer. ๐ฆ event-stream / flatmap-stream3.3.6(fix: 3.3.4 (reverted)) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2018-11-26โฑ๏ธ7y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-28182 CVE-2024-28182 | HTTP/2 CONTINUATION Frame Flood Denial of Service across Web Servers & Proxies Unbounded HTTP/2 CONTINUATION frame processing permits remote resource exhaustion and server crash. ๐ฆ nghttp2 / Envoy / Node.js<1.61.0(fix: 1.61.0) CWE-400: Uncontrolled Resource Consumption๐ก 2 feed signals | 2024-04-03โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-45338 CVE-2024-45338 | Go net/http Content-Length Chunked Encoding HTTP Request Smuggling Inconsistent handling of chunked transfer encoding in Go HTTP server permits HTTP request smuggling. ๐ฆ Go net/http<1.21.11, <1.22.4(fix: 1.22.4) CWE-444: Inconsistent Interpretation of HTTP Requests๐ก 1 feed signal๐ป Direct Build Impact | 2024-06-04โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2024-34064 CVE-2024-34064 | Jinja2 Template Engine XML/HTML Attribute Injection via Macro Arguments Flaw in Jinja2 XML and HTML attribute escaping allows attribute injection and Cross-Site Scripting (XSS). ๐ฆ Jinja2<3.1.4(fix: 3.1.4) CWE-79: Cross-site Scripting (XSS)๐ก 1 feed signal๐ป Direct Build Impact | 2024-05-06โฑ๏ธ2y ago | ๐ป TOOLCHAIN THREAT |
UVI-2024-52303 CVE-2024-52303 | OpenSSL ChaCha20-Poly1305 Cipher State Corruption and Cryptographic Bypass Improper state handling in OpenSSL ChaCha20-Poly1305 can result in uninitialized memory leaks or integrity bypass. ๐ฆ OpenSSL3.0.0 - 3.0.14, 3.1.0 - 3.1.6(fix: 3.0.15) CWE-327: Use of a Broken or Risky Cryptographic Algorithm๐ก 1 feed signal | 2024-08-20โฑ๏ธ2y ago | ๐ฌ THEORETICAL ADVISORY |
UVI-2023-34362 CVE-2023-34362 | Progress Software MOVEit Transfer SQL Injection Zero-Day (CL0P Ransomware) Unauthenticated SQL injection in MOVEit Transfer web application exploited in massive global corporate extortion campaign. ๐ฆ MOVEit Transfer<2021.0.6, <2022.0.4, <2023.0.1(fix: 2023.0.1) CWE-89: SQL Injection๐ก 2 feed signals | 2023-06-02โฑ๏ธ3y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-MAL-2025-0101 ๐งฉ MALICIOUS EXT | VS Code Extension Marketplace Typosquat 'vscode-prettier-formatter' ClipBanker Trojan Malicious VS Code extension impersonating official Prettier formatter injects cryptocurrency address substitution malware. ๐ฆ vscode-prettier-formatter1.0.0 - 1.4.2(fix: Removed by Microsoft) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-16โฑ๏ธ1y 8m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0102 ๐ก๏ธ NON-CVE MALWARE | Malicious NPM Package 'aws-credential-sync' Stealing Local AWS & SSH Keys Trojanized npm utility claiming to synchronize AWS profiles silently exfiltrates ~/.aws/credentials and ~/.ssh/id_rsa to Discord webhooks. ๐ฆ aws-credential-sync0.1.0 - 0.2.3(fix: Removed by npm Security) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-22โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0103 ๐ก๏ธ NON-CVE MALWARE | Malicious PyPI Package 'kubernetes-helm-helper' Deploying Subnet Reverse Shell Typosquat on Python Package Index embeds obfuscated reverse shell connecting developer machines to command-and-control server. ๐ฆ kubernetes-helm-helper1.0.0 - 1.0.4(fix: Removed by PyPA) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-28โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0104 ๐ก๏ธ NON-CVE MALWARE | Typosquat NPM Package 'solana-web3-utils' Exfiltrating Private Keys from Local .env Files Malicious package targeting blockchain developers recursively searches directories for .env files containing private keys. ๐ฆ solana-web3-utils0.1.1 - 0.1.8(fix: Removed by npm Security) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-04โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0105 ๐งฉ MALICIOUS EXT | Malicious VS Code Extension 'rust-analyzer-turbo' Side-Loading Obfuscated C2 Beacon Fake high-performance Rust extension drops native dynamic library executing Cobalt Strike beacon in developer background. ๐ฆ rust-analyzer-turbo0.9.0 - 1.0.2(fix: Removed by Microsoft) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-10โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0106 ๐ก๏ธ NON-CVE MALWARE | Malicious NPM Package 'react-native-debugger-pro' Harvesting iOS/Android Simulator Tokens Trojanized mobile debugging library reads simulator Keychain files and browser cookies on developer MacBooks. ๐ฆ react-native-debugger-pro2.1.0 - 2.1.4(fix: Removed by npm Security) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-14โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0107 ๐ก๏ธ NON-CVE MALWARE | Trojanized Terraform Provider 'terraform-provider-cloudstack' Exfiltrating State Files Malicious Terraform provider published to public registry intercepts terraform apply to steal terraform.tfstate plaintext secrets. ๐ฆ terraform-provider-cloudstack0.5.0 - 0.5.3(fix: Removed by HashiCorp) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-18โฑ๏ธ1y 7m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0108 ๐ก๏ธ NON-CVE MALWARE | Malicious Go Module 'go-grpc-healthcheck' Stealing CI/CD Environment Variables via init() Backdoored Go module executes covert token theft during package initialization using Go runtime init() function. ๐ฆ go-grpc-healthcheck0.1.0 - 0.1.2(fix: Revoked in Go VulnDB) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-21โฑ๏ธ1y 6m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0109 ๐ก๏ธ NON-CVE MALWARE | Malicious NPM Package 'vite-plugin-pwa-analyzer' Bundling Silent Cryptominer into Builds Trojanized Vite plugin injects obfuscated WebAssembly cryptocurrency miner into generated production JavaScript bundles. ๐ฆ vite-plugin-pwa-analyzer1.0.0 - 1.2.1(fix: Removed by npm Security) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-25โฑ๏ธ1y 6m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0110 ๐ก๏ธ NON-CVE MALWARE | Malicious NPM Package 'electron-builder-macos-helper' Stealing Apple Signing Certificates Trojanized npm package targeting desktop app developers extracts Apple Developer ID code signing certificates and passwords. ๐ฆ electron-builder-macos-helper0.2.0 - 0.3.1(fix: Removed by npm Security) CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-27โฑ๏ธ1y 6m ago | ๐ป TOOLCHAIN THREAT |
UVI-MAL-2025-0111 ๐ก๏ธ NON-CVE MALWARE | QakBot & Cobalt Strike Multi-Feed C2 Infiltration & Stage 2 Beaconing Campaign Coordinated malware delivery campaign using weaponized ZIP attachments and DLL sideloading to establish resilient Cobalt Strike and QakBot C2 beacon channels. ๐ฆ Windows Developer WorkstationsAll unmonitored endpoints(fix: EDR Blocklist + C2 DNS Sinkhole) CWE-506: Embedded Malicious Code๐ก 6 feed signals๐ป Direct Build Impact | 2025-02-18โฑ๏ธ1y 7m ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-PHISH-2025-0812 ๐ก๏ธ NON-CVE MALWARE | Deceptive Developer Phishing & Malicious GitHub OAuth Token Harvester Campaign Targeted credential harvesting and rogue OAuth consent flow impersonating legitimate CI/CD code review bots to siphon private enterprise repositories. ๐ฆ Developer Identity & Code RepositoriesAll unmanaged OAuth apps(fix: OAuth App Revocation + SSO Re-Auth) CWE-451: User Interface Misrepresentation of Critical Information๐ก 4 feed signals๐ป Direct Build Impact | 2025-02-22โฑ๏ธ1y 6m ago | ๐ค ACTIVE BOTNET / C2 |
UVI-NET-2025-0441 ๐ก๏ธ NON-CVE MALWARE | Global Distributed SSH & Developer Runner Brute-Force Botnet Spray High-volume distributed brute-force network targeting public SSH bastions, developer devboxes, and cloud CI/CD runners. ๐ฆ OpenSSH & Developer Remote WorkstationsAll servers with password auth enabled(fix: SSH Keys Only + Fail2ban Blocklist) CWE-307: Improper Restriction of Excessive Authentication Attempts๐ก 6 feed signals | 2025-02-25โฑ๏ธ1y 6m ago | ๐ช๏ธ MASS SCANNER SPRAY |
UVI-EXP-2025-0919 CVE-2024-21887CVE-2024-21893 | Edge Gateway Authentication Bypass & Weaponized Zero-Day Exploit Wave Remote unauthenticated code execution in edge enterprise gateways exhibits 97th percentile EPSS exploitation probability. ๐ฆ Ivanti Connect Secure & Policy Secure Gateways9.x, 22.x prior to hotfix(fix: Vendor Security Hotfix Applied) CWE-78: Improper Neutralization of Special Elements used in an OS Command๐ก 5 feed signals | 2025-01-15โฑ๏ธ1y 8m ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2024-38526 CVE-2024-38526 | Polyfill.io CDN Domain Acquisition & Malicious Script Redirection Supply Chain Attack Compromised CDN domain polyfill.io served dynamic malicious redirects targeting mobile browsers across 100,000+ websites. ๐ฆ polyfill.io CDN ServiceAll assets served via polyfill.io after Feb 2024(fix: Migrated to Cloudflare / Fastly mirror) CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐ก 3 feed signals๐ป Direct Build Impact | 2024-06-25โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2020-1472 CVE-2020-1472 | Microsoft Netlogon Cryptographic Flaw Elevation of Privilege (Zerologon) Flaw in AES-CFB8 implementation allows unauthenticated domain elevation to Domain Admin in seconds. ๐ฆ Windows Server (Domain Controller)2008 R2, 2012, 2016, 2019(fix: August 2020 Security Update) CWE-327: Use of a Broken or Risky Cryptographic Algorithm๐ก 3 feed signals | 2020-08-11โฑ๏ธ6y ago | ๐ดโโ ๏ธ RANSOMWARE VECTOR |
UVI-2022-42889 CVE-2022-42889 | Apache Commons Text Remote Code Execution via StringSubstitutor Interpolator (Text4Shell) Improper variable interpolation in StringSubstitutor enables unauthenticated RCE via dns, url, and script prefixes. ๐ฆ Apache Commons Text1.5 - 1.9(fix: 1.10.0) CWE-94: Improper Control of Generation of Code๐ก 3 feed signals๐ป Direct Build Impact | 2022-10-13โฑ๏ธ3y ago | ๐ป TOOLCHAIN THREAT |
UVI-2024-21413 CVE-2024-21413 | Microsoft Outlook MonikerLink NTLM Credential Leaking & Remote Code Execution Critical vulnerability in Microsoft Outlook bypasses Protected View to leak NTLM hashes and execute remote code via file:// monikers. ๐ฆ Microsoft OutlookOffice 2016, 2019, LTSC 2021, Microsoft 365 Apps(fix: February 2024 Security Update) CWE-94: Improper Control of Generation of Code๐ก 3 feed signals | 2024-02-13โฑ๏ธ2y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-2022-30190 CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution (Follina) Zero-day vulnerability in MSDT invoked via Microsoft Word ms-msdt schema allows code execution even when macros are disabled. ๐ฆ Microsoft WindowsWindows 7, 8.1, 10, 11, Server 2008-2022(fix: June 2022 Cumulative Update) CWE-94: Improper Control of Generation of Code๐ก 3 feed signals | 2022-05-30โฑ๏ธ4y ago | ๐จ IN-THE-WILD EXPLOITED |
UVI-INFO-2025-0001 ๐ก INFO DISCLOSURE | Informational: Residential Proxy Botnets Fueling Automated Credential-Stuffing Against Dev & Git Portals Public chatter and investigative reports track massive distributed botnets rotating consumer IPs to bypass rate-limiting on developer portals. ๐ฆ Developer SSO & Git PortalsAll instances lacking FIDO2 enforcement CWE-307: Improper Restriction of Excessive Authentication Attempts๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-14โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0002 ๐ก INFO DISCLOSURE | Informational: Prompt Injection Vectors in Autonomous IDE AI Coding Assistants Security research highlights untrusted context poisoning in AI coding extensions, enabling silent workspace secret exfiltration. ๐ฆ IDE AI Extensions & AssistantsAll agentic extensions lacking strict egress sandboxing CWE-94: Improper Control of Generation of Code (Code Injection)๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-22โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0003 ๐ก INFO DISCLOSURE | Informational: Post-Quantum Transition Race Conditions & Degradation Vectors in Hybrid TLS 1.3 Cryptographic researcher chatter and preprints identify record fragmentation vulnerabilities in early ML-KEM deployments. ๐ฆ TLS 1.3 Hybrid ImplementationsImplementations negotiating X25519Kyber768 CWE-310: Cryptographic Issues๐ก 2 feed signals | 2024-11-12โฑ๏ธ1y 10m ago | ๐ก RESEARCH |
UVI-INFO-2025-0004 ๐ก INFO DISCLOSURE | Informational: Dangling CNAME Hijacking of Orphaned Cloud Storage in CI/CD Build Pipelines Underground chatter and telemetry indicate threat actors systematically claiming abandoned S3 and Blob domains cited in legacy setup scripts. ๐ฆ Build Artifact & Installer PipelinesScripts lacking SHA-256 hash checks CWE-829: Inclusion of Functionality from Untrusted Sphere๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-18โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0005 ๐ก INFO DISCLOSURE | Informational: eBPF Stealth Rootkit Techniques & Container Escape Vectors Discussed in Underground Channels Underground hacker telemetry and researcher PoCs demonstrate eBPF ring-buffer manipulation to conceal malicious processes. ๐ฆ Linux Kernel eBPF SubsystemKernels allowing unconstrained CAP_BPF / unprivileged BPF CWE-250: Execution with Unnecessary Privileges๐ก 2 feed signals | 2025-01-30โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0006 ๐ก INFO DISCLOSURE | Informational: Browser Extension Native Messaging Bridge Hijacking by Infostealer Malware Investigative reporting and infostealer malware analysis reveal systematic tampering with Native Messaging host registries on dev machines. ๐ฆ Browser Native Messaging BridgesAll installations with user-writable NativeMessagingHosts registries CWE-427: Uncontrolled Search Path Element๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-18โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0007 ๐ก INFO DISCLOSURE | Informational: Adversarial Model Context Protocol (MCP) Tool Poisoning & Shadow Server Registration Security research highlights untrusted schema injection in AI developer assistants connecting to local Model Context Protocol (MCP) endpoints. ๐ฆ Model Context Protocol (MCP) ClientsAll clients allowing unconfirmed auto-tool execution CWE-94: Improper Control of Generation of Code๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-24โฑ๏ธ1y 6m ago | ๐ก RESEARCH |
UVI-INFO-2025-0008 ๐ก INFO DISCLOSURE | Informational: ML Supply Chain Typosquatting Bypassing SafeTensors Deserialization Guarantees Public research alerts flag malicious Hugging Face model weights bundling companion preprocessing scripts that execute arbitrary Python code. ๐ฆ Hugging Face Model RepositoriesAll models downloaded with trust_remote_code=True CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-12โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0009 ๐ก INFO DISCLOSURE | Informational: BGP Route Hijacking Campaigns Intercepting Regional Open-Source Package Mirrors Network telemetry and underground chatter indicate localized BGP prefix hijacks intercepting package registry traffic to serve poisoned dependency tarballs. ๐ฆ Open-Source Package MirrorsClients running without lockfile hash enforcement CWE-300: Channel Accessible by Non-Endpoint๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-29โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0010 ๐ก INFO DISCLOSURE | Informational: VS Code Extension Shadow-Forking & Dormant Publisher Account Takeovers Threat actors actively purchase expired domains linked to abandoned VS Code Marketplace extensions to push malicious automatic updates. ๐ฆ VS Code ExtensionsAll extensions from abandoned publisher domains CWE-494: Download of Code Without Integrity Check๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-17โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0011 ๐ก INFO DISCLOSURE | Informational: Real-Time AI Voice Cloning Vishing Targeting Enterprise DevOps & IT Helpdesks Security chatter and intelligence bulletins warn of sophisticated vishing attacks using generative AI voice models to reset engineer MFA credentials. ๐ฆ Enterprise IT Helpdesk ProceduresAll organizations relying on voice-only authentication CWE-287: Improper Authentication๐ก 2 feed signals๐ป Direct Build Impact | 2025-02-08โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0012 ๐ก INFO DISCLOSURE | Informational: GitHub Actions Runner Cache Poisoning via Cross-Branch Cache Key Collisions Research teardowns reveal techniques where external pull requests exploit actions/cache scoping to poison dependency caches for main branch builds. ๐ฆ GitHub Actions WorkflowsAll workflows using loose restore-keys with PR triggers CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-18โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0013 ๐ก INFO DISCLOSURE | Informational: WebAssembly SIMD Register Allocation Flaws Inducing Host Process Memory Corruption Academic cryptographers and browser security researchers publish preprints detailing register allocation flaws in Wasm JIT engines. ๐ฆ WebAssembly JIT Engines (V8 / Wasmtime)Runtimes prior to 2025 SIMD register bounds patches CWE-125: Out-of-bounds Read๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-14โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0014 ๐ก INFO DISCLOSURE | Informational: Unauthenticated Wireless ADB Probing on Developer Local Area Networks Network telemetry highlights automated malware scanning developer home and office subnets for open Android Debug Bridge ports. ๐ฆ Android Debug Bridge (ADB)All configurations listening on 0.0.0.0:5555 CWE-284: Improper Access Control๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-08โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0015 ๐ก INFO DISCLOSURE | Informational: Dangling DNS CNAME Takeovers Targeting Corporate Developer Portals & Documentation Investigative research catalogs thousands of abandoned developer documentation subdomains vulnerable to zero-click domain takeovers. ๐ฆ Corporate DNS InfrastructureAll domains with unlinked CNAME records CWE-350: Reliance on Reverse DNS Resolution for Security๐ก 2 feed signals๐ป Direct Build Impact | 2025-01-04โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0016 ๐ก INFO DISCLOSURE | Informational: Semantic Concurrency & Memory Bugs in LLM-Transpiled C-to-Rust Codebases Security essays and academic audits highlight silent race conditions and use-after-free bugs introduced by automated C-to-Rust rewrites. ๐ฆ Automated C-to-Rust RewritesCrates utilizing unsafe blocks without formal Miri verification CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer๐ก 2 feed signals๐ป Direct Build Impact | 2024-12-28โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0017 ๐ก INFO DISCLOSURE | Informational: Devcontainer Root Breakouts via Ubiquitous /var/run/docker.sock Mounts Cloud threat research highlights systemic container breakouts in remote IDE environments sharing host Docker sockets. ๐ฆ Devcontainers / Docker WorkspacesAll configurations mounting /var/run/docker.sock CWE-250: Execution with Unnecessary Privileges๐ก 2 feed signals๐ป Direct Build Impact | 2024-12-15โฑ๏ธ1y 9m ago | ๐ก RESEARCH |
UVI-INFO-2025-0018 ๐ก INFO DISCLOSURE | Informational: Git Submodule Path Traversal & Hook Execution Vectors in Recursive Clones Underground intel and exploit proof-of-concepts detail path traversal techniques in .gitmodules weaponized against developers running git clone --recursive. ๐ฆ Git Source Control ManagementUnpatched Git clients prior to submodule traversal remediations CWE-22: Improper Limitation of a Pathname to a Restricted Directory๐ก 2 feed signals๐ป Direct Build Impact | 2024-11-20โฑ๏ธ1y 10m ago | ๐ก RESEARCH |
UVI-INFO-2025-0019 ๐ก INFO DISCLOSURE | Informational: Persistent Background Daemonization via NPM postinstall Process Detachment Threat intelligence telemetry detects malicious npm packages spawning detached POSIX daemon processes that outlive package installation. ๐ฆ npm Package EcosystemAll packages executing untrusted postinstall scripts CWE-506: Embedded Malicious Code๐ก 2 feed signals๐ป Direct Build Impact | 2024-11-08โฑ๏ธ1y 10m ago | ๐ก RESEARCH |
UVI-INFO-2025-0020 ๐ก INFO DISCLOSURE | Informational: Cache-Timing Side-Channels in Early Post-Quantum (PQC) ML-KEM Reference Implementations Cryptographic preprints analyze microarchitectural timing leakages in newly standardized post-quantum key encapsulation algorithms. ๐ฆ PQC Reference Implementations (ML-KEM / Kyber)Reference implementations lacking constant-time division primitives CWE-385: Covert Timing Channel๐ก 2 feed signals | 2024-10-18โฑ๏ธ1y 11m ago | ๐ก RESEARCH |
UVI-INFO-2025-0021 ๐ก INFO DISCLOSURE | Informational: Shadow AI Code Assistant Telemetry Exfiltration via Rogue Language Server Protocol (LSP) Daemons Investigative research tracks unofficial AI coding plugins transmitting proprietary source code ASTs to third-party telemetry mirrors. ๐ฆ Unofficial AI IDE Extensions & Community LSP DaemonsUnvetted community releases CWE-359: Exposure of Private Personal Information to an Unauthorized Actor๐ก 1 feed signal๐ป Direct Build Impact | 2025-02-18โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0022 ๐ก INFO DISCLOSURE | Informational: Local Model Context Protocol (MCP) Indirect Prompt Injection Triggering Arbitrary Shell Execution Security preprints demonstrate prompt injection via untrusted repository READMEs and issues invoking local MCP command tools. ๐ฆ Autonomous AI Coding Agents with MCP Shell ToolsAll agents lacking mandatory human confirmation CWE-94: Improper Control of Generation of Code๐ก 1 feed signal๐ป Direct Build Impact | 2025-02-25โฑ๏ธ1y 6m ago | ๐ก RESEARCH |
UVI-INFO-2025-0023 ๐ก INFO DISCLOSURE | Informational: Drive-By Browser DevTools Protocol (CDP) WebSocket Hijacking Probing Localhost Debug Ports Security disclosures identify drive-by web scripts port-scanning localhost (9222/5858) to hijack developer browser sessions. ๐ฆ Chromium Remote Debugging & Node InspectorInstances running with --remote-debugging-port on 0.0.0.0 or 127.0.0.1 CWE-306: Missing Authentication for Critical Function๐ก 1 feed signal๐ป Direct Build Impact | 2025-01-20โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0024 ๐ก INFO DISCLOSURE | Informational: Container-to-Host Root Escalation via Shared Docker Socket in Self-Hosted CI/CD Runners Cloud threat research documents recurring privilege escalation in self-hosted GitHub Actions and GitLab CI runner clusters. ๐ฆ Self-Hosted CI/CD Runners Mounting /var/run/docker.sockAll runner pools using shared Docker daemon sockets CWE-250: Execution with Unnecessary Privileges๐ก 1 feed signal๐ป Direct Build Impact | 2025-01-28โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0025 ๐ก INFO DISCLOSURE | Informational: Zero-Click Pre-Launch Build Task Hooks in Crafted .vscode/tasks.json Bypassing Workspace Trust Security researcher writeup reveals how crafted repository task configurations execute arbitrary code when cloning and inspecting code. ๐ฆ VS Code & Derivative IDEsConfigurations permitting runOn: folderOpen in untrusted folders CWE-862: Missing Authorization๐ก 1 feed signal๐ป Direct Build Impact | 2025-02-04โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0026 ๐ก INFO DISCLOSURE | Informational: Steganographic Code Execution Payloads Disguised Inside Open-Source AI Model Weights (GGUF / Safetensors) AI safety researchers discover malicious steganographic payloads and polyglot files uploaded to public machine learning registries. ๐ฆ Open-Source AI Model Weights & Quantization ToolsUnverified model drops on public hubs CWE-502: Deserialization of Untrusted Data๐ก 1 feed signal๐ป Direct Build Impact | 2025-02-12โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
UVI-INFO-2025-0027 ๐ก INFO DISCLOSURE | Informational: Automated Developer Tunnels (Cloudflare / ngrok) Accidentally Exposing Cloud Metadata (IMDSv1) Telemetry reports mass scanning of ephemeral tunnel subdomains harvesting exposed cloud credentials from local dev servers. ๐ฆ Developer Tunneling Utilities & Webhook ProxiesUnauthenticated tunnel configurations CWE-918: Server-Side Request Forgery (SSRF)๐ก 1 feed signal๐ป Direct Build Impact | 2025-01-15โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0028 ๐ก INFO DISCLOSURE | Informational: Unauthenticated Named Pipe Relay in Windows Subsystem for Linux (WSL2) & Docker Desktop Security research discloses local privilege escalation vectors via unauthenticated inter-process named pipes on Windows developer laptops. ๐ฆ Docker Desktop for Windows & WSL2 Host ServicesVersions with permissive named pipe DACLs CWE-276: Incorrect Default Permissions๐ก 1 feed signal๐ป Direct Build Impact | 2025-01-08โฑ๏ธ1y 8m ago | ๐ก RESEARCH |
UVI-INFO-2025-0029 ๐ก INFO DISCLOSURE | Informational: Branch History Injection & Speculative Cache Side-Channels in Node.js & V8 JIT Compilers Academic preprint details microarchitectural cache-timing side channels in JavaScript JIT execution engines. ๐ฆ Node.js & V8 Runtime EnginesRuntimes sharing thread memory across untrusted scripts CWE-1258: Exposure of Sensitive Information through Sentinels in Speculative Execution๐ก 1 feed signal | 2024-12-14โฑ๏ธ1y 9m ago | ๐ก RESEARCH |
UVI-INFO-2025-0030 ๐ก INFO DISCLOSURE | Informational: Malicious Recursive Git Submodule Configurations Executing Arbitrary Pre-Commit Scripts Security research analyzes argument injection vectors in recursive git submodule cloning (`--recurse-submodules`). ๐ฆ Git Version Control System (Submodule Commands)Git versions lacking strict submodule path sanitization CWE-88: Improper Neutralization of Argument Delimiters in a Command๐ก 1 feed signal๐ป Direct Build Impact | 2024-11-30โฑ๏ธ1y 9m ago | ๐ก RESEARCH |
UVI-INFO-2025-0031 ๐ก INFO DISCLOSURE | Informational: Trojan Source 2.0: Invisible Unicode Directional Overrides Masking Vulnerabilities in Code Reviews Academic researchers publish new Unicode Bidirectional (BiDi) override techniques that evade modern syntax highlighters. ๐ฆ Code Review Systems & IDE Syntax HighlightersEnvironments lacking Unicode BiDi control character warnings CWE-116: Improper Encoding or Escaping of Output๐ก 1 feed signal๐ป Direct Build Impact | 2024-11-12โฑ๏ธ1y 10m ago | ๐ก RESEARCH |
UVI-INFO-2025-0032 ๐ก INFO DISCLOSURE | Informational: Mass Abandoned Domain Hijacking Targeting Stale Open-Source Package Maintainers Threat intelligence monitors automated re-registration of expired maintainer email domains to hijack package release tokens. ๐ฆ Dormant Packages in npm, PyPI, and RubyGemsPackages authored with expired custom domain email addresses CWE-287: Improper Authentication๐ก 1 feed signal๐ป Direct Build Impact | 2024-10-30โฑ๏ธ1y 10m ago | ๐ก RESEARCH |
UVI-INFO-2025-0033 ๐ก INFO DISCLOSURE | Informational: Monorepo Dependency Confusion Exploiting Unscoped Internal Package Fallbacks Security research whitepaper demonstrates corporate credential harvesting via unscoped internal package name squatting. ๐ฆ Corporate Monorepo Package ConfigurationsRepositories utilizing unscoped internal package identifiers CWE-427: Uncontrolled Search Path Element๐ก 1 feed signal๐ป Direct Build Impact | 2024-10-15โฑ๏ธ1y 11m ago | ๐ก RESEARCH |
UVI-INFO-2025-0034 ๐ก INFO DISCLOSURE | Informational: Unauthenticated Lateral Movement to Kubelet API via Active Developer Port-Forward Tunnels Cloud penetration testing writeups demonstrate container breakouts pivoting through active `kubectl port-forward` tunnels. ๐ฆ Kubernetes Developer CLI Tools (kubectl)Workstations with persistent port-forward sessions CWE-918: Server-Side Request Forgery (SSRF)๐ก 1 feed signal๐ป Direct Build Impact | 2024-09-28โฑ๏ธ1y 11m ago | ๐ก RESEARCH |
UVI-INFO-2025-0035 ๐ก INFO DISCLOSURE | Informational: Dormant Secret Persistence in Local Git Object Packs from Untracked Stashes & Reflog Buffers Forensic research warns that deleting secrets from code still leaves plain-text tokens in `.git/objects` packs. ๐ฆ Local Git Working DirectoriesAll repositories with default git garbage collection settings CWE-312: Cleartext Storage of Sensitive Information๐ก 1 feed signal๐ป Direct Build Impact | 2024-09-10โฑ๏ธ2y ago | ๐ก RESEARCH |
UVI-INFO-2025-0036 ๐ก INFO DISCLOSURE | Informational: Localhost Port Grabbing & OAuth PKCE Downgrade in Developer CLI Authentication Flows Security research evaluates loopback redirect security in CLI tools (AWS CLI, gcloud, Supabase, Vercel). ๐ฆ Developer CLI Authentication ToolsCLI tools using fixed loopback ports without mandatory PKCE CWE-601: URL Redirection to Untrusted Site ('Open Redirect')๐ก 1 feed signal๐ป Direct Build Impact | 2024-08-22โฑ๏ธ2y ago | ๐ก RESEARCH |
UVI-INFO-2025-0037 ๐ก INFO DISCLOSURE | Informational: GitHub Security Lab Advisory GHSL-2025-021: Arbitrary Workflow Command Injection in CI/CD Automation Toolkits GitHub Security Lab research identifies systemic expression injection vulnerabilities across open-source GitHub Actions workflows. ๐ฆ GitHub Actions WorkflowsWorkflows interpolating untrusted event context directly in run: blocks CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')๐ก 1 feed signal๐ป Direct Build Impact | 2025-02-18โฑ๏ธ1y 7m ago | ๐ก RESEARCH |
Showing 1 โ 50 of 11,090 advisories
Rows per page:
Page 1 of 222