Exultia.tech

Universal Vulnerability Intelligence (UVI)

Real-time multi-source threat consensus across 111 synchronized global feeds, active zero-days, and supply chain malware.

Total Consolidated Threats
11,090
๐Ÿšจ 1,695+ Zero-Daysโ€ข๐Ÿ’ป 5,307 Workstationโ€ข๐Ÿ›ก๏ธ 9,203 Non-CVEโ€ข๐Ÿ“ก 107 Informational
Triage Methodology:
Layout:
Showing page 1 of 222 (11,090 matched advisories out of 11,090 total)
IdentifierThreat & Target Summary
Date / Ageโ†•
Exploitation Reality
UVI-2021-44228
CVE-2021-44228CVE-2021-45046
Apache Log4j2 JNDI Message Lookup Remote Code Execution (Log4Shell)
Unauthenticated remote code execution via recursive JNDI resolution in log messages across enterprise Java applications.
๐Ÿ“ฆ Apache Log4j2.0-beta9 - 2.14.1(fix: 2.17.1)
CWE-502: Deserialization of Untrusted Data๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2021-12-10โฑ๏ธ4y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2024-3094
CVE-2024-3094
XZ Utils / Liblzma Upstream Supply Chain Backdoor in sshd Authentication
Critical malicious backdoor inserted into xz-utils liblzma enabling unauthorized authentication bypass in OpenSSH daemon.
๐Ÿ“ฆ xz-utils / liblzma5.6.0 - 5.6.1(fix: 5.6.1-r1 / 5.4.6 LTS)๐Ÿ“ฆ OpenSSH Daemon (via libsystemd)Fedora 40, Rawhide, Debian Sid(fix: Reverted to 5.4.x)
CWE-506: Embedded Malicious Code๐Ÿ“ก 4 feed signals๐Ÿ’ป Direct Build Impact
2024-03-29โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-27982
CVE-2024-27982
Node.js Child Process Windows Batch File Command Injection (BatBadBut)
Improper argument escaping in child_process.spawn on Windows permits arbitrary shell command execution via batch files (.bat/.cmd).
๐Ÿ“ฆ Node.js (Windows)<18.20.2, <20.12.2, <21.7.2(fix: 20.12.2 LTS)
CWE-78: Improper Neutralization of Special Elements used in an OS Command๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2024-04-10โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-21626
CVE-2024-21626
runc Leaked Host File Descriptor Host Root Filesystem Overwrite Container Breakout
Vulnerability in runc allows malicious container images or exec sessions to overwrite host binaries and achieve full host breakout.
๐Ÿ“ฆ runc / Docker / Containerd<=1.1.11(fix: 1.1.12)
CWE-403: Exposure of File Descriptor to Unintended Control Sphere๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2024-01-31โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-24576
CVE-2024-24576
Rust std::process Command Argument Injection on Windows (BatBadBut)
Improper command-line argument escaping in Rust standard library on Windows enables arbitrary command execution.
๐Ÿ“ฆ Rust Standard Library (Windows)<1.77.2(fix: 1.77.2)
CWE-78: Improper Neutralization of Special Elements used in an OS Command๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-04-09โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-6387
CVE-2024-6387
OpenSSH Server RegreSSHion Pre-Authentication Remote Code Execution
Signal handler race condition in OpenSSH daemon permits unauthenticated remote code execution as root on glibc Linux systems.
๐Ÿ“ฆ OpenSSH sshd (Linux glibc)8.5p1 - 9.7p1(fix: 9.8p1)
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-07-01โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2024-38063
CVE-2024-38063
Windows TCP/IP Stack IPv6 Packet Processing Remote Code Execution
Zero-click remote code execution in Windows TCP/IP kernel stack triggered by specially crafted IPv6 packets.
๐Ÿ“ฆ Microsoft Windows TCP/IP Stack (tcpip.sys)Windows 10, 11, Server 2016-2022(fix: August 2024 Patch Tuesday)
CWE-191: Integer Underflow (Wrap or Confusion)๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-08-13โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2023-44487
CVE-2023-44487
HTTP/2 Rapid Reset Stream Multiplexing Distributed Denial of Service
Flaw in HTTP/2 protocol stream cancellation permits unprecedented distributed denial of service volumetric attacks.
๐Ÿ“ฆ HTTP/2 Protocol Implementations (Envoy, NGINX, Go, Apache)All HTTP/2 implementations prior to Oct 2023(fix: Vendor updates)
CWE-400: Uncontrolled Resource Consumption๐Ÿ“ก 2 feed signals
2023-10-10โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2023-38545
CVE-2023-38545
libcurl SOCKS5 Hostname Resolution Heap Buffer Overflow
Heap-based buffer overflow in libcurl during SOCKS5 proxy handshake permits arbitrary code execution or crash.
๐Ÿ“ฆ libcurl / curl command line7.69.0 - 8.3.0(fix: 8.4.0)
CWE-122: Heap-based Buffer Overflow๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2023-10-11โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-32002
CVE-2024-32002CVE-2024-32004
Git Client Recursive Clone Remote Code Execution via Malicious Submodules
Vulnerability in Git client allows arbitrary code execution during 'git clone --recursive' on case-insensitive filesystems (Windows/macOS).
๐Ÿ“ฆ Git Core Client<2.45.1, <2.44.1, <2.43.4(fix: 2.45.1)
CWE-178: Improper Handling of Case Sensitivity๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2024-05-14โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2023-4863
CVE-2023-4863CVE-2023-5129
libwebp Lossless Image Decoding Heap Buffer Overflow Zero-Day
Actively exploited heap buffer overflow in libwebp library enables remote code execution when rendering malicious WebP images.
๐Ÿ“ฆ libwebp / Electron / Chromium<1.3.2(fix: 1.3.2)
CWE-122: Heap-based Buffer Overflow๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2023-09-12โฑ๏ธ3y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2022-22963
CVE-2022-22965
Spring Cloud Function & Framework SpEL ClassLoader Remote Code Execution (Spring4Shell)
Unauthenticated remote code execution in Spring Framework via class binding on Java 9+ runtimes.
๐Ÿ“ฆ Spring Framework5.3.0 - 5.3.17, 5.2.0 - 5.2.19(fix: 5.3.18)
CWE-94: Improper Control of Generation of Code ('Code Injection')๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2022-03-31โฑ๏ธ4y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2023-5044
CVE-2023-5044
Kubernetes Ingress-Nginx Incomplete Annotation Validation Arbitrary Code Injection
Improper input sanitization in ingress-nginx annotations allows arbitrary code execution and cluster credential theft.
๐Ÿ“ฆ Kubernetes ingress-nginx<1.9.0(fix: 1.9.0)
CWE-94: Code Injection๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2023-10-25โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2024-4291
CVE-2024-4291
Large-Scale PyPI and npm Package Typosquatting Credential Exfiltration Campaign
Automated distribution of over 300 trojanized open-source packages executing postinstall scripts to steal SSH keys and AWS secrets.
๐Ÿ“ฆ Multiple PyPI & npm typosquats300+ packages(fix: Yanked / Quarantined)
CWE-506: Embedded Malicious Code๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2024-05-08โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2023-4911
CVE-2023-4911
glibc Dynamic Loader Buffer Overflow via GLIBC_TUNABLES (Looney Tunables)
Local privilege escalation to root in GNU C library dynamic loader triggered by crafted GLIBC_TUNABLES environment variable.
๐Ÿ“ฆ GNU C Library (glibc)2.34 - 2.38(fix: 2.38-r1)
CWE-122: Heap-based Buffer Overflow๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2023-10-03โฑ๏ธ2y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2023-36742
CVE-2023-36742
Visual Studio Code / Electron Workspace Trust Command Injection Bypass
Bypass of Workspace Trust security boundary permits arbitrary code execution upon opening untrusted git repositories.
๐Ÿ“ฆ Visual Studio Code<1.83.1(fix: 1.83.1)
CWE-94: Code Injection๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2023-09-12โฑ๏ธ3y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-23897
CVE-2024-23897
Jenkins Core CLI args4j Arbitrary File Read and Remote Code Execution
Unauthenticated arbitrary file read on Jenkins controllers via args4j @ file expansion feature leading to full server takeover.
๐Ÿ“ฆ Jenkins Core<=2.441, LTS <=2.426.2(fix: 2.442 / LTS 2.426.3)
CWE-22: Improper Limitation of a Pathname to a Restricted Directory๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-01-24โฑ๏ธ2y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2024-21624
CVE-2024-21624
Docker Desktop Windows and macOS Host File Overwrite Vulnerability
Symlink traversal vulnerability in Docker Desktop container mount synchronization allows host filesystem write.
๐Ÿ“ฆ Docker Desktop (Windows/macOS)<4.27.0(fix: 4.27.0)
CWE-59: Improper Link Resolution Before File Access๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-02-01โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2021-3156
CVE-2021-3156
Sudo Heap-Based Buffer Overflow Local Root Privilege Escalation (Baron Samedit)
Heap buffer overflow in Sudo allows any local user to obtain root privileges without authentication.
๐Ÿ“ฆ Sudo1.8.2 - 1.8.31p2, 1.9.0 - 1.9.5p1(fix: 1.9.5p2)
CWE-122: Heap-based Buffer Overflow๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2021-01-26โฑ๏ธ5y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2024-1597
CVE-2024-1597
PostgreSQL pg_dump and pg_dumpall SQL Injection and Command Execution
Improper quoting in pg_dump when dumping databases containing object names with newlines permits code execution.
๐Ÿ“ฆ PostgreSQL pg_dump<16.2, <15.6, <14.11(fix: 16.2)
CWE-89: SQL Injection๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-02-08โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2022-37868
CVE-2022-37868CVE-2022-3602
OpenSSL X.509 Certificate Name Constraint Punycode Buffer Overflow
Buffer overflow in OpenSSL during certificate verification when parsing email addresses containing Punycode characters.
๐Ÿ“ฆ OpenSSL3.0.0 - 3.0.6(fix: 3.0.7)
CWE-120: Buffer Copy without Checking Size of Input๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2022-11-01โฑ๏ธ3y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2014-0160
CVE-2014-0160
OpenSSL TLS Heartbeat Extension Memory Information Disclosure (Heartbleed)
Catastrophic missing bounds check in OpenSSL Heartbeat extension enables unauthenticated remote memory dumping.
๐Ÿ“ฆ OpenSSL1.0.1 - 1.0.1f(fix: 1.0.1g)
CWE-125: Out-of-bounds Read๐Ÿ“ก 2 feed signals
2014-04-07โฑ๏ธ12y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2017-0144
CVE-2017-0144
Microsoft Windows SMBv1 Server Remote Code Execution (EternalBlue / WannaCry)
Zero-click remote code execution in Windows SMBv1 server protocol exploited by WannaCry and NotPetya worms.
๐Ÿ“ฆ Microsoft Windows SMBv1Windows 7, 8.1, 10, Server 2008-2016(fix: MS17-010 Update)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2017-03-14โฑ๏ธ9y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2020-10148
CVE-2020-10148
SolarWinds Orion Platform SUNBURST Supply Chain DLL Backdoor
Trojanized SolarWinds.Orion.Core.BusinessLayer.dll injected into official build releases by nation-state actors.
๐Ÿ“ฆ SolarWinds Orion Platform2019.4 HF 5 - 2020.2.1(fix: 2020.2.1 HF 2)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2020-12-14โฑ๏ธ5y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2018-20834
CVE-2018-20834
npm Event-Stream Flatmap-Stream Social Engineering Supply Chain Attack
Legitimate maintainer social engineered into transferring npm package ownership to attacker who injected Bitcoin wallet stealer.
๐Ÿ“ฆ event-stream / flatmap-stream3.3.6(fix: 3.3.4 (reverted))
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2018-11-26โฑ๏ธ7y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-28182
CVE-2024-28182
HTTP/2 CONTINUATION Frame Flood Denial of Service across Web Servers & Proxies
Unbounded HTTP/2 CONTINUATION frame processing permits remote resource exhaustion and server crash.
๐Ÿ“ฆ nghttp2 / Envoy / Node.js<1.61.0(fix: 1.61.0)
CWE-400: Uncontrolled Resource Consumption๐Ÿ“ก 2 feed signals
2024-04-03โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-45338
CVE-2024-45338
Go net/http Content-Length Chunked Encoding HTTP Request Smuggling
Inconsistent handling of chunked transfer encoding in Go HTTP server permits HTTP request smuggling.
๐Ÿ“ฆ Go net/http<1.21.11, <1.22.4(fix: 1.22.4)
CWE-444: Inconsistent Interpretation of HTTP Requests๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-06-04โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2024-34064
CVE-2024-34064
Jinja2 Template Engine XML/HTML Attribute Injection via Macro Arguments
Flaw in Jinja2 XML and HTML attribute escaping allows attribute injection and Cross-Site Scripting (XSS).
๐Ÿ“ฆ Jinja2<3.1.4(fix: 3.1.4)
CWE-79: Cross-site Scripting (XSS)๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-05-06โฑ๏ธ2y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2024-52303
CVE-2024-52303
OpenSSL ChaCha20-Poly1305 Cipher State Corruption and Cryptographic Bypass
Improper state handling in OpenSSL ChaCha20-Poly1305 can result in uninitialized memory leaks or integrity bypass.
๐Ÿ“ฆ OpenSSL3.0.0 - 3.0.14, 3.1.0 - 3.1.6(fix: 3.0.15)
CWE-327: Use of a Broken or Risky Cryptographic Algorithm๐Ÿ“ก 1 feed signal
2024-08-20โฑ๏ธ2y ago
๐Ÿ”ฌ THEORETICAL ADVISORY
UVI-2023-34362
CVE-2023-34362
Progress Software MOVEit Transfer SQL Injection Zero-Day (CL0P Ransomware)
Unauthenticated SQL injection in MOVEit Transfer web application exploited in massive global corporate extortion campaign.
๐Ÿ“ฆ MOVEit Transfer<2021.0.6, <2022.0.4, <2023.0.1(fix: 2023.0.1)
CWE-89: SQL Injection๐Ÿ“ก 2 feed signals
2023-06-02โฑ๏ธ3y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-MAL-2025-0101
๐Ÿงฉ MALICIOUS EXT
VS Code Extension Marketplace Typosquat 'vscode-prettier-formatter' ClipBanker Trojan
Malicious VS Code extension impersonating official Prettier formatter injects cryptocurrency address substitution malware.
๐Ÿ“ฆ vscode-prettier-formatter1.0.0 - 1.4.2(fix: Removed by Microsoft)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-16โฑ๏ธ1y 8m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0102
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious NPM Package 'aws-credential-sync' Stealing Local AWS & SSH Keys
Trojanized npm utility claiming to synchronize AWS profiles silently exfiltrates ~/.aws/credentials and ~/.ssh/id_rsa to Discord webhooks.
๐Ÿ“ฆ aws-credential-sync0.1.0 - 0.2.3(fix: Removed by npm Security)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-22โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0103
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious PyPI Package 'kubernetes-helm-helper' Deploying Subnet Reverse Shell
Typosquat on Python Package Index embeds obfuscated reverse shell connecting developer machines to command-and-control server.
๐Ÿ“ฆ kubernetes-helm-helper1.0.0 - 1.0.4(fix: Removed by PyPA)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-28โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0104
๐Ÿ›ก๏ธ NON-CVE MALWARE
Typosquat NPM Package 'solana-web3-utils' Exfiltrating Private Keys from Local .env Files
Malicious package targeting blockchain developers recursively searches directories for .env files containing private keys.
๐Ÿ“ฆ solana-web3-utils0.1.1 - 0.1.8(fix: Removed by npm Security)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-04โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0105
๐Ÿงฉ MALICIOUS EXT
Malicious VS Code Extension 'rust-analyzer-turbo' Side-Loading Obfuscated C2 Beacon
Fake high-performance Rust extension drops native dynamic library executing Cobalt Strike beacon in developer background.
๐Ÿ“ฆ rust-analyzer-turbo0.9.0 - 1.0.2(fix: Removed by Microsoft)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-10โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0106
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious NPM Package 'react-native-debugger-pro' Harvesting iOS/Android Simulator Tokens
Trojanized mobile debugging library reads simulator Keychain files and browser cookies on developer MacBooks.
๐Ÿ“ฆ react-native-debugger-pro2.1.0 - 2.1.4(fix: Removed by npm Security)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-14โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0107
๐Ÿ›ก๏ธ NON-CVE MALWARE
Trojanized Terraform Provider 'terraform-provider-cloudstack' Exfiltrating State Files
Malicious Terraform provider published to public registry intercepts terraform apply to steal terraform.tfstate plaintext secrets.
๐Ÿ“ฆ terraform-provider-cloudstack0.5.0 - 0.5.3(fix: Removed by HashiCorp)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-18โฑ๏ธ1y 7m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0108
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious Go Module 'go-grpc-healthcheck' Stealing CI/CD Environment Variables via init()
Backdoored Go module executes covert token theft during package initialization using Go runtime init() function.
๐Ÿ“ฆ go-grpc-healthcheck0.1.0 - 0.1.2(fix: Revoked in Go VulnDB)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-21โฑ๏ธ1y 6m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0109
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious NPM Package 'vite-plugin-pwa-analyzer' Bundling Silent Cryptominer into Builds
Trojanized Vite plugin injects obfuscated WebAssembly cryptocurrency miner into generated production JavaScript bundles.
๐Ÿ“ฆ vite-plugin-pwa-analyzer1.0.0 - 1.2.1(fix: Removed by npm Security)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-25โฑ๏ธ1y 6m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0110
๐Ÿ›ก๏ธ NON-CVE MALWARE
Malicious NPM Package 'electron-builder-macos-helper' Stealing Apple Signing Certificates
Trojanized npm package targeting desktop app developers extracts Apple Developer ID code signing certificates and passwords.
๐Ÿ“ฆ electron-builder-macos-helper0.2.0 - 0.3.1(fix: Removed by npm Security)
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-27โฑ๏ธ1y 6m ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-MAL-2025-0111
๐Ÿ›ก๏ธ NON-CVE MALWARE
QakBot & Cobalt Strike Multi-Feed C2 Infiltration & Stage 2 Beaconing Campaign
Coordinated malware delivery campaign using weaponized ZIP attachments and DLL sideloading to establish resilient Cobalt Strike and QakBot C2 beacon channels.
๐Ÿ“ฆ Windows Developer WorkstationsAll unmonitored endpoints(fix: EDR Blocklist + C2 DNS Sinkhole)
CWE-506: Embedded Malicious Code๐Ÿ“ก 6 feed signals๐Ÿ’ป Direct Build Impact
2025-02-18โฑ๏ธ1y 7m ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-PHISH-2025-0812
๐Ÿ›ก๏ธ NON-CVE MALWARE
Deceptive Developer Phishing & Malicious GitHub OAuth Token Harvester Campaign
Targeted credential harvesting and rogue OAuth consent flow impersonating legitimate CI/CD code review bots to siphon private enterprise repositories.
๐Ÿ“ฆ Developer Identity & Code RepositoriesAll unmanaged OAuth apps(fix: OAuth App Revocation + SSO Re-Auth)
CWE-451: User Interface Misrepresentation of Critical Information๐Ÿ“ก 4 feed signals๐Ÿ’ป Direct Build Impact
2025-02-22โฑ๏ธ1y 6m ago
๐Ÿค– ACTIVE BOTNET / C2
UVI-NET-2025-0441
๐Ÿ›ก๏ธ NON-CVE MALWARE
Global Distributed SSH & Developer Runner Brute-Force Botnet Spray
High-volume distributed brute-force network targeting public SSH bastions, developer devboxes, and cloud CI/CD runners.
๐Ÿ“ฆ OpenSSH & Developer Remote WorkstationsAll servers with password auth enabled(fix: SSH Keys Only + Fail2ban Blocklist)
CWE-307: Improper Restriction of Excessive Authentication Attempts๐Ÿ“ก 6 feed signals
2025-02-25โฑ๏ธ1y 6m ago
๐ŸŒช๏ธ MASS SCANNER SPRAY
UVI-EXP-2025-0919
CVE-2024-21887CVE-2024-21893
Edge Gateway Authentication Bypass & Weaponized Zero-Day Exploit Wave
Remote unauthenticated code execution in edge enterprise gateways exhibits 97th percentile EPSS exploitation probability.
๐Ÿ“ฆ Ivanti Connect Secure & Policy Secure Gateways9.x, 22.x prior to hotfix(fix: Vendor Security Hotfix Applied)
CWE-78: Improper Neutralization of Special Elements used in an OS Command๐Ÿ“ก 5 feed signals
2025-01-15โฑ๏ธ1y 8m ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2024-38526
CVE-2024-38526
Polyfill.io CDN Domain Acquisition & Malicious Script Redirection Supply Chain Attack
Compromised CDN domain polyfill.io served dynamic malicious redirects targeting mobile browsers across 100,000+ websites.
๐Ÿ“ฆ polyfill.io CDN ServiceAll assets served via polyfill.io after Feb 2024(fix: Migrated to Cloudflare / Fastly mirror)
CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2024-06-25โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2020-1472
CVE-2020-1472
Microsoft Netlogon Cryptographic Flaw Elevation of Privilege (Zerologon)
Flaw in AES-CFB8 implementation allows unauthenticated domain elevation to Domain Admin in seconds.
๐Ÿ“ฆ Windows Server (Domain Controller)2008 R2, 2012, 2016, 2019(fix: August 2020 Security Update)
CWE-327: Use of a Broken or Risky Cryptographic Algorithm๐Ÿ“ก 3 feed signals
2020-08-11โฑ๏ธ6y ago
๐Ÿดโ€โ˜ ๏ธ RANSOMWARE VECTOR
UVI-2022-42889
CVE-2022-42889
Apache Commons Text Remote Code Execution via StringSubstitutor Interpolator (Text4Shell)
Improper variable interpolation in StringSubstitutor enables unauthenticated RCE via dns, url, and script prefixes.
๐Ÿ“ฆ Apache Commons Text1.5 - 1.9(fix: 1.10.0)
CWE-94: Improper Control of Generation of Code๐Ÿ“ก 3 feed signals๐Ÿ’ป Direct Build Impact
2022-10-13โฑ๏ธ3y ago
๐Ÿ’ป TOOLCHAIN THREAT
UVI-2024-21413
CVE-2024-21413
Microsoft Outlook MonikerLink NTLM Credential Leaking & Remote Code Execution
Critical vulnerability in Microsoft Outlook bypasses Protected View to leak NTLM hashes and execute remote code via file:// monikers.
๐Ÿ“ฆ Microsoft OutlookOffice 2016, 2019, LTSC 2021, Microsoft 365 Apps(fix: February 2024 Security Update)
CWE-94: Improper Control of Generation of Code๐Ÿ“ก 3 feed signals
2024-02-13โฑ๏ธ2y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-2022-30190
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution (Follina)
Zero-day vulnerability in MSDT invoked via Microsoft Word ms-msdt schema allows code execution even when macros are disabled.
๐Ÿ“ฆ Microsoft WindowsWindows 7, 8.1, 10, 11, Server 2008-2022(fix: June 2022 Cumulative Update)
CWE-94: Improper Control of Generation of Code๐Ÿ“ก 3 feed signals
2022-05-30โฑ๏ธ4y ago
๐Ÿšจ IN-THE-WILD EXPLOITED
UVI-INFO-2025-0001
๐Ÿ“ก INFO DISCLOSURE
Informational: Residential Proxy Botnets Fueling Automated Credential-Stuffing Against Dev & Git Portals
Public chatter and investigative reports track massive distributed botnets rotating consumer IPs to bypass rate-limiting on developer portals.
๐Ÿ“ฆ Developer SSO & Git PortalsAll instances lacking FIDO2 enforcement
CWE-307: Improper Restriction of Excessive Authentication Attempts๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-14โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0002
๐Ÿ“ก INFO DISCLOSURE
Informational: Prompt Injection Vectors in Autonomous IDE AI Coding Assistants
Security research highlights untrusted context poisoning in AI coding extensions, enabling silent workspace secret exfiltration.
๐Ÿ“ฆ IDE AI Extensions & AssistantsAll agentic extensions lacking strict egress sandboxing
CWE-94: Improper Control of Generation of Code (Code Injection)๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-22โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0003
๐Ÿ“ก INFO DISCLOSURE
Informational: Post-Quantum Transition Race Conditions & Degradation Vectors in Hybrid TLS 1.3
Cryptographic researcher chatter and preprints identify record fragmentation vulnerabilities in early ML-KEM deployments.
๐Ÿ“ฆ TLS 1.3 Hybrid ImplementationsImplementations negotiating X25519Kyber768
CWE-310: Cryptographic Issues๐Ÿ“ก 2 feed signals
2024-11-12โฑ๏ธ1y 10m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0004
๐Ÿ“ก INFO DISCLOSURE
Informational: Dangling CNAME Hijacking of Orphaned Cloud Storage in CI/CD Build Pipelines
Underground chatter and telemetry indicate threat actors systematically claiming abandoned S3 and Blob domains cited in legacy setup scripts.
๐Ÿ“ฆ Build Artifact & Installer PipelinesScripts lacking SHA-256 hash checks
CWE-829: Inclusion of Functionality from Untrusted Sphere๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-18โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0005
๐Ÿ“ก INFO DISCLOSURE
Informational: eBPF Stealth Rootkit Techniques & Container Escape Vectors Discussed in Underground Channels
Underground hacker telemetry and researcher PoCs demonstrate eBPF ring-buffer manipulation to conceal malicious processes.
๐Ÿ“ฆ Linux Kernel eBPF SubsystemKernels allowing unconstrained CAP_BPF / unprivileged BPF
CWE-250: Execution with Unnecessary Privileges๐Ÿ“ก 2 feed signals
2025-01-30โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0006
๐Ÿ“ก INFO DISCLOSURE
Informational: Browser Extension Native Messaging Bridge Hijacking by Infostealer Malware
Investigative reporting and infostealer malware analysis reveal systematic tampering with Native Messaging host registries on dev machines.
๐Ÿ“ฆ Browser Native Messaging BridgesAll installations with user-writable NativeMessagingHosts registries
CWE-427: Uncontrolled Search Path Element๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-18โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0007
๐Ÿ“ก INFO DISCLOSURE
Informational: Adversarial Model Context Protocol (MCP) Tool Poisoning & Shadow Server Registration
Security research highlights untrusted schema injection in AI developer assistants connecting to local Model Context Protocol (MCP) endpoints.
๐Ÿ“ฆ Model Context Protocol (MCP) ClientsAll clients allowing unconfirmed auto-tool execution
CWE-94: Improper Control of Generation of Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-24โฑ๏ธ1y 6m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0008
๐Ÿ“ก INFO DISCLOSURE
Informational: ML Supply Chain Typosquatting Bypassing SafeTensors Deserialization Guarantees
Public research alerts flag malicious Hugging Face model weights bundling companion preprocessing scripts that execute arbitrary Python code.
๐Ÿ“ฆ Hugging Face Model RepositoriesAll models downloaded with trust_remote_code=True
CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-12โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0009
๐Ÿ“ก INFO DISCLOSURE
Informational: BGP Route Hijacking Campaigns Intercepting Regional Open-Source Package Mirrors
Network telemetry and underground chatter indicate localized BGP prefix hijacks intercepting package registry traffic to serve poisoned dependency tarballs.
๐Ÿ“ฆ Open-Source Package MirrorsClients running without lockfile hash enforcement
CWE-300: Channel Accessible by Non-Endpoint๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-29โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0010
๐Ÿ“ก INFO DISCLOSURE
Informational: VS Code Extension Shadow-Forking & Dormant Publisher Account Takeovers
Threat actors actively purchase expired domains linked to abandoned VS Code Marketplace extensions to push malicious automatic updates.
๐Ÿ“ฆ VS Code ExtensionsAll extensions from abandoned publisher domains
CWE-494: Download of Code Without Integrity Check๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-17โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0011
๐Ÿ“ก INFO DISCLOSURE
Informational: Real-Time AI Voice Cloning Vishing Targeting Enterprise DevOps & IT Helpdesks
Security chatter and intelligence bulletins warn of sophisticated vishing attacks using generative AI voice models to reset engineer MFA credentials.
๐Ÿ“ฆ Enterprise IT Helpdesk ProceduresAll organizations relying on voice-only authentication
CWE-287: Improper Authentication๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-02-08โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0012
๐Ÿ“ก INFO DISCLOSURE
Informational: GitHub Actions Runner Cache Poisoning via Cross-Branch Cache Key Collisions
Research teardowns reveal techniques where external pull requests exploit actions/cache scoping to poison dependency caches for main branch builds.
๐Ÿ“ฆ GitHub Actions WorkflowsAll workflows using loose restore-keys with PR triggers
CWE-829: Inclusion of Functionality from Untrusted Control Sphere๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-18โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0013
๐Ÿ“ก INFO DISCLOSURE
Informational: WebAssembly SIMD Register Allocation Flaws Inducing Host Process Memory Corruption
Academic cryptographers and browser security researchers publish preprints detailing register allocation flaws in Wasm JIT engines.
๐Ÿ“ฆ WebAssembly JIT Engines (V8 / Wasmtime)Runtimes prior to 2025 SIMD register bounds patches
CWE-125: Out-of-bounds Read๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-14โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0014
๐Ÿ“ก INFO DISCLOSURE
Informational: Unauthenticated Wireless ADB Probing on Developer Local Area Networks
Network telemetry highlights automated malware scanning developer home and office subnets for open Android Debug Bridge ports.
๐Ÿ“ฆ Android Debug Bridge (ADB)All configurations listening on 0.0.0.0:5555
CWE-284: Improper Access Control๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-08โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0015
๐Ÿ“ก INFO DISCLOSURE
Informational: Dangling DNS CNAME Takeovers Targeting Corporate Developer Portals & Documentation
Investigative research catalogs thousands of abandoned developer documentation subdomains vulnerable to zero-click domain takeovers.
๐Ÿ“ฆ Corporate DNS InfrastructureAll domains with unlinked CNAME records
CWE-350: Reliance on Reverse DNS Resolution for Security๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2025-01-04โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0016
๐Ÿ“ก INFO DISCLOSURE
Informational: Semantic Concurrency & Memory Bugs in LLM-Transpiled C-to-Rust Codebases
Security essays and academic audits highlight silent race conditions and use-after-free bugs introduced by automated C-to-Rust rewrites.
๐Ÿ“ฆ Automated C-to-Rust RewritesCrates utilizing unsafe blocks without formal Miri verification
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-12-28โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0017
๐Ÿ“ก INFO DISCLOSURE
Informational: Devcontainer Root Breakouts via Ubiquitous /var/run/docker.sock Mounts
Cloud threat research highlights systemic container breakouts in remote IDE environments sharing host Docker sockets.
๐Ÿ“ฆ Devcontainers / Docker WorkspacesAll configurations mounting /var/run/docker.sock
CWE-250: Execution with Unnecessary Privileges๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-12-15โฑ๏ธ1y 9m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0018
๐Ÿ“ก INFO DISCLOSURE
Informational: Git Submodule Path Traversal & Hook Execution Vectors in Recursive Clones
Underground intel and exploit proof-of-concepts detail path traversal techniques in .gitmodules weaponized against developers running git clone --recursive.
๐Ÿ“ฆ Git Source Control ManagementUnpatched Git clients prior to submodule traversal remediations
CWE-22: Improper Limitation of a Pathname to a Restricted Directory๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-11-20โฑ๏ธ1y 10m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0019
๐Ÿ“ก INFO DISCLOSURE
Informational: Persistent Background Daemonization via NPM postinstall Process Detachment
Threat intelligence telemetry detects malicious npm packages spawning detached POSIX daemon processes that outlive package installation.
๐Ÿ“ฆ npm Package EcosystemAll packages executing untrusted postinstall scripts
CWE-506: Embedded Malicious Code๐Ÿ“ก 2 feed signals๐Ÿ’ป Direct Build Impact
2024-11-08โฑ๏ธ1y 10m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0020
๐Ÿ“ก INFO DISCLOSURE
Informational: Cache-Timing Side-Channels in Early Post-Quantum (PQC) ML-KEM Reference Implementations
Cryptographic preprints analyze microarchitectural timing leakages in newly standardized post-quantum key encapsulation algorithms.
๐Ÿ“ฆ PQC Reference Implementations (ML-KEM / Kyber)Reference implementations lacking constant-time division primitives
CWE-385: Covert Timing Channel๐Ÿ“ก 2 feed signals
2024-10-18โฑ๏ธ1y 11m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0021
๐Ÿ“ก INFO DISCLOSURE
Informational: Shadow AI Code Assistant Telemetry Exfiltration via Rogue Language Server Protocol (LSP) Daemons
Investigative research tracks unofficial AI coding plugins transmitting proprietary source code ASTs to third-party telemetry mirrors.
๐Ÿ“ฆ Unofficial AI IDE Extensions & Community LSP DaemonsUnvetted community releases
CWE-359: Exposure of Private Personal Information to an Unauthorized Actor๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-02-18โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0022
๐Ÿ“ก INFO DISCLOSURE
Informational: Local Model Context Protocol (MCP) Indirect Prompt Injection Triggering Arbitrary Shell Execution
Security preprints demonstrate prompt injection via untrusted repository READMEs and issues invoking local MCP command tools.
๐Ÿ“ฆ Autonomous AI Coding Agents with MCP Shell ToolsAll agents lacking mandatory human confirmation
CWE-94: Improper Control of Generation of Code๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-02-25โฑ๏ธ1y 6m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0023
๐Ÿ“ก INFO DISCLOSURE
Informational: Drive-By Browser DevTools Protocol (CDP) WebSocket Hijacking Probing Localhost Debug Ports
Security disclosures identify drive-by web scripts port-scanning localhost (9222/5858) to hijack developer browser sessions.
๐Ÿ“ฆ Chromium Remote Debugging & Node InspectorInstances running with --remote-debugging-port on 0.0.0.0 or 127.0.0.1
CWE-306: Missing Authentication for Critical Function๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-01-20โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0024
๐Ÿ“ก INFO DISCLOSURE
Informational: Container-to-Host Root Escalation via Shared Docker Socket in Self-Hosted CI/CD Runners
Cloud threat research documents recurring privilege escalation in self-hosted GitHub Actions and GitLab CI runner clusters.
๐Ÿ“ฆ Self-Hosted CI/CD Runners Mounting /var/run/docker.sockAll runner pools using shared Docker daemon sockets
CWE-250: Execution with Unnecessary Privileges๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-01-28โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0025
๐Ÿ“ก INFO DISCLOSURE
Informational: Zero-Click Pre-Launch Build Task Hooks in Crafted .vscode/tasks.json Bypassing Workspace Trust
Security researcher writeup reveals how crafted repository task configurations execute arbitrary code when cloning and inspecting code.
๐Ÿ“ฆ VS Code & Derivative IDEsConfigurations permitting runOn: folderOpen in untrusted folders
CWE-862: Missing Authorization๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-02-04โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0026
๐Ÿ“ก INFO DISCLOSURE
Informational: Steganographic Code Execution Payloads Disguised Inside Open-Source AI Model Weights (GGUF / Safetensors)
AI safety researchers discover malicious steganographic payloads and polyglot files uploaded to public machine learning registries.
๐Ÿ“ฆ Open-Source AI Model Weights & Quantization ToolsUnverified model drops on public hubs
CWE-502: Deserialization of Untrusted Data๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-02-12โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0027
๐Ÿ“ก INFO DISCLOSURE
Informational: Automated Developer Tunnels (Cloudflare / ngrok) Accidentally Exposing Cloud Metadata (IMDSv1)
Telemetry reports mass scanning of ephemeral tunnel subdomains harvesting exposed cloud credentials from local dev servers.
๐Ÿ“ฆ Developer Tunneling Utilities & Webhook ProxiesUnauthenticated tunnel configurations
CWE-918: Server-Side Request Forgery (SSRF)๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-01-15โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0028
๐Ÿ“ก INFO DISCLOSURE
Informational: Unauthenticated Named Pipe Relay in Windows Subsystem for Linux (WSL2) & Docker Desktop
Security research discloses local privilege escalation vectors via unauthenticated inter-process named pipes on Windows developer laptops.
๐Ÿ“ฆ Docker Desktop for Windows & WSL2 Host ServicesVersions with permissive named pipe DACLs
CWE-276: Incorrect Default Permissions๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-01-08โฑ๏ธ1y 8m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0029
๐Ÿ“ก INFO DISCLOSURE
Informational: Branch History Injection & Speculative Cache Side-Channels in Node.js & V8 JIT Compilers
Academic preprint details microarchitectural cache-timing side channels in JavaScript JIT execution engines.
๐Ÿ“ฆ Node.js & V8 Runtime EnginesRuntimes sharing thread memory across untrusted scripts
CWE-1258: Exposure of Sensitive Information through Sentinels in Speculative Execution๐Ÿ“ก 1 feed signal
2024-12-14โฑ๏ธ1y 9m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0030
๐Ÿ“ก INFO DISCLOSURE
Informational: Malicious Recursive Git Submodule Configurations Executing Arbitrary Pre-Commit Scripts
Security research analyzes argument injection vectors in recursive git submodule cloning (`--recurse-submodules`).
๐Ÿ“ฆ Git Version Control System (Submodule Commands)Git versions lacking strict submodule path sanitization
CWE-88: Improper Neutralization of Argument Delimiters in a Command๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-11-30โฑ๏ธ1y 9m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0031
๐Ÿ“ก INFO DISCLOSURE
Informational: Trojan Source 2.0: Invisible Unicode Directional Overrides Masking Vulnerabilities in Code Reviews
Academic researchers publish new Unicode Bidirectional (BiDi) override techniques that evade modern syntax highlighters.
๐Ÿ“ฆ Code Review Systems & IDE Syntax HighlightersEnvironments lacking Unicode BiDi control character warnings
CWE-116: Improper Encoding or Escaping of Output๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-11-12โฑ๏ธ1y 10m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0032
๐Ÿ“ก INFO DISCLOSURE
Informational: Mass Abandoned Domain Hijacking Targeting Stale Open-Source Package Maintainers
Threat intelligence monitors automated re-registration of expired maintainer email domains to hijack package release tokens.
๐Ÿ“ฆ Dormant Packages in npm, PyPI, and RubyGemsPackages authored with expired custom domain email addresses
CWE-287: Improper Authentication๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-10-30โฑ๏ธ1y 10m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0033
๐Ÿ“ก INFO DISCLOSURE
Informational: Monorepo Dependency Confusion Exploiting Unscoped Internal Package Fallbacks
Security research whitepaper demonstrates corporate credential harvesting via unscoped internal package name squatting.
๐Ÿ“ฆ Corporate Monorepo Package ConfigurationsRepositories utilizing unscoped internal package identifiers
CWE-427: Uncontrolled Search Path Element๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-10-15โฑ๏ธ1y 11m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0034
๐Ÿ“ก INFO DISCLOSURE
Informational: Unauthenticated Lateral Movement to Kubelet API via Active Developer Port-Forward Tunnels
Cloud penetration testing writeups demonstrate container breakouts pivoting through active `kubectl port-forward` tunnels.
๐Ÿ“ฆ Kubernetes Developer CLI Tools (kubectl)Workstations with persistent port-forward sessions
CWE-918: Server-Side Request Forgery (SSRF)๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-09-28โฑ๏ธ1y 11m ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0035
๐Ÿ“ก INFO DISCLOSURE
Informational: Dormant Secret Persistence in Local Git Object Packs from Untracked Stashes & Reflog Buffers
Forensic research warns that deleting secrets from code still leaves plain-text tokens in `.git/objects` packs.
๐Ÿ“ฆ Local Git Working DirectoriesAll repositories with default git garbage collection settings
CWE-312: Cleartext Storage of Sensitive Information๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-09-10โฑ๏ธ2y ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0036
๐Ÿ“ก INFO DISCLOSURE
Informational: Localhost Port Grabbing & OAuth PKCE Downgrade in Developer CLI Authentication Flows
Security research evaluates loopback redirect security in CLI tools (AWS CLI, gcloud, Supabase, Vercel).
๐Ÿ“ฆ Developer CLI Authentication ToolsCLI tools using fixed loopback ports without mandatory PKCE
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2024-08-22โฑ๏ธ2y ago
๐Ÿ“ก RESEARCH
UVI-INFO-2025-0037
๐Ÿ“ก INFO DISCLOSURE
Informational: GitHub Security Lab Advisory GHSL-2025-021: Arbitrary Workflow Command Injection in CI/CD Automation Toolkits
GitHub Security Lab research identifies systemic expression injection vulnerabilities across open-source GitHub Actions workflows.
๐Ÿ“ฆ GitHub Actions WorkflowsWorkflows interpolating untrusted event context directly in run: blocks
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')๐Ÿ“ก 1 feed signal๐Ÿ’ป Direct Build Impact
2025-02-18โฑ๏ธ1y 7m ago
๐Ÿ“ก RESEARCH
Showing 1 โ€“ 50 of 11,090 advisories
Rows per page:
Page 1 of 222