REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
32 reports · page 1 of 1

snyk_blog · tlp:amber · 7/9/2026, 12:00:00 AM
Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) A harmless-looking symlink in a Git repo can redirect a tool into reading or writing anywhere on your machine. That old trick is now showing up in AI coding assistants, with nasty results. Symlinks Are Still Scary — And Yes, Git Supports Them | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing Evo New EN Select your language English Deutsch Español França…
Read original ↗https://snyk.io/blog/symlinks-are-still-scarysnyk_blog · tlp:amber · 6/29/2026, 12:00:00 AM
Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Snyk VulnBench JS 1.0: 300 repeated scans show LLM security findings vary by run, while SAST and models catch different vulnerability gaps. Snyk VulnBench JS 1.0: LLM Bug Repeatability | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing Evo New EN Select your language English Deutsch Español Français 日本語 Português Login Free and Team Plan Customers Snyk app.sn…
snyk_blog · tlp:amber · 6/25/2026, 12:00:00 AM
NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context. NVD in the AI Era: Multi-Source Vulnerability Intelligence | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing…
Read original ↗https://snyk.io/blog/nvd-multi-source-vulnerability-intelligencesnyk_blog · tlp:amber · 6/24/2026, 1:00:00 PM
A Note to Our Customers and Partners A note to our customers and partners about Snyk's AI transformation and organizational changes. A Note to Our Customers and Partners | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing Evo New EN Select your language English Deutsch Español Français 日本語 Português Login Free and Team Plan Customers Snyk app.snyk.io Enterprise Plan Customers 🇺🇸 Snyk US - 1 app.snyk.io 🇺🇸 Snyk US - 2…
Read original ↗https://snyk.io/blog/a-note-to-our-customers-and-partnerssnyk_blog · tlp:amber · 6/23/2026, 5:00:00 AM
When a vendor's breach becomes yours: lessons from the Klue incident A forgotten credential at vendor Klue let attackers reach customers' Salesforce data. How modern SaaS breaches cascade, and the keys you should audit. When a vendor's breach becomes yours: lessons from the Klue incident | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven …
Read original ↗https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incidentsnyk_blog · tlp:amber · 6/18/2026, 4:00:00 AM
The full Snyk AI Security Platform, free for open source maintainers Open source maintainers are drowning in real vulnerability reports and need help prioritizing, fixing, and shipping remediation faster. Snyk’s Secure Developer Program gives qualifying projects free access to the Snyk AI Security Platform. The full Snyk AI Security Platform, free for open source maintainers | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI…
Read original ↗https://snyk.io/blog/secure-developer-programsnyk_blog · tlp:amber · 6/16/2026, 11:00:00 PM
A Day in the Life of an AI Engineer in Snyk's Lisbon Office Explore a day in the life of an AI Engineer at Snyk's Lisbon office. See what it's like building AI-powered security tools, collaborating globally, and enjoying the vibrant culture of Portugal's capital city. A Day in the Life of an AI Engineer in Snyk's Lisbon Office | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a sing…
Read original ↗https://snyk.io/blog/a-day-in-the-life-of-an-ai-engineer-in-snyks-lisbon-officesnyk_blog · tlp:amber · 6/16/2026, 9:00:00 PM
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate. Mastra npm Scope Takeover | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security…
Read original ↗https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scopesnyk_blog · tlp:amber · 6/15/2026, 12:00:00 AM
The Government Just Banned an AI Model. An Engineer's Perspective. A government order abruptly took down a powerful AI model, exposing a new kind of supply chain risk for engineering teams. Security leaders need contingency plans before the next model disappears. The Government Just Banned an AI Model | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows A…
Read original ↗https://snyk.io/blog/government-ban-ai-model-engineer-perspectivesnyk_blog · tlp:amber · 6/14/2026, 1:00:00 PM
When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams On June 12, 2026, a US export-control directive led Anthropic to disable Claude Fable 5 and Mythos 5 worldwide over a reported jailbreak. The reported trigger was a code-analysis capability that defenders use routinely. Here is what happened, how the security community read it, and what security teams can take from it. When a Government Pulls an AI Model: What the Fable 5 …
Read original ↗https://snyk.io/blog/fable-mythos-suspension-security-takeawayssnyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers. Node-gyp Supply Chain Compromise | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in…
Read original ↗https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gypsnyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
So You Have an AI Security Budget. Now what? An AI security budget should fund more than visibility. The real priority is unified governance and enforcement across agentic development and production apps. So You Have an AI Security Budget. Now What? | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applications DeepCode AI…
Read original ↗https://snyk.io/blog/ai-security-budgetsnyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
Type Level Security: The future of secure AI code generation? Secure-by-design types can turn common bugs into compile-time errors. This post explores how type-level security could help prevent entire classes of AI-generated vulnerabilities. Type Level Security for Secure AI Code Generation | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven wo…
Read original ↗https://snyk.io/blog/type-level-securitysnyk_blog · tlp:amber · 6/3/2026, 12:00:00 AM
The New Security Risks of the Agentic Development Lifecycle AI agents are changing how software gets built, and with it, where security risk begins. Learn why securing the process matters as much as securing the code. The New Security Risks of Agentic Development | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applicatio…
Read original ↗https://snyk.io/blog/agentic-development-lifecyclesnyk_blog · tlp:amber · 6/2/2026, 12:00:00 AM
Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection jqwik 1.10.0 added a hidden prompt injection aimed at AI coding agents, using terminal escape codes to conceal destructive instructions from humans while leaving them readable to logs and tools. jqwik 1.10.0 Prompt Injection Explained | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a singl…
Read original ↗https://snyk.io/blog/protestware-open-source-maintainer-qwik-1-10-0-prompt-injectionsnyk_blog · tlp:amber · 6/1/2026, 12:00:00 AM
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages. Miasma Attack Hits Red Hat npm Packages | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a si…
Read original ↗https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packagessnyk_blog · tlp:amber · 5/29/2026, 4:00:00 AM
Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI Stop security backlogs. Snyk's Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal. Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platfo…
Read original ↗https://snyk.io/blog/snyk-remediation-agent-in-the-clisnyk_blog · tlp:amber · 5/29/2026, 4:00:00 AM
How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development See how Relay Network securely adopted AI coding with Snyk and GitHub Copilot, implementing "secure at inception" to reduce vulnerabilities and accelerate development. How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Mod…
Read original ↗https://snyk.io/blog/relay-network-ai-coding-securely-coagentic-developmentsnyk_blog · tlp:amber · 5/27/2026, 4:00:00 AM
Continuous Offensive Security: The Line We've Been Walking Snyk's Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here's why lineage matters. Snyk Continuous Offensive Security | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure…
Read original ↗https://snyk.io/blog/continuous-offensive-securitysnyk_blog · tlp:amber · 5/23/2026, 4:00:00 PM
Laravel Lang Supply Chain Advisory Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration. Laravel Lang Supply Chain Advisory | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applications DeepCode AI Purpose…
Read original ↗https://snyk.io/blog/laravel-lang-supply-chain-advisorysnyk_blog · tlp:amber · 5/21/2026, 5:00:00 PM
Snyk announces Anthropic updates: Evo integrates with Claude Enterprise, and Snyk Desk comes to Claude Desktop Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic's Claude Enterprise, and the Snyk Security Desktop Extension is now available in Claude for macOS and Windows. Snyk announces Evo Integration with Claude Enterprise and Snyk Desk comes to Claude Desktop | Snyk You need to en…
Read original ↗https://snyk.io/blog/claude-enterprise-integration-desktop-expansionsnyk_blog · tlp:amber · 5/21/2026, 5:00:00 AM
Securing The AI Revolution: How Snyk And Our Partners Are Scaling For The Future AI is accelerating code creation. Learn how Snyk is scaling its AI Security Platform and investing in new partner programs to help enterprises govern AI-generated code at scale. Securing the AI Revolution with Snyk Partners | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows…
Read original ↗https://snyk.io/blog/securing-ai-revolution-snyk-partnerssnyk_blog · tlp:amber · 5/20/2026, 12:00:00 AM
A Day in the Life of a Strategy Co-Op in Snyk’s Boston Office Go behind the scenes with Lulu, a Strategy Co-Op at Snyk, and discover a day balancing high-impact AI security projects with a vibrant Boston office culture. A Day in the Life of a Strategy Co-Op at Snyk | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applicat…
Read original ↗https://snyk.io/blog/strategy-co-op-snyk-boston-officesnyk_blog · tlp:amber · 5/19/2026, 11:00:00 PM
The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here's what we know. The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised | Snyk You need to enable JavaScript to run thi…
Read original ↗https://snyk.io/blog/durabletask-pypi-supply-chain-attacksnyk_blog · tlp:amber · 5/18/2026, 11:00:00 PM
Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain worm campaign. Here's what the malware does, how to detect exposure, and how to respond. Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Comp…
Read original ↗https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attacksnyk_blog · tlp:amber · 5/15/2026, 12:00:00 AM
Malicious node-ipc versions published to npm in suspected maintainer account compromise On May 14, 2026, multiple malicious versions of the popular npm package node-ipc were published to the npm registry. Current public reporting identifies node... Malicious node-ipc Versions Published to npm | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven …
Read original ↗https://snyk.io/blog/malicious-node-ipc-versions-published-npmsnyk_blog · tlp:amber · 5/11/2026, 5:00:00 AM
TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache poisoning, and OIDC token extraction from runner memory — producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here's what happened, what was sto…
Read original ↗https://snyk.io/blog/tanstack-npm-packages-compromisedsnyk_blog · tlp:amber · 4/30/2026, 12:00:00 AM
lightning PyPI Compromise: A Bun-Based Credential Stealer in Python A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here's what's in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier. Lightning PyPI Compromise: Bun-Based Stealer | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform…
Read original ↗https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealersnyk_blog · tlp:amber · 4/29/2026, 12:00:00 AM
Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira Bridge the gap to autonomous fixes. Snyk and Atlassian integrate to transform Jira security tickets into precision fixes using Snyk Studio AI, eliminating context switching and resolving vulnerabilities in minutes. Snyk and Atlassian Unveil Intelligent Remediation for Jira | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Securi…
Read original ↗https://snyk.io/blog/atlassian-integration-intelligent-remediation-jirasnyk_blog · tlp:amber · 4/29/2026, 12:00:00 AM
"A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages A new npm supply chain attack self-branded "Mini Shai-Hulud" compromised four SAP-ecosystem packages on April 29, 2026. Snyk has live advisories. Here's the technical breakdown, IOCs, and what to do. Bun-Based Stealer Hits SAP CAP npm Packages | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a sing…
Read original ↗https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packagessnyk_blog · tlp:amber · 4/29/2026, 12:00:00 AM
Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) CVE-2026-40478: The Thymeleaf template injection (CVSS 9.1) is conditional. Patch to 3.1.4+ immediately, and audit your code for dynamic view or template expression misuse, which is the key precondition for exploitability. The Thymeleaf Template Injection That Only Hurts If You Let It | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk A…
Read original ↗https://snyk.io/blog/thymeleaf-injectionsnyk_blog · tlp:amber · 4/27/2026, 11:00:00 PM
Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments. Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers | …
Read original ↗https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers