#MaliciousCode
Microsoft engineer Andres Freund inadvertently uncovered malicious code in versions of the XZ Utils compression tool, potentially averting thousands of infections. #XZUtils #MaliciousCode #SecurityDiscovery #AndresFreund
March 31, 2024 at 8:57 PM
Hoeveel malicious code stond er op mijn oude PC.

#Onderzoek #DetectiveWerk #PC #OudePC #MaliciousCode
October 28, 2025 at 11:30 AM
Hoeveel malicious code stond er op mijn oude PC.

#Onderzoek #DetectiveWerk #PC #OudePC #MaliciousCode
October 28, 2025 at 11:30 AM
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files #AppleMacOS #Docker #MaliciousCode
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
  Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended workspace boundary and interact with resources on the host system. The more severe issue, tracked as CVE-2026-77179, affects Docker Sandboxes versions 0.28.0 through versions before 0.42.0 on macOS and is rated Critical. Docker fixed the vulnerability in Sandboxes 0.42.0, released September 7. The company disclosed the security issues publicly on September 15. Docker Sandboxes are designed to give AI coding agents their own microVM environment where they can execute code, install packages and use development tools without directly accessing the host. The security architecture treats the microVM as the primary trust boundary, with the agent receiving full control, including "sudo", inside that environment. Resources such as a developer's project directory are selectively exposed across the boundary. The problem in CVE-2026-77179 occurs in the virtio-fs host server, which handles filesystem sharing between the macOS host and the sandbox. Docker said the component could follow a symbolic link when reopening an unlinked file through a previously stored pathname. A malicious process inside the VM could exploit this behavior by changing a parent directory into a symbolic link after the original path had been accepted. When the host subsequently reused the stored path, the operation could be redirected to a different location outside the authorized workspace. This creates a path traversal condition across the VM boundary. Docker said an attacker could consequently read or modify arbitrary host files available to the account running the virtual machine monitor. Depending on what files can be changed, the access could potentially be turned into host-side code execution. The requirement for malicious code to already be executing inside the sandbox does not eliminate the security concern. Docker Sandboxes are intended to contain precisely the type of untrusted code that an autonomous coding agent might encounter through a compromised repository, malicious dependency, poisoned package or manipulated instruction. If that code can alter host-visible filesystem paths, the microVM's isolation boundary becomes vulnerable at the point where the host performs the subsequent filesystem operation. The second vulnerability, CVE-2026-79994, affects versions 0.37.0 through versions before 0.42.0. Docker rates it High with a CVSS 4.0 score of 8.7. This issue affects the guest-to-host relay used for Unix domain sockets. The relay initially verified that a requested socket was located inside an authorized workspace, but later established the connection by using the pathname again. A malicious guest could change an intermediate directory into a symlink during that interval, causing the host to connect to an AF_UNIX socket outside the permitted workspace. The vulnerability is classified as a time-of-check to time-of-use (TOCTOU) race condition, because the security decision is made against a pathname whose meaning can change before the privileged operation occurs. The resulting connection could expose data or host-side capabilities provided by the targeted socket. Together, the two flaws expose different host interfaces through a similar underlying weakness: trusting a pathname after an attacker-controlled environment has had an opportunity to alter what that pathname resolves to. The risk is amplified by how Sandboxes share development workspaces. Docker says "sbx run" normally mounts the current directory into the sandbox with read-write access, meaning an agent can directly modify the developer's working tree. Docker also warns that files such as Git hooks, CI configuration, IDE task definitions and project scripts can affect subsequent host-side development activity. For users unable to update immediately, Docker recommends clone mode and advises against additional read-write host mounts. Clone mode mounts the repository read-only at "/run/sandbox/source" while the agent works from a private clone inside the VM. However, it is not a confidentiality boundary: files available in the mounted repository, including untracked files such as ".env", may still be readable by the agent. Docker has reported no exploitation of either vulnerability. Neither issue was listed in CISA's Known Exploited Vulnerabilities catalog at the time of disclosure. The company credited Oren Yomtov of accomplish.ai with discovering CVE-2026-77179 and Jurre van Bergen of ThreatNotify with finding CVE-2026-79994. The fixes arrived amid wider security scrutiny of AI coding environments. Earlier research from Cyera Research Labs demonstrated how a prompt-injected coding agent operating inside a Docker-based environment could be used as part of an attack chain against the host through a separate Docker Engine vulnerability. The latest disclosures reinforce the importance of treating autonomous coding agents as potentially hostile workloads, even when they are placed inside purpose-built isolation mechanisms. Users running affected Sandboxes versions should upgrade to 0.42.0 or later. Docker Sandboxes 0.43.0, released September 15, is the latest stable release as of September 18.
dlvr.it
September 18, 2026 at 5:05 PM
It's not exactly something that is going to affect users but still wild to see such a blatant use of malicious code in the wild.

#javascript #cookies #maliciouscode
April 1, 2025 at 5:07 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
October 20, 2025 at 6:57 PM
🚨 #RedHat learned that the latest versions of the #xz tools and libraries contain #MaliciousCode that appears to be intended to allow unauthorized access. This code is present in versions 5.6.0 & 5.6.1 of the libraries.
This #vulnerability was assigned #CVE-2024-3094.
www.redhat.com/en/blog/urge...
Urgent security alert for Fedora 41 and Fedora Rawhide users
Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthor...
www.redhat.com
March 30, 2024 at 12:34 PM
October 19, 2025 at 9:10 PM
AI Model Claude Deploys Malicious Code in Unprecedented Attack

#ClaudeAI #MaliciousCode #VantaWire #TechNews

🔗 https://www.vantawire.com/ai-model-claude-deploys-malicious-code-in-unprecedented-atta/
August 19, 2026 at 2:30 PM
Claude published malicious code to the Internet and attacked 3 real companies arstechnica.com/security/202... #RegulateAI #RegulateTech #ClaudeAI #AnthropicAI #hacks #MaliciousCode
Claude published malicious code to the Internet and attacked 3 real companies
Had the hacks used conventional methods, someone would likely go to prison.
arstechnica.com
August 1, 2026 at 3:55 PM
Developer gets 4 years for activating network “kill switch” to avenge his firing https://arstechni.ca... #maliciouscode #cybercrime #killswitch #developer #Policy
August 22, 2025 at 8:02 PM
Enhancing Security in VSCode Extensions: Addressing the Threat of Malicious Code

#vscode
#maliciouscode
#ransomware
#cybersecurity
#softwaresecurity
Enhancing Security in VSCode Extensions: Addressing the Threat of Malicious Code | The DefendOps Diaries
Explore the security risks of VSCode extensions and the threat of malicious code integration.
thedefendopsdiaries.com
March 20, 2025 at 8:03 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
October 6, 2025 at 2:32 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
September 29, 2025 at 3:34 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
September 8, 2025 at 4:36 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
August 29, 2025 at 4:35 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
August 11, 2025 at 2:32 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
July 15, 2025 at 4:31 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
July 2, 2025 at 8:26 PM
Finding malicious code - Abhisek Datta, Co-Founder, @SafeDep teaches us how to use static code analysis, emulation & LLM inference to protect developers against #maliciouscode in #OSSpackages. #securechaincon #devsecops https://cstu.io/d57ea4
June 19, 2025 at 2:29 PM