Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
vulnerabilityinsights
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Feb 6
280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII
#
ai
#
applicationsecurity
#
vulnerabilityinsights
4
 reactions
Comments
Add Comment
7 min read
ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Jan 15
ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations
#
securitylabs
#
vulnerabilityinsights
#
cicd
#
secrets
Comments
Add Comment
6 min read
SHA1-Hulud, npm supply chain incident
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Nov 25 '25
SHA1-Hulud, npm supply chain incident
#
supplychainsecurity
#
vulnerabilityinsights
Comments
Add Comment
3 min read
Malicious MCP Server on npm postmark-mcp Harvests Emails
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Sep 26 '25
Malicious MCP Server on npm postmark-mcp Harvests Emails
#
ai
#
opensourcesecurity
#
vulnerabilityinsights
1
 reaction
Comments
Add Comment
10 min read
When "Private" Isn’t: The Security Risks of GPT Chats Leaking to Search Engines
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Aug 2 '25
When "Private" Isn’t: The Security Risks of GPT Chats Leaking to Search Engines
#
ai
#
engineering
#
vulnerabilityinsights
1
 reaction
Comments
Add Comment
3 min read
Reconstructing the TJ Actions Changed Files GitHub Actions Compromise
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Mar 18 '25
Reconstructing the TJ Actions Changed Files GitHub Actions Compromise
#
vulnerabilityinsights
1
 reaction
Comments
Add Comment
10 min read
CVE-2025-29927 Authorization Bypass in Next.js Middleware
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Mar 25 '25
CVE-2025-29927 Authorization Bypass in Next.js Middleware
#
vulnerabilityinsights
3
 reactions
Comments
Add Comment
3 min read
Suspicious Maintainer Unveils Threads of npm Supply Chain Attack
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Jul 17 '24
Suspicious Maintainer Unveils Threads of npm Supply Chain Attack
#
engineering
#
vulnerabilityinsights
#
javascript
#
node
2
 reactions
Comments
Add Comment
8 min read
Buildkit GRPC SecurityMode privilege check: Build-time container breakout (CVE-2024-23653)
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Feb 2 '24
Buildkit GRPC SecurityMode privilege check: Build-time container breakout (CVE-2024-23653)
#
containersecurity
#
vulnerabilityinsights
#
kubernetes
#
docker
5
 reactions
Comments
Add Comment
5 min read
Leaky Vessels deep dive: Escaping from Docker one syscall at a time
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Feb 7 '24
Leaky Vessels deep dive: Escaping from Docker one syscall at a time
#
vulnerabilityinsights
#
ccpp
#
docker
#
kubernetes
4
 reactions
Comments
Add Comment
45 min read
Vulnerability: runc process.cwd and leaked fds container breakout (CVE-2024-21626)
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Feb 2 '24
Vulnerability: runc process.cwd and leaked fds container breakout (CVE-2024-21626)
#
containersecurity
#
vulnerabilityinsights
#
kubernetes
#
docker
4
 reactions
Comments
Add Comment
5 min read
Buildkit mount cache race: Build-time race condition container breakout (CVE-2024-23651)
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Feb 1 '24
Buildkit mount cache race: Build-time race condition container breakout (CVE-2024-23651)
#
containersecurity
#
vulnerabilityinsights
#
kubernetes
#
docker
1
 reaction
Comments
Add Comment
5 min read
How to update cURL
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Oct 12 '23
How to update cURL
#
devsecops
#
engineering
#
opensourcesecurity
#
vulnerabilityinsights
8
 reactions
Comments
Add Comment
8 min read
How to find and fix Critical WebP zero-day vulnerability CVE-2023-4863
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Oct 6 '23
How to find and fix Critical WebP zero-day vulnerability CVE-2023-4863
#
vulnerabilityinsights
2
 reactions
Comments
Add Comment
6 min read
Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem
SnykSec
SnykSec
SnykSec
Follow
for
Snyk
Sep 29 '23
Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem
#
containersecurity
#
vulnerabilityinsights
#
opensourcesecurity
#
docker
1
 reaction
Comments
Add Comment
9 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account