Skip to content

ioc: 2 new compromise candidate(s)#36

Closed
brian93512 wants to merge 1 commit into
mainfrom
ioc-candidates/26579671572
Closed

ioc: 2 new compromise candidate(s)#36
brian93512 wants to merge 1 commit into
mainfrom
ioc-candidates/26579671572

Conversation

@brian93512
Copy link
Copy Markdown
Member

Automated IOC compromise candidates generated from OSV ecosystem feeds for the last 24 hours.

Review each entry carefully:

  • Does this read like a real supply-chain compromise or malicious publish, rather than an ordinary CVE?
  • Is the version pinning exact and narrow enough?
  • Is BLOCK the right action, or should this be downgraded to WARN?
  • Is the reason clear enough for someone triaging a finding?

Close this PR if any candidate looks like a normal vulnerability that should stay in AS-004 / OSV instead of the manual blacklist.

@brian93512
Copy link
Copy Markdown
Member Author

Closing this generated IOC candidate because compliance-trestle arbitrary file write is a normal vulnerability and should be covered through AS-004/OSV, not promoted into the manual AS-008 compromise blacklist.

@brian93512 brian93512 closed this May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant