Skip to content

ioc: 4 new compromise candidate(s)#37

Closed
brian93512 wants to merge 1 commit into
mainfrom
ioc-candidates/26640170045
Closed

ioc: 4 new compromise candidate(s)#37
brian93512 wants to merge 1 commit into
mainfrom
ioc-candidates/26640170045

Conversation

@brian93512
Copy link
Copy Markdown
Member

Automated IOC compromise candidates generated from OSV ecosystem feeds for the last 24 hours.

Review each entry carefully:

  • Does this read like a real supply-chain compromise or malicious publish, rather than an ordinary CVE?
  • Is the version pinning exact and narrow enough?
  • Is BLOCK the right action, or should this be downgraded to WARN?
  • Is the reason clear enough for someone triaging a finding?

Close this PR if any candidate looks like a normal vulnerability that should stay in AS-004 / OSV instead of the manual blacklist.

@brian93512
Copy link
Copy Markdown
Member Author

Closing this generated IOC candidate because these are generic CVE/RCE/arbitrary-write/command-injection vulnerabilities rather than confirmed supply-chain compromise or malicious package versions. They should remain AS-004/OSV coverage, not manual AS-008 blacklist entries.

@brian93512 brian93512 closed this May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant