Home / Companies / Snyk / Blog / February 2022

February 2022 Summaries

27 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
The Node.js ecosystem, specifically yarn and npm package managers, are vulnerable to attacks using niche configurations and hidden characters in code snippets. Attackers can create malicious packages with seemingly innocent names but execute a binary from the `.rc` file, which is not downloaded when running `npm install`. This attack vector exploits the way package managers search for configuration files hierarchically, allowing attackers to hide malicious code in plain sight. Developers may miss red flags, such as unusual file permissions or hidden files, and need to be cautious of third-party code, run it inside a sandboxed environment, and monitor their systems for suspicious behavior. The attack highlights the importance of increasing awareness among developers about these vulnerability vectors to prevent exploitation and improve overall security.
Feb 28, 2022 1,240 words in the original blog post.
Snyk expresses solidarity with Ukrainians affected by Russia’s invasion and with Russian civilians uninvolved in the aggression, framing the crisis as a shared humanitarian and security concern. In response, the company has doubled free Snyk Open Source testing limits for developers worldwide because of heightened cyberattack risks and pledged $100,000 to United Help Ukraine to support displaced people with donations, food, and medical supplies. Its cybersecurity experts also recommend that organizations strengthen multifactor authentication, update software, test ransomware-resistant backups, restrict and monitor network traffic, and train employees to recognize social engineering. The company additionally encourages individuals to support Ukrainian relief through United Help Ukraine, a Deed-organized charity campaign, or Come Back Alive.
Feb 25, 2022 452 words in the original blog post.
In recognition of Black History Month, three members of Snyk’s Black employee resource group share personal reflections on identity, racism, representation, family, and career development across Germany, Sweden, and the United States. Sharon Ikhuoria describes growing up as an Afro-German woman facing assumptions about her belonging and education, emphasizing the lasting effects of racism, the value of visible role models, and her pursuit of advanced education as a way to inspire others. Michael Poe reflects on navigating his own identity in the United States and on helping his biracial son understand ethnicity, difference, and the social realities he may encounter while growing up in Sweden. LaToya Muff recounts her family’s experiences with segregation and racial intimidation in rural Georgia, discusses continuing barriers to generational wealth, and encourages Black professionals entering technology to embrace their perspectives despite limited diversity. Together, their stories present Black History Month as both a celebration of achievement and an opportunity to acknowledge historical and ongoing inequities while supporting confidence, education, and inclusion.
Feb 24, 2022 2,199 words in the original blog post.
A critical vulnerability was discovered in Magento Ecommerce, Magento Open Source, and Adobe Commerce versions, allowing an unauthenticated user to utilize SQL injection or PHP object injection at the checkout process. A patch was initially released, but further testing revealed it wasn't sufficient to mitigate the issue, leading to a new patch being rolled out to address the vulnerability. The new patch adds a reusable framework function to sanitize user input and provides additional security measures to prevent exploitation of the vulnerability. It is essential to apply both patches and run secure backups before deployment to ensure the security of the platform. Security researchers recommend monitoring public repositories, such as those on GitHub, for potential issues using tools like Snyk, which can alert developers to vulnerabilities and suggest possible fixes.
Feb 24, 2022 711 words in the original blog post.
A Snyk marketing team member describes using The Big Fix, a community security event, to make an open-source contribution despite limited technical experience. After creating a free Snyk account, connecting it to GitHub, and scanning a fork of the Terratest infrastructure-testing library, the author identified a straightforward vulnerability involving an outdated Docker image and used Snyk’s automated fix feature to generate a pull request. Recognizing that fixing only the fork had limited impact, the author copied the change into a pull request for the original Terratest repository. The account presents The Big Fix as an accessible process for scanning projects, addressing vulnerabilities through pull requests, engaging with the DevSecCon community, and earning rewards, while noting that the month-long event culminated in a 24-hour Big Fix-a-Thon and had already produced hundreds of thousands of identified vulnerabilities and tens of thousands of fixes.
Feb 23, 2022 1,359 words in the original blog post.
Snyk has launched a new Global Service Provider program designed to support leading solution providers in bringing its developer-first tools and methodologies into their services, with the goal of helping customers on their DevSecOps journey. The program aims to address security in the fast-paced DevOps world, where every company is becoming a software company, and customers are looking to embrace developer security as an important step of development. Snyk partners play a crucial role in making this shift a reality by providing flexibility and choice for customers, allowing them to add the optimum services for their business vision and customers. The program enables service delivery partners to offer a wide range of services to help customers across the DevSecOps journey, including security assessment, implementation, and integration services. With Snyk's platform, service delivery partners can secure code, elevate quality, and protect customers from risk, addressing emerging vulnerabilities such as Log4Shell and ensuring compliance with regulations like the Federal Trade Commission's Executive Order on global cybersecurity.
Feb 23, 2022 696 words in the original blog post.
Snyk’s 2022 Big Fix campaign encouraged developers and security practitioners worldwide to address vulnerabilities in applications and open-source projects, resulting in more than 300,000 identified vulnerabilities across over 28,000 projects and over 60,000 repository fixes spanning languages, container images, and infrastructure-as-code projects. Its finale was a 24-hour livestream beginning February 25, featuring regional programming across Asia-Pacific, Europe, and North America through Twitch and YouTube. Sessions included discussions and demonstrations on software supply-chain and open-source security, security champion programs, secure development lifecycles, monitoring, PCI development, and practical techniques for securing or testing Node.js, Java, Docker, Kubernetes, and other technologies. Speakers included security professionals, developers, educators, and representatives from organizations such as IBM, HackerOne, Docker, Sysdig, Stripe, Rapid7, Atlassian, and Codefresh. Participants could register for the month-long event, connect Snyk to their projects, fix vulnerabilities for a free T-shirt, join the community on Discord, and share progress using the #thebigfix tag.
Feb 21, 2022 973 words in the original blog post.
The developer-centric approach to software development has become a fundamental shift in the industry, with developers now holding a bigger audience and voice. This shift is driven by the growing importance of tooling and company culture in affecting productivity and approach. Developers need tools that simplify their job, integrate seamlessly with other tools and workflows, and empower them to take ownership of their work. A servant leadership approach prioritizes getting work done over legwork and gives developers more choice in tools and team structures. This shift also applies to the partnership between security and development, where decentralization and empowerment are key to protecting new pipelines and establishing secure coding practices. Ultimately, building empowered and autonomous development teams requires listening to what the team is trying to achieve and helping them solve problems themselves.
Feb 18, 2022 1,108 words in the original blog post.
Magento is a widely used e-commerce platform, available as the community-supported Magento Open Source and the Adobe-managed Adobe Commerce, and powers an estimated 158,000 sites including major global brands. The text highlights CVE-2022-24086, a critical improper input-validation vulnerability disclosed in February 2022 that affected certain Magento and Adobe Commerce versions and could permit SQL injection, PHP object injection, database manipulation, or remote code execution during checkout-related processing. Adobe’s patch updates sanitization logic in Magento’s Filter.php and VarDirective.php files with additional regular-expression handling, and users are advised to test patches outside production and maintain secure backups. It also recommends using Composer-based dependency management and security scanning tools such as Snyk, including repository and CI/CD integrations, to identify vulnerabilities in Magento core packages, extensions, infrastructure, and deployment workflows.
Feb 17, 2022 682 words in the original blog post.
Snyk announced its acquisition of Fugue to expand its developer-focused cloud security capabilities by connecting application code, infrastructure as code, and the live cloud environment. The companies aim to create a feedback loop that helps developers identify, prioritize, and remediate vulnerabilities, cloud misconfigurations, and infrastructure drift without disconnecting fixes from source-controlled configuration. Fugue’s cloud security posture management technology and policy-as-code approach, including support for Open Policy Agent and Rego, will be integrated with Snyk’s existing IaC security tools to provide unified policies across development and deployment. Snyk plans to continue supporting current Fugue customers while incorporating Fugue functionality, policies, and cloud context into its platform, with the stated goal of improving issue prioritization, drift detection, exploitability analysis, and collaboration between developers, security teams, and operations teams.
Feb 17, 2022 1,099 words in the original blog post.
Snyk’s The Big Fix initiative encourages developers to identify and remediate open-source vulnerabilities, offering participants limited-edition shirts and prize opportunities while improving software security. After creating free Snyk and Big Fix accounts, developers can connect public or private repositories to Snyk Open Source, which scans package manifests for vulnerable dependencies, suggests remediation options, and can generate pull requests for proposed fixes. Contributors can also locate projects through the Snyk Vulnerability Database and submit fixes to open-source communities, as illustrated by an Invoice Ninja contribution that traced an outdated DOMPDF dependency to a 2014 cross-site scripting issue in PHP-Font-Lib. The process emphasizes safely upgrading dependencies, testing changes locally, and submitting reviewed pull requests to avoid breaking projects relied upon by users.
Feb 16, 2022 805 words in the original blog post.
Snyk has partnered with Sysdig to provide a comprehensive security solution for developers working with containerized applications and Kubernetes environments. The partnership aims to deliver end-to-end security from code development to runtime, reducing the noise of vulnerabilities and providing feedback and visibility from production back to developers. By combining Snyk's early feedback on containers during development and Sysdig's runtime intelligence, developers can prioritize critical issues and fix them faster, while security and ops teams can focus on real-time threats and incident response. The integration of the full Snyk and Sysdig platforms secures everything from code to infrastructure running in Kubernetes clusters.
Feb 16, 2022 679 words in the original blog post.
Research into Python object traversal found that recursively resolving user-influenced dotted attribute paths with `getattr()` can expose private data, bypass access controls, or enable remote code execution when dangerous methods are reached and invoked. Using custom rules in Snyk Code’s static analysis engine, the researcher identified this pattern in Celery’s `exception_to_python` function, where JSON-backed exception data could control a module name, attribute path, and argument. By supplying values that resolved to `os.system` and a command string, the researcher demonstrated stored command injection, tracked as CVE-2021-23727, which could allow attackers with backend access to execute commands and potentially compromise systems or move laterally through a network. Celery fixed the issue in version 5.2.2 by validating target modules and resolved attribute types before invoking functions, underscoring the need to treat deserialized or remotely stored data as untrusted and validate it before object resolution or method calls.
Feb 15, 2022 1,584 words in the original blog post.
Kubernetes resource management evolved from manual YAML definitions to Helm charts and then operators, which extend the Kubernetes API with custom control loops that automate application lifecycle tasks but can introduce security risks because they often require significant privileges. Securing operators begins with Kubernetes RBAC, using namespace-scoped Roles and RoleBindings where possible instead of cluster-wide permissions, applying least privilege, and regularly reviewing third-party operator roles and documentation. Operator developers and users share responsibility for limiting scope, favoring namespace-scoped operators unless cluster-wide functionality is necessary, and hardening operator containers through security contexts that prevent privilege escalation, root execution, and writable root filesystems. The discussion also notes the transition from deprecated PodSecurityPolicy to Pod Security Admission, which applies privileged, baseline, or restricted policies at the namespace level. When properly designed and controlled, operators can strengthen security by reducing manual configuration errors, responding to incidents faster, and running dedicated in-cluster security services such as Snyk, which identifies vulnerabilities in Kubernetes workloads.
Feb 15, 2022 1,375 words in the original blog post.
The Snyk Business trial is now available as a free trial for organizations to test their security across the entire Software Development Life Cycle (SDLC). The trial offers unlimited scanning in all Snyk products, scanning capabilities across the SDLC, and easy roll-out process. It also includes unlimited testing in various Snyk products, priority scoring, security fixes, dynamic monitoring, extensive reporting, intuitive management, and automation capabilities to support a quality security culture. This trial is designed to empower developers and security professionals to take control of their organization's security posture, reducing the risk of security incidents and improving overall application security knowledge.
Feb 15, 2022 612 words in the original blog post.
Regula, an open-source policy-as-code tool maintained by Fugue engineers and now associated with Snyk IaC, scans Terraform, CloudFormation, Azure Resource Manager, and Kubernetes configurations for security and compliance issues, including policies mapped to CIS benchmarks. The post demonstrates integrating Regula with Scalr, a Terraform automation and collaboration platform, to prevent insecure infrastructure from being deployed by running Regula as a pre-plan custom hook and Terraform formatting and validation checks after planning. Using intentionally vulnerable AWS S3 Terraform code, it shows how Regula identifies issues such as missing server-side encryption, reports severity, rule IDs, affected files, and remediation links, and blocks the Scalr pipeline through a nonzero exit code until violations are resolved. It also explains that teams can waive rules for individual resources or disable rules when operational requirements justify exceptions. After developers correct the configuration and recommit changes, Scalr reruns the hooks and, if they pass, completes Terraform plan and apply operations while managing state, illustrating an automated workflow for embedding IaC security checks into Terraform deployments.
Feb 11, 2022 2,123 words in the original blog post.
The Argo CD team discovered a high-severity vulnerability, CVE-2022-24348, which allows attackers to steal sensitive information from deployments by exploiting a directory/path traversal vulnerability in the Helm chart repository. The vulnerability affects versions 0.5.0 through 2.1.12, 2.2.7, and 2.3.1 of Argo CD. To fix this issue, users are advised to upgrade immediately to the latest versions, specifically 2.3.2, 2.2.8, or 2.1.14. The vulnerability highlights the importance of securing software supply chains against supply chain attacks, where attackers try to infiltrate software as it's being constructed rather than after its release. To mitigate this risk, developers can implement practices such as small, easy-to-review commits, treating all SDLC systems like production, not using shared credentials, and knowing their supply chain. Implementing a secure supply chain is critical, including private, managed repositories with vetted and signed artifacts, software bill of materials (SBoM), and tools like Snyk to automate security testing and compliance.
Feb 10, 2022 1,375 words in the original blog post.
Microservice security is a strategy that aims to minimize the risks associated with microservices application architecture, which involves building secure microservices and ensuring they communicate securely with each other. Microservices offer agility and flexibility in deployment and scaling, but also introduce security risks if not implemented properly. To address these risks, development teams should adopt a DevSecOps culture, integrate application security tools into their CI/CD pipelines, implement dependency scanning to detect vulnerabilities in open source components, use secure containers, build API gateways to protect APIs from abuse, and design the architecture with security in mind from the start. By following these best practices, organizations can ensure a more secure microservices-based application.
Feb 10, 2022 1,226 words in the original blog post.
Modern applications combine proprietary code with extensive open source dependencies, making both static application security testing (SAST) and software composition analysis (SCA) necessary for comprehensive security coverage. SAST analyzes internally written source or bytecode to identify potential vulnerabilities and code flaws, while SCA inventories direct and transitive open source dependencies to identify known vulnerabilities and licensing risks. Although traditional tools can be slow, difficult to integrate, and prone to false positives, using only one methodology leaves important areas unexamined: SAST cannot fully address third-party component risks, and SCA cannot detect flaws in custom code. A combined, developer-friendly approach should integrate early into development workflows, provide fast and actionable findings, and avoid adding unnecessary tool complexity or delaying releases. The text presents Snyk Code and Snyk Open Source as an example of a consolidated SAST and SCA platform that scans within IDEs, repositories, and CI/CD workflows, provides remediation guidance, and also extends coverage to containers and infrastructure as code.
Feb 10, 2022 1,806 words in the original blog post.
Pulumi is an open-source tool that enables developers to build code in multiple languages, such as JavaScript, Python, Go, TypeScript, and .NET, to create infrastructure as code (IaC). It supports Google Cloud, where a Pulumi stack can be created for automating the Snyk Kubernetes integration for containers. The process involves setting up a Kubernetes integration ID from the Snyk app, cloning a sample repository, authenticating to Google Cloud, creating a new Pulumi stack and configuring required settings, deploying everything with `pulumi up`, and retrieving the Kubernetes config. Once set up, the Snyk controller is installed in the snyk-monitor namespace, along with a config map and secret managed by Pulumi. The integration enables importing and testing running workloads and identifying vulnerabilities in their associated images and configurations that might make those workloads less secure.
Feb 09, 2022 2,064 words in the original blog post.
The Big Fix is a month-long event where developers, DevOps, and security practitioners come together to find and fix security vulnerabilities in software, open-source dependencies, Docker container images, or infrastructure as code policies. The event aims to make the digital world more secure by bringing together individuals of all skill levels and backgrounds. Participants will have access to Snyk's tools and expertise to help them identify and fix security issues in their projects. Those who participate will receive free Snyk swag, including a t-shirt, and be recognized for their efforts. The event culminates with a live 24-hour Big Fix-a-Thon streaming on Twitch, where experts will provide guidance and support to help participants overcome the biggest headaches. By joining The Big Fix, individuals can level up their security knowledge and developer expertise while making the software world more secure.
Feb 09, 2022 1,029 words in the original blog post.
The Payment Card Industry Data Security Standard (PCI DSS) is a thorough process that reviews companies' systems and policies for handling and storing sensitive consumer cardholder data, ensuring end users' data is kept safe and secure. PCI compliance is crucial in the payments industry, with MasterCard and Visa mandating merchants and service providers to be compliant, imposing penalties for non-compliance. The compliance process involves a series of checks by accredited third-party auditors to ensure secure data handling processes are in place. Static application security testing (SAST) and software composition analysis (SCA) tools can help meet PCI DSS requirements, with Snyk providing a platform to handle both needs. By using Snyk, developers can streamline the PCI compliance process, automate scanning into CI/CD pipelines, and document ongoing issues, making it easier to stay compliant.
Feb 08, 2022 1,359 words in the original blog post.
Karyn Smith has joined Snyk as the new Chief Legal Officer, bringing her extensive experience from Twilio and Zynga to the role. She will provide indispensable legal counsel and business advice to support Snyk's growth journey. Karyn previously served as General Counsel and Corporate Secretary at Twilio, where she successfully built a team of over 140 attorneys and supported the company's global expansion. Prior to that, she was Vice President and Deputy General Counsel at Zynga and a partner at Cooley LLP. She currently serves on the Board of Halcyon and is a founding member of Chief. As part of her transition, Stephanie Dominy will take on a new role as Vice President of Legal Operations and Special Projects. Karyn's appointment aims to continue Snyk's growth and help recruit more talented female leaders in 2022 and beyond.
Feb 07, 2022 539 words in the original blog post.
Nearly two months after Log4Shell’s disclosure, Snyk reports that it helped customers remediate the critical Java vulnerability up to 100 times faster than the industry average through rapid inclusion in its vulnerability database, real-time dependency and container scanning, analysis of transitive, unmanaged, and shaded JAR dependencies, and automated pull requests for fixes. The material promotes an infographic detailing the Log4Shell timeline, customer time and cost savings, and customer feedback, while also advertising an on-demand introductory workshop on solving capture-the-flag challenges.
Feb 05, 2022 167 words in the original blog post.
As enterprises undergo digital transformation, they need to rapidly deliver secure software with the ability to measure and manage application risk across multiple projects and development teams. Application risk profiling is a crucial aspect of this goal, involving a three-level approach to assessing risk: static categorization, dynamic quantification, and real-time assessment. By using tools like Snyk, enterprises can gain real-time visibility into application risk and prioritize efforts on high-risk applications. Key Risk Indicators (KRIs) also play a vital role in driving healthy vulnerability management, enabling teams to track application security metrics and surface vulnerabilities for remediation. By leveraging these approaches, enterprises can improve their security posture and deliver secure enterprise software.
Feb 03, 2022 875 words in the original blog post.
At Snyk, researchers spend time studying vulnerabilities to anticipate malicious hackers' actions. The author of the original Wordle game was acquired by the NY Times, leading to numerous copycat versions in app and web-app form. A custom Wordle site was discovered with a query string parameter that looked like gibberish but was actually ciphertext. The author attempted to solve it using Atbash ciphers, then Caesar ciphers, and ultimately found a key that could be used to decode any custom Wordle. This key revealed a pattern of letter shifts that can be applied to any custom Wordle, allowing the author to create their own puzzle with the same solution.
Feb 02, 2022 903 words in the original blog post.
Snyk applies its shift-left DevSecOps philosophy to API development by giving developers early, automated feedback on OpenAPI-defined REST APIs, helping improve delivery speed, security, consistency, and usability. To standardize its growing API-first platform, the company created an API Stylebook and initially used peer pull-request reviews, but recognized that manual reviews can be slow and prone to inconsistency in a distributed organization. Snyk therefore introduced local and CI-integrated linting based on shared rules, allowing developers to identify compliance issues before manual review. After finding conventional pattern-based linting insufficient for expressing evolving API standards, Snyk partnered with Optic to develop Optic CI, which uses a TypeScript-based rules language and evaluates changes between API versions rather than only static specifications. This approach is intended to support continuous API improvement without accumulating excessive exceptions, with future work planned around API version management.
Feb 01, 2022 1,128 words in the original blog post.