If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: research.jfrog.com - JFrog Security Research.

site address: research.jfrog.com redirected to: research.jfrog.com

site title: JFrog Security Research

Our opinion (on Thursday 27 August 2026 9:07:21 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=The latest security issues and vulnerabilities discovered by the JFrog security research team! CVE s, malicious packages and more;
description=Cutting Edge Security Research to Protect the Modern Software Supply Chain;
description=Cutting Edge Security Research to Protect the Modern Software Supply Chain;

Headings (most frequently used words):

jfrog, security, the, latest, by, team, vulnerabilities, discovered, in, edge, from, malicious, packages, flagged, catalog, oss, tools, released, cutting, research, to, protect, modern, software, supply, chain, get, critical, alerts, first, detection, report, products, powered, com,

Text of the page (most frequently used words):
the (63), and (38), jfrog (33), security (33), 2026 (26), cve (21), published (19), vulnerable (16), team (12), 2022 (12), research (11), #discovered (10), for (9), version (8), 2024 (8), time (8), packages (8), vulnerabilities (7), versions (7), oss (7), malicious (7), compromised (7), vulnerability (6), get (6), github (6), openssl (6), software (6), latest (6), jul (6), high (6), npm (6), all (5), report (5), our (5), code (5), you (5), with (5), 3094 (5), tools (5), threats (5), supply (5), chain (5), package (5), real (5), min (5), read (5), researcher (5), use (4), oct (4), class (4), jar (4), whether (4), commons (4), text (4), tool (4), nov (4), see (4), new (4), from (4), repositories (4), popular (4), catalog (4), via (4), aug (4), post (4), critical (4), crates (4), researchers (3), open (3), source (3), given (3), mar (3), affected (3), released (3), when (3), community (3), your (3), environment (3), flagged (3), 17497 (3), execution (3), execute (3), jfsa (3), 17496 (3), 17534 (3), 62661 (3), shai (3), hulud (3), were (3), platform (3), build (3), cookies (2), policy (2), powered (2), learn (2), more (2), about (2), products (2), findings (2), xray (2), quickly (2), both (2), edge (2), recursively (2), searches (2), stringlookupfactory (2), regardless (2), containing (2), file (2), names (2), content (2), pom (2), xml (2), files (2), attempts (2), fingerprint (2), objects (2), included (2), looks (2), scriptstringlookup (2), disables (2), lookup (2), function (2), effectively (2), patching (2), can (2), also (2), patch (2), disable (2), dnsstringlookup (2), urlstringlookup (2), funtionalities (2), finds (2), binaries (2), statically (2), linked (2), specifically (2), diferentiates (2), between (2), fixed (2), determines (2), client (2), authentication (2), required (2), ssl (2), server (2), which (2), case (2), servers (2), based (2), will (2), 3602 (2), 3786 (2), checks (2), local (2), machine (2), currently (2), last (2), updated (2), modern (2), help (2), continuously (2), automated (2), maintainers (2), releases (2), yuval (2), moravchick (2), notegen (2), arbitrary (2), command (2), natan (2), nehorai (2), medium (2), engineers (2), scanners (2), again (2), this (2), miasma (2), guy (2), korolevski (2), worm (2), has (2), nuget (2), json (2), net (2), betting (2), results (2), typosquat (2), identified (2), attack (2), installed (2), assume (2), cves (2), malware (2), through (2), keyv (2), rust (2), only (2), silently (2), proc (2), alerts (2), first (2), follow (2), discover (2), model (2), rights, reserved, ltd, settings, privacy, terms, com, how, top, priority, find, any, other, type, issue, one, please, immediately, may, able, participate, bug, bounty, program, earn, rewards, their, quality, part, group, behind, enhancing, its, unique, database, utilizing, patented, technology, detect, unknown, issues, proprietary, detection, scan_commons_text_versions, text_4_shell_patch, scan_vulnerable_openssl_code, openssl_req_client_cert, detector, arise, many, cases, respond, essence, supports, range, identify, such, detected, aggregated, global, sources, widespread, application, development, public, have, become, target, attacks, foster, secure, developers, monitors, tooling, reports, repository, wider, contains, indications, own, number, growing, tauri, shell, allow, bash, python, 001676778, chat, preview, xss, unsanitized, skill, html, rendering, 001676777, kimi, fetchurl, ssrf, protection, bypass, dns, resolving, hostnames, redirects, 001667223, reachy, mini, bluetooth, handler, root, script, path, traversal, collaborate, create, advanced, built, deep, understanding, attackers, techniques, continually, identifying, publicly, available, disclosing, them, posts, blogs, asyncapi, previously, during, second, coming, hijacked, deliver, valid, provenance, loaded, install, persistent, cross, backdoor, returns, disclosed, typosquatted, named, newtonsoftt, note, double, suffix, been, masquerading, newtonsoft, library, while, quietly, shipping, trojanized, fork, trojan, rigs, digitain, online, later, generations, exfiltrates, rigged, round, perfect, heist, targets, rig, blog, recently, targeting, xinference, pypi, yanked, after, users, reported, suspicious, behavior, imported, these, must, afek, berger, sqlite, llm, slop, spreading, starting, cacheable, harvests, credentials, publishes, itself, every, writable, plants, hooks, shavit, satou, major, campaign, strikes, affecting, 400, august, 20th, arrayref, internment, append, vec, pulled, macro1, macro2, whose, downloads, executes, remote, payload, cargo, yair, benamou, thank, spam, unsubscribe, anytime, know, uncover, zero, days, dedicated, are, committed, advancing, discovery, analysis, exposure, methods, cutting, protect, home, theme,


Text of the page (random words):
jfrog security research jfrog security research model threats discover follow jfrog security theme home model threats discover follow jfrog security cutting edge security research to protect the modern software supply chain our dedicated team of security engineers and researchers are committed to advancing software security through discovery analysis and exposure of new vulnerabilities and attack methods get critical security alerts first be the first to know when we uncover zero days critical cves and supply chain threats powered by jfrog security research team critical security alerts only no spam unsubscribe anytime thank you latest from jfrog s security latest from jfrog s security real time post compromised rust crates on crates io silently execute malware at build time yair benamou jfrog security researcher on august 20th the popular rust crates arrayref internment and append only vec were compromised on crates io the malicious versions silently pulled in proc macro1 a typosquat of proc macro2 whose build rs downloads and executes a remote payload on cargo build 5 min read published on 20 aug 2026 real time post major shai hulud campaign strikes npm again affecting keyv and 400 packages shavit satou jfrog security researcher the jfrog security research team identified a new version of the shai hulud supply chain malware spreading through compromised npm packages starting with keyv and cacheable the worm harvests credentials publishes itself to every writable npm package and plants execution hooks in github repositories if you installed a compromised version assume your environment is affected 8 min read published on 4 aug 2026 real time post sqlite critical cves or llm slop afek berger jfrog security researcher the jfrog security research team recently identified a supply chain attack targeting the xinference package on pypi versions 2 6 0 2 6 1 and 2 6 2 were compromised and yanked by maintainers after users reported suspicious behavior if you installed or imported these versions you must assume your environment is compromised 5 min read published on 30 jul 2026 blog the perfect heist nuget typosquat targets betting platform to rig results guy korolevski jfrog security researcher the jfrog security research team has discovered and disclosed a typosquatted nuget package named newtonsoftt json net note the double t and the net suffix this package has been masquerading as the popular newtonsoft json library while quietly shipping a trojanized fork the trojan rigs digitain an online betting platform and in later generations exfiltrates rigged round results 14 min read published on 21 jul 2026 real time post miasma worm returns to npm guy korolevski jfrog security researcher asyncapi npm packages previously compromised during shai hulud the second coming were hijacked again this time to deliver miasma v3 the malicious releases use valid npm provenance execute when loaded and install a persistent cross platform backdoor 11 min read published on 14 jul 2026 see all jfrog security blogs see all jfrog security real time posts latest vulnerabilities discovered by the team latest vulnerabilities discovered by the team jfrog security researchers and engineers collaborate to create advanced vulnerability scanners built on a deep understanding of attackers techniques we use our automated scanners to help the community by continually identifying new vulnerabilities in publicly available software packages and disclosing them vulnerabilities discovered see all vulnerabilities last updated on 25 aug 2026 the reachy mini bluetooth command handler is vulnerable to arbitrary root script execution via path traversal high cve 2026 62661 cve 2026 62661 cve 2026 62661 high discovered by natan nehorai published on 25 aug 2026 jfsa 2026 001667223 kimi code is vulnerable to a fetchurl ssrf protection bypass via dns resolving hostnames and redirects medium cve 2026 17534 cve 2026 17534 cve 2026 17534 medium discovered by natan nehorai published on 27 jul 2026 jfsa 2026 001676777 notegen is vulnerable to chat preview xss via unsanitized ai skill html rendering high cve 2026 17496 cve 2026 17496 cve 2026 17496 high discovered by yuval moravchick published on 26 jul 2026 jfsa 2026 001676778 notegen is vulnerable to arbitrary os command execution via tauri shell allow execute for bash python high cve 2026 17497 cve 2026 17497 cve 2026 17497 high discovered by yuval moravchick published on 26 jul 2026 malicious packages flagged in jfrog catalog malicious packages flagged in jfrog catalog given the widespread use of open source software oss packages in modern application development public oss repositories have become a popular target for supply chain attacks to help foster a secure environment for developers the jfrog security research team continuously monitors popular repositories with our automated tooling and reports malicious packages discovered to repository maintainers and the wider community the jfrog catalog contains malicious package indications both from open source repositories and jfrog s own findings the number of releases flagged as malicious in the jfrog catalog is continuously growing detected by jfrog research and aggregated from global sources latest security oss tools released by the team latest security oss tools released by the team when new software security threats arise in many cases the time to respond is of the essence the jfrog security research team supports the community with a range of oss tools to identify such threats in your software quickly oss tools released see all oss tools last updated on 31 mar 2024 cve 2024 3094 detector checks if the local machine is vulnerable to cve 2024 3094 and currently affected by cve 2024 3094 checks if the local machine is vulnerable to cve 2024 3094 and currently affected by cve 2024 3094 get it on github published on 31 mar 2024 published on 31 mar 2024 openssl_req_client_cert determines whether client authentication is required by the ssl server in which case servers based on openssl 3 0 0 3 0 6 will be vulnerable to cve 2022 3602 cve 2022 3786 determines whether client authentication is required by the ssl server in which case servers based on openssl 3 0 0 3 0 6 will be vulnerable to cve 2022 3602 cve 2022 3786 get it on github published on 2 nov 2022 published on 2 nov 2022 scan_vulnerable_openssl_code finds binaries with a statically linked version of openssl specifically the tool diferentiates between openssl 3 0 0 3 0 6 vulnerable versions and 3 0 7 fixed version finds binaries with a statically linked version of openssl specifically the tool diferentiates between openssl 3 0 0 3 0 6 vulnerable versions and 3 0 7 fixed version get it on github published on 2 nov 2022 published on 2 nov 2022 text_4_shell_patch looks for the vulnerable scriptstringlookup class in the commons text jar given and disables the lookup function effectively patching the vulnerability the tool can also patch disable the vulnerable dnsstringlookup and urlstringlookup funtionalities looks for the vulnerable scriptstringlookup class in the commons text jar given and disables the lookup function effectively patching the vulnerability the tool can also patch disable the vulnerable dnsstringlookup and urlstringlookup funtionalities get it on github published on 24 oct 2022 published on 24 oct 2022 scan_commons_text_versions recursively searches for the class code of stringlookupfactory regardless of containing jar file names and content of pom xml files and attempts to fingerprint the versions of the objects to report whether the included version of commons text is vulnerable recursively searches for the class code of stringlookupfactory regardless of containing jar file names and content of pom xml files and attempts to fingerprint the versions of the objects to report whether the included version of commons text is vulnerable get it on github published on 18 oct 2022 published on 18 oct 2022 the jfrog detection edge the jfrog security research team is part of the group behind jfrog xray enhancing its unique vulnerability database and utilizing patented technology to quickly detect unknown security issues in both open source and proprietary code learn more about xray report vulnerabilities discovered in jfrog products the security and quality of our code is a top priority for jfrog if you find a vulnerability or any other type of security issue in one of our products please report it to us immediately security researchers may be able to participate in a bug bounty program and earn rewards for their findings learn more about how to report a vulnerability powered by jfrog com terms of use cookies policy privacy policy cookies settings 2026 all rights reserved jfrog ltd
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • JFrog Security Research
  • twitter
  • Software Vulnerabilities
  • Reading Time
  • Software Vulnerabilities
  • Malicious Packages
  • OSS Tools
  • The JFrog Detection Edge
  • The JFrog Detection Edge
  • Powered By jfrog.com

Verified site has: 12 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-12


The site also has references to the 1 subdomain(s)

  jfrog.com  Verify


The site also has 2 references to external domain(s).

 twitter.com  Verify  github.com  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/research.jfrog.com/
X-GitHub-Request-Id 6528:170668:50967F:5118F3:6A8FFE48
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Thu, 27 Aug 2026 09:07:21 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290020-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787821641.103635,VS0,VE93
Vary Accept-Encoding
X-Fastly-Request-ID 6dfa38bfd428d0fd56802ebd0927d0402da735b2
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
last-modified Thu, 27 Aug 2026 01:44:00 GMT
access-control-allow-origin *
etag W/ 6a8f9660-17662
expires Thu, 27 Aug 2026 09:06:34 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache REVALIDATED
x-github-request-id CEAA:39DB2D:4E7EFE:4F0143:6A8FFE48
x-github-edge-region fra
accept-ranges bytes
date Thu, 27 Aug 2026 09:07:21 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290020-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787821641.222928,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 564f706177ee29f11fcbfe50b7b02a9ebdb5eb73
content-length 24047

Meta Tags

title="JFrog Security Research"
name="gridsome:hash" content="587e8798c61bb4eeedc356ba539fa1848925d7d4"
data-vue-tag="ssr" charset="utf-8"
data-vue-tag="ssr" name="generator" content="Gridsome v0.7.23"
data-vue-tag="ssr" data-key="viewport" name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"
data-vue-tag="ssr" data-key="format-detection" name="format-detection" content="telephone=no"
data-vue-tag="ssr" name="referrer" content="origin"
data-vue-tag="ssr" http-equiv="Content-Security-Policy" content="default-src * 'self' 'unsafe-eval' 'unsafe-inline' htt????/jfrog.com; img-src 'self' * data: ; font-src 'self' * data: ;"
data-vue-tag="ssr" name="title" content="JFrog Security Research"
data-vue-tag="ssr" name="description" content="The latest security issues and vulnerabilities discovered by the JFrog security research team! CVE's, malicious packages and more"
data-vue-tag="ssr" name="google-site-verification" content="22wipx-oHtD2k4YCDe8uUqr0MOjdLgBTUaqWznU14uw"
data-vue-tag="ssr" name="description" content="Cutting Edge Security Research to Protect the Modern Software Supply Chain"
data-vue-tag="ssr" name="description" content="Cutting Edge Security Research to Protect the Modern Software Supply Chain"

Load Info

page size24047
load time (s)0.295663
redirect count1
speed download81515
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"