Christophe Tafani-Dereeper's Avatar

Christophe Tafani-Dereeper

@christophetd.fr

Cloud and container security β€’ Security research and open source at Datadog πŸ‡¨πŸ‡­πŸ‡«πŸ‡· https://christophetd.fr

1,499
Followers
116
Following
83
Posts
02.05.2023
Joined
Posts Following

Latest posts by Christophe Tafani-Dereeper @christophetd.fr

The Codex version is better. The tail pointer is the defining difference β€” it shows a stronger understanding of linked list design. O(1)
   append is the whole reason you'd use a linked list over an array in many scenarios, and the Claude version gets that wrong. The Codex
  version is also cleaner structurally (shared nodeAt helper, no redundant initializations).

The Codex version is better. The tail pointer is the defining difference β€” it shows a stronger understanding of linked list design. O(1) append is the whole reason you'd use a linked list over an array in many scenarios, and the Claude version gets that wrong. The Codex version is also cleaner structurally (shared nodeAt helper, no redundant initializations).

I asked Claude (Opus 4.6) and Codex (GPT-5.3) to each generate a simple LinkedList implementation in Java.

Then I asked Claude to pick the better one. No hesitation: "The Codex version is better" πŸ€”

gist.github.com/christophetd...

12.02.2026 14:43 πŸ‘ 7 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

If you're using VSCode or Cursor, this is a pretty solid extension to have in your toolbox!

26.01.2026 16:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Decoding the GitHub recommendations for npm maintainers | Datadog Security Labs This blog post explores the rationale and implementation behind GitHub's security recommendations for npm maintainers following numerous high-profile supply-chain incidents. It details how hardening p...

Decoding the GitHub recommendations for npm maintainers

securitylabs.datadoghq.com/articles/dec...

by @phrawzty.com

09.01.2026 14:52 πŸ‘ 0 πŸ” 3 πŸ’¬ 0 πŸ“Œ 1
Post image

Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users

securitylabs.datadoghq.com/articles/inv...

10.12.2025 13:04 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1
Post image Post image

CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js

securitylabs.datadoghq.com/articles/cve...

04.12.2025 21:47 πŸ‘ 6 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Preview
Building an npm worm Building an npm virus via self-replicating lifecycle scripts.

"Building an npm worm" (2016)

contolini.com/building-an-...

01.12.2025 09:57 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

A few days ago, a new piece of malware started spreading in npm, compromising and backdooring hundreds of legitimate npm packages and GitHub users. Read the analysis from our security research team:

securitylabs.datadoghq.com/articles/sha...

26.11.2025 08:57 πŸ‘ 6 πŸ” 5 πŸ’¬ 0 πŸ“Œ 1

If you're in cloud security, do have a look at this piece of research I've been working on! Feedback / thoughts welcome

08.10.2025 21:40 πŸ‘ 6 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
ChatControl wants to scan all your private messages The EU is pushing legislation that would scan all our private messages, even in encrypted apps.

The EU is advancing legislation requiring all messaging platforms to scan private messages, even in encrypted apps like Signal/WhatsApp/Telegram.

600+ security researchers oppose ChatControl for being technically flawed.

Learn more about it πŸ‘‰ metalhearf.fr/posts/chatco...

#ChatControl #privacy

25.09.2025 16:11 πŸ‘ 5 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1

Thanks! This was an incredibly great post

26.09.2025 20:51 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

If you're into cloud security, fwd:cloudsec Europe is now live.

Schedule: fwdcloudsec.org/conference/e...

15.09.2025 07:12 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Bitnami Deprecation

I did a bit more looking into the upcoming bitnami deprecation. The images are still getting millions of pulls a week, so depending on exactly what tags vanish next week, there could be a lot of broken deploys on the 28th!

raesene.github.io/blog/2025/08...

21.08.2025 13:11 πŸ‘ 5 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

@micahflee.com thank you for the amazing and inspiring defcon talk

10.08.2025 01:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I arbitrarily picked a list of 50 talks I'm most excited about that are happening next week at DEF CON / Black Hat / BSides LV / The Diana Initiative.

I'll also add recordings/slides to this list when they become available!

29.07.2025 20:17 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

Getting ready for DEF CON next week!

βœ… Slides
βœ… Demos
βœ… Custom shirt designed for the occasion

28.07.2025 10:23 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
MalwareBazaar - c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441 Threat intel on c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441 (MD5 ed375deea6f7407d2ff9dab1cb326473)

This is dropping ed375deea6f7407d2ff9dab1cb326473 (bazaar.abuse.ch/sample/c68e4...)

credits Varun Sharma for the share on LinkedIn

18.07.2025 22:34 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

Looks like the maintainer of a number of highly-popular npm packages was phished through npnjs[.]com, and his access used to publish malicious versions of their packages

x.com/JounQin/stat...

www.linkedin.com/feed/update/...

github.com/prettier/esl...

18.07.2025 22:34 πŸ‘ 5 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0

Great research, would you be able to share the sample GitHub repositories and/or their metadata? I'm working on an open-source tool and could use some additional samples!

08.07.2025 08:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Stratus Red Team AWS attack techniques are now mapped to the Threat Technique Catalog for AWS

Stratus Red Team AWS attack techniques: stratus-red-team.cloud/attack-techn...

Threat Technique Catalog by AWS: aws-samples.github.io/threat-techn...

23.06.2025 12:04 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Security Best Practices - Model Context Protocol

The MCP spec has been updated to include security best practices

β€’ Confused deputy
β€’ Token passthrough
β€’ Session hijacking

modelcontextprotocol.io/specificatio...

23.06.2025 08:54 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

Solid way to start the week

10.06.2025 09:38 πŸ‘ 29 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Anatidaephobia Anatidaephobia is the irrational fear of being watched/stalked by one or more duck(s). It is not a recognized or documented phobia in the field of psychology or psychiatry. The term "anatidaephobia" w...

phobia.fandom.com/wiki/Anatida...

26.05.2025 19:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

πŸ‘€

15.05.2025 14:19 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Happy to discuss submission ideas!

08.05.2025 10:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you're a cloud practitioner based in Europe, definitely submit to fwd:cloudsec Berlin happening in September!

We're actively seeking submissions from first time speakers and non-security folks. In that case, you can submit by May 30th and get initial feedback on your submission!

08.05.2025 10:39 πŸ‘ 7 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
fwd:cloudsec Europe 2025 | fwd:cloudsec fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...

Ticket sales for fwd:cloudsec Europe 2025 goes live on April 22nd, first batch at 9 AM CET and a second batch at 7PM CET. Tickets are sold through Swoogo, link at fwdcloudsec.org/conference/e... ..

20.04.2025 06:48 πŸ‘ 6 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0

My story breaking this news exclusively was 7K+ words and had almost all of this in it, and more:
www.npr.org/2025/04/15/n...

18.04.2025 01:57 πŸ‘ 4555 πŸ” 1990 πŸ’¬ 89 πŸ“Œ 121
Preview
Malicious Maven packages, SSRFs strike again, and stealing cloud credentials from web applications | Datadog Security Labs This month’s digest has a little bit of everythingβ€”cloud threats, supply chain attacks, and a reminder that yes, attackers are still exploiting SSRFs.

The March edition of the Datadog Security Digest is out!

securitylabs.datadoghq.com/newsletters/...

β€’ New MITRE ATT&CK coverage matrix in Stratus Red Team
β€’ Compromised GitHub actions
β€’ Malicious Maven packages
β€’ Exploitation of SSRF vulnerabilities on the rise
β€’ ... and more

27.03.2025 22:21 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Looking forward to it! ☁️πŸ‡ͺπŸ‡ΊπŸ‡©πŸ‡ͺ

24.03.2025 12:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections.

My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees.

Here’s what I found and why it matters πŸ‘‰ wietze.github.io/blog/bypassi...

24.03.2025 09:08 πŸ‘ 36 πŸ” 19 πŸ’¬ 1 πŸ“Œ 0