Shadow Code: an AI built the backdoor. Another AI found it.
A critical stored SQL injection discovered inside four internal codebases published to a personal public repository.
Cylent Labs
Case studies from live engagements, original research, and the intelligence we act on. Published as findings close.
A critical stored SQL injection discovered inside four internal codebases published to a personal public repository.
Two CI workflows trusted a stranger’s code with production secrets and package-publishing rights.
An anonymous dashboard exposed a production connection and accepted unauthenticated SQL through its datasource proxy.
5 articles
Case studyFrom one company name to a critical stored SQL injection inside code nobody knew was public.
Case studyHow an untrusted pull request reached production secrets and package-publishing rights.
Case studyA public dashboard became an unauthenticated proxy into its production database.
Case studyFour weaknesses chained from open registration to metadata theft and proprietary model exposure.
Case studyA benign public package began receiving callbacks from real machines within days.
Try a broader term or choose “All writing” to reset the archive.