Skip to content

Enhance Figma link detection for credential theft#4034

Merged
peterdj45 merged 4 commits intomainfrom
peter.fn.link_figma_deck_cred_theft
Mar 4, 2026
Merged

Enhance Figma link detection for credential theft#4034
peterdj45 merged 4 commits intomainfrom
peter.fn.link_figma_deck_cred_theft

Conversation

@peterdj45
Copy link
Copy Markdown
Member

Description

broadening scope of the rule to include /design/ link paths

also adding suspicious topic check

Associated samples

@peterdj45 peterdj45 requested a review from a team February 14, 2026 02:01
@peterdj45 peterdj45 requested a review from a team as a code owner February 14, 2026 02:01
github-actions Bot added a commit that referenced this pull request Feb 14, 2026
@github-actions github-actions Bot added test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules hunting-required Hunts needed to validate rule efficacy labels Feb 14, 2026
@github-actions
Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

github-actions Bot added a commit that referenced this pull request Mar 4, 2026
@peterdj45
Copy link
Copy Markdown
Member Author

hunts look good, results in ESC-7382

L90D Shared EML: https://platform.sublime.security/messages/hunt?huntId=019cb643-6935-75a1-b692-a57e1b8ff4e9

@peterdj45 peterdj45 added the review-needed Indicates that a PR is waiting for review label Mar 4, 2026
@peterdj45 peterdj45 added this pull request to the merge queue Mar 4, 2026
Merged via the queue into main with commit bc2d3df Mar 4, 2026
3 checks passed
@peterdj45 peterdj45 deleted the peter.fn.link_figma_deck_cred_theft branch March 4, 2026 19:27
github-actions Bot added a commit that referenced this pull request Mar 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy review-needed Indicates that a PR is waiting for review test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants