ProjectDiscovery's nuclei-templates repository received new pull requests adding exposure-detection templates for BaGet and Devtron. One submission, opened by DhiyaneshGeek, adds a template for detecting BaGet exposure and was marked verified:true, configured with max-request: 1, and validated with a Shodan query. The pull request carried a verified GitHub signature, was labeled Ready to merge, and automated review reported no security issues in the template.
A separate pull request by johnk3r adds two Devtron-focused templates: one to identify an exposed Devtron panel and another to detect an exposed env-config JavaScript file. The author said the templates were tested against both vulnerable and patched targets to improve accuracy and reduce false positives, while ProjectDiscovery's automated checks also found no security issues. Together, the submissions expand Nuclei coverage for identifying publicly exposed package management and DevOps administration assets.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A separate GitHub pull request (#15870) was opened in the same repository to add two Nuclei templates for detecting exposed Devtron panel and env-config resources. The submitter stated the templates were validated against vulnerable and patched targets, and automated review found no security issues.
A GitHub pull request (#15857) was opened in the projectdiscovery/nuclei-templates repository to add a new Nuclei template for detecting BaGet exposure. Automated review reported no security issues and marked the template as verified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.