Have you heard of "cloaking"? Advertisers peddling malicious or adult content use cloaking technology to run ads without getting banned by Google, Facebook, TikTok, etc.
Bad guys are now using it to deliver dynamic payloads in malicious NPM packages! getsafety.com/blog-posts/npm…
The Safety research team has identified a new NPM based malware we are calling "Integrator-Filescrypt". This campaign uses a unique "cloaking" technique to hide from researchers and cloud providers. It's sneaky, & effective. Read more on our blog: getsafety.com/blog-posts/npm…
CVSS Severity is no longer an effective way to prioritize and triage your vulnerabilities! Learn how Safety's multi-dimensional approach to software vulnerability assessment reduces vulnerability noise by up to 90%. 🔍📊🛡️
safetycli.com/research/beyon…
In part 2 of our series on CVSS and the future of vulnerability assessment, read how Safety combines Severity with Exploitability, Reachability, and Project Context to allow developers to focus on the findings that matter. #devops#devsecops#CVSS#Python
2/ 🎯 Why the Change?
It's not just a name. We're launching TWO game-changing products and a whole new approach to software security. Stay tuned for details!
#softwaresupplychain