Software Supply Chain Security for Python.
Monitor and secure Python packages against vulnerabilities using the industry's leading vulnerability database.
Have you heard of "cloaking"? Advertisers peddling malicious or adult content use cloaking technology to run ads without getting banned by Google, Facebook, TikTok, etc.
Bad guys are now using it to deliver dynamic payloads in malicious NPM packages! https://t.co/1NGyuifvMT
The Safety research team has identified a new NPM based malware we are calling "Integrator-Filescrypt". This campaign uses a unique "cloaking" technique to hide from researchers and cloud providers. It's sneaky, & effective. Read more on our blog: https://t.co/1NGyuifvMT
A HIGH-severity CVE in cURL and libcurl was disclosed today. Read how these vulnerabilities impact the Python ecosystem and the steps you can take to protect your projects:
https://t.co/ehWvytWn1c #cve#python#curl#libcurl#vulnerabilities#DevOps#devsecops
In part 2 of our series on CVSS and the future of vulnerability assessment, read how Safety combines Severity with Exploitability, Reachability, and Project Context to allow developers to focus on the findings that matter. #devops#devsecops#CVSS#Python
CVSS Severity is no longer an effective way to prioritize and triage your vulnerabilities! Learn how Safety's multi-dimensional approach to software vulnerability assessment reduces vulnerability noise by up to 90%. πππ‘οΈ
https://t.co/sl6Ar0E21r
6/ π€ Let's Connect! We're eager to hear your thoughts and challenges in software supply chain security.
https://t.co/vMR72DncjW
#vulnerabilitymanagement
π’ Thread: PyUp is now Safety Cybersecurity! π
1/ π We've got some exciting news! PyUp is now Safety Cybersecurity! We're on a mission to improve how you secure your software supply chain.
https://t.co/uekr5UnUoL
#SafetyCybersecurity#DevSecOps#SoftwareSupplyChain
2/ π― Why the Change?
It's not just a name. We're launching TWO game-changing products and a whole new approach to software security. Stay tuned for details!
#softwaresupplychain
Learn about the role of CVSS in software supply chain vulnerabilities in our latest blog post, and why severity isn't enough when prioritizing and triaging your vulnerabilities. ππ‘οΈπ https://t.co/09rVh6Yqg2
#Python#CVSS#Cybersecurity#softwaresupplychain#devsecops#DevOps
ReDoS Vulnerabilities: Beyond Python (Part 3)
Read about our Cybersecurity Intelligence Team's discovery of new ReDoS vulnerabilities in Git-url-parse, Semgrep and OSSGadget in our latest research post https://t.co/np5M4xXobb #Cybersecurity#SoftwareSupplyChain#Python#DevSecOps