NPM Package Masquerading as Popular Material Tailwind Library To Install Malicious Code

Researchers at ReversingLabs discovered a malicious npm package masquerading as the Material Tailwind library. Their finding highlights a new trend for threat actors to install malicious code, dubbed impostor packages, say the researchers.

GitLab Cloud Seed Aims to Simplify Google Cloud Integration

At Google Next ’22, GitLab launched GitLab Cloud Seed, a new open-source solution integrated in GitLab One DevOps platform that aims to simplify Google Cloud account management, deployment to Google Cloud Run, and Google SQL database provisioning.

NCC Group Dissect Aims to Scale Incident Response to Thousands of Systems

Developed at Fox-IT, part of NCC Group, Dissect is a recently open-sourced toolset that aims to enable incident response on thousands of systems at a time by analyzing large volumes of forensic data at high speed, says Fox-IT.

Two New Git Vulnerabilities Affecting Local Clones and Git Shell Patched

Two Git vulnerabilities affecting local clones and git shell interactive mode in version 2.38 and older have been recently patched.

Docker Introduces Hardened Desktop for Business Users

The latest release of Docker Desktop introduces a new security model to help sys admins secure their organizations’ supply chains. Dubbed Hardened Desktop and available only to business customers, the new model includes Settings Management and Enhanced Container Isolation.