Proofpoint has uncovered the Cruciferra crypter, an advanced malware delivery service using BYOVD, Process Ghosting, and multiple evasion techniques to deploy Windows malware.
GitHub has introduced a default three day cooldown for Dependabot version updates to help reduce the risk of poisoned software packages spreading through supply chains.