Critical remote code execution in vm2, a widely used Node.js sandbox library
GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.
Read PostLearn about cybersecurity trends, best practices, and third-party threats to secure your code and digital infrastructure.

GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.
Read Post
GitLab's Threat Research Group found a critical template injection in Serena that runs attacker code the moment a developer opens a repository.

Stuck in an evaluation with no way out, an AI agent escaped in an hour through the one service on its allowlist. Here's the gap that opened.

GitLab’s Vulnerability Research team has uncovered a new Python supply chain attack targeting PyPI, deploying the Shai-Hulud worm to steal credentials from CI/CD systems.

Learn how we built custom controls that detect and prevent malware campaigns like those used for Contagious Interview and how to deploy them in your environment.

Learn how GitLab's Signals Engineering team built the WATCH framework to continuously validate our security monitoring pipeline.

Learn how centralized pipeline policies can detect and block the patterns behind a series of recent attacks.

Learn how GitLab's Signals Engineering team uses our AI platform to automatically surface detection gaps from security incidents — no manual review required.
All fields required