Socket
フィード

Identifying and Preventing Fraudulent Engineering Candidates: An Investigation into 80 Confirmed Cases
Socket
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
21時間前

Ongoing Supply Chain Attack Targets CrowdStrike npm Packages
1

Socket
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.
2日前

Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
5

Socket
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
3日前

pnpm 10.16 Adds New Setting for Delayed Dependency Updates
Socket
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
3日前

Crates.io Users Targeted by Phishing Emails
Socket
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
6日前

Introducing Custom Pull Request Alert Comment Headers
Socket
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.
6日前

Rust Support Now in Beta
Socket
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.
7日前

Announcing Socket Fix 2.0
1

Socket
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
8日前

Feross on Risky Business Weekly Podcast: npm’s Ongoing Supply Chain Attacks
Socket
Socket CEO Feross Aboukhadijeh joins Risky Business Weekly to unpack recent npm phishing attacks, their limited impact, and the risks if attackers get smarter.
8日前

Introducing Tier 1 Reachability: Precision CVE Triage for Enterprise Teams
Socket
Socket’s new Tier 1 Reachability filters out up to 80% of irrelevant CVEs, so security teams can focus on the vulnerabilities that matter.
9日前