Socket
フィード

Introducing Webhook Events for Alert Changes
Socket
Add real-time Socket webhook events to your workflows to automatically receive software supply chain alert changes in real time.
1日前

ENISA Becomes a CVE Root, Expanding Its Role in Europe’s Vulnerability Ecosystem
Socket
ENISA has become a CVE Program Root, giving the EU a central authority for coordinating vulnerability reporting, disclosure, and cross-border response.
1日前

Introducing Socket Scanning for OpenVSX Extensions
Socket
Socket now scans OpenVSX extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
2日前

Announcing Bun and vlt Support in Socket
Socket
Bringing supply chain security to the next generation of JavaScript package managers
3日前

Announcing Socket Certified Patches: One-Click Fixes for Vulnerable Dependencies
Socket
A safer, faster way to eliminate vulnerabilities without updating dependencies
4日前

Reachability for Ruby Now in Beta
Socket
Reachability analysis for Ruby is now in beta, helping teams identify which vulnerabilities are truly exploitable in their applications.
5日前

npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
Socket
Malicious npm packages use Adspect cloaking and fake CAPTCHAs to fingerprint visitors and redirect victims to crypto-themed scam sites.
5日前

Another Round of TEA Protocol Spam Floods npm, But It’s Not a Worm
Socket
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.
8日前

PyPI Expands Trusted Publishing to GitLab Self-Managed as Adoption Passes 25 Percent
Socket
PyPI adds Trusted Publishing support for GitLab Self-Managed as adoption reaches 25% of uploads
8日前

Malicious Chrome Extension Exfiltrates Seed Phrases, Enabling Wallet Takeover
Socket
A malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions, enabling full wallet takeover.
10日前
