Socket
フィード
38% of CISOs Fear They’re Not Moving Fast Enough on AI
Socket
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
13時間前
Go Supply Chain Attack: Malicious Package Exploits Go Module Proxy Caching for Persistence
Socket
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
1日前
Socket Joins TC54 to Help Shape the Future of SBOMs, CycloneDX, and PURL
Socket
Socket is joining TC54 to help develop standards for software supply chain security, contributing to the evolution of SBOMs, CycloneDX, and Package URL specifications.
5日前
PyPI’s New Archival Feature Closes a Major Security Gap
Socket
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
6日前
North Korean APT Lazarus Targets Developers with Malicious npm Package
Socket
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korean connection.
6日前
CISA Brings KEV Data to GitHub
Socket
CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated updates for security teams and researchers.
7日前
Opengrep Emerges as Open Source Alternative Amid Semgrep Licensing Controversy
Socket
Opengrep forks Semgrep to preserve open source SAST in response to controversial licensing changes.
8日前
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
1
Socket
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
12日前
cURL Project and Go Security Teams Reject CVSS as Broken
2
Socket
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
12日前
Bun 1.2 Released with Improved Node.js Compatibility and Built-in S3 Object Support
1
Socket
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.
14日前