Socket
フィード

The Changelog Podcast: Practical Steps to Stay Safe on npm
Socket
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.
21時間前

Security Community Slams MIT-linked Report Claiming AI Powers 80% of Ransomware
Socket
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.
2日前

Ruby Core Team Assumes Stewardship of RubyGems and Bundler, Former Maintainers Offer to Transfer All Rights to Matz
Socket
Ruby's creator Matz assumes control of RubyGems and Bundler repositories while former maintainers agree to step back and transfer all rights to end the dispute.
3日前

10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
4日前

Introducing Socket Firewall Enterprise: Flexible, Configurable Protection for Modern Package Ecosystems
1
Socket
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.
8日前

New CNAPulse Dashboard Tracks CNA Activity and Disclosure Trends
Socket
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.
8日前

Introducing GitHub Actions Scanning Support
Socket
Detect malware, unsafe data flows, and license issues in GitHub Actions with Socket’s new workflow scanning support.
9日前

Introducing Webhook Events for Pull Request Scans
Socket
Add real-time Socket webhook events to your workflows to automatically receive pull request scan results and security alerts in real time.
10日前

Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys
Socket
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
11日前

Unify Your Security Stack with Socket Basics
Socket
A single platform for static analysis, secrets detection, container scanning, and CVE checks—built on trusted open source tools, ready to run out of the box.
11日前
