Socket

フィード

記事のアイキャッチ画像
Temporal API Ships in Chrome 144, Marking a Major Shift for JavaScript Date Handling
Socket
Chrome 144 introduces the Temporal API, a modern approach to date and time handling designed to fix long-standing issues with JavaScript’s Date object.
3日前
記事のアイキャッチ画像
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Socket
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
4日前
記事のアイキャッチ画像
Node.js Fixes AsyncLocalStorage Crash Bug That Could Take Down Production Servers
Socket
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.
5日前
記事のアイキャッチ画像
Malicious Chrome Extension Steals MEXC API Keys for Account Takeover
Socket
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.
7日前
記事のアイキャッチ画像
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives Growth
Socket
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.
10日前
記事のアイキャッチ画像
Insecure Agents Podcast: Certified Patches, Supply Chain Security, and AI Agents
Socket
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.
11日前
記事のアイキャッチ画像
Tailwind CSS Announces 75% Layoffs as LLMs Reshape OSS Business Models
Socket
Tailwind Labs laid off 75% of its engineering team after revenue dropped 80%, as LLMs redirect traffic away from documentation where developers discover paid products.
11日前
記事のアイキャッチ画像
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens
Socket
The planned feature introduces a review step before releases go live, following the Shai-Hulud attacks and a rocky migration off classic tokens that disrupted maintainer workflows.
12日前
記事のアイキャッチ画像
GitHub Actions Pricing Whiplash: Self-Hosted Actions Billing Change Postponed
Socket
GitHub postponed a new billing model for self-hosted Actions after developer pushback, but moved forward with hosted runner price cuts on January 1.
14日前
記事のアイキャッチ画像
2025 Report: Destructive Malware in Open Source Packages
Socket
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
1ヶ月前