Socket

フィード

記事のアイキャッチ画像
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Socket
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
9時間前
記事のアイキャッチ画像
Python Tools Are Quickly Adopting the New pylock.toml Standard
Socket
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
10時間前
記事のアイキャッチ画像
Go Support Is Now Generally Available
Socket
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.
1日前
記事のアイキャッチ画像
vlt Launches Real-Time Dependency Analysis Powered by Socket
Socket
vlt adds real-time security selectors powered by Socket, enabling developers to query and analyze package risks directly in their dependency graph.
1日前
記事のアイキャッチ画像
CISA Extends MITRE Contract as Crisis Accelerates Alternative CVE Coordination Efforts
Socket
CISA extended MITRE’s CVE contract by 11 months, avoiding a shutdown but leaving long-term governance and coordination issues unresolved.
2日前
記事のアイキャッチ画像
Rubygems Ecosystem Support Now Generally Available
はてなブックマークアイコン 1
Socket
Socket's Rubygems ecosystem support is moving from beta to GA, featuring enhanced security scanning to detect supply chain threats beyond traditional CVEs in your Ruby dependencies.
3日前
記事のアイキャッチ画像
Malicious npm Package Disguised as Advcash Integration Triggers Reverse Shell
Socket
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment success, targeting servers handling transactions.
4日前
記事のアイキャッチ画像
Turtles, Clams, and Cyber Threat Actors: Shell Usage
Socket
The Socket Threat Research Team uncovers how threat actors weaponize shell techniques across npm, PyPI, and Go ecosystems to maintain persistence and exfiltrate data.
7日前
記事のアイキャッチ画像
VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Questions About Reform
Socket
At VulnCon 2025, NIST scrapped its NVD consortium plans, admitted it can't keep up with CVEs, and outlined automation efforts amid a mounting backlog.
8日前
記事のアイキャッチ画像
A New Design for GitHub PR Comments
はてなブックマークアイコン 1
Socket
We redesigned our GitHub PR comments to deliver clear, actionable security insights without adding noise to your workflow.
8日前