Socket
フィード
NVD Backlog Tops 20,000 CVEs Awaiting Analysis as NIST Prepares System Updates
Socket
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
4時間前
Malicious npm Package Exploits WhatsApp Authentication with Remote Kill Switch for File Destruction
Socket
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.
4日前
PyPI Introduces Digital Attestations to Strengthen Python Package Security
Socket
PyPI now supports digital attestations, enhancing security and trust by allowing package maintainers to verify the authenticity of Python packages.
4日前
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
1
Socket
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
5日前
RubyGems.org Adds New Maintainer Role
Socket
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
6日前
Node.js Implements Stricter Policies for Semver-Major Pull Requests Ahead of Release Deadlines
1
Socket
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.
11日前
Roblox Developers Targeted with npm Packages Infected with Skuld Infostealer and Blank Grabber
Socket
Socket's threat research team has detected five malicious npm packages targeting Roblox developers, deploying malware to steal credentials and personal data.
11日前
vlt Debuts New JavaScript Package Manager and Serverless Registry at NodeConf EU
Socket
vlt introduced its new package manager and a serverless registry this week, innovating in a space where npm has stagnated.
11日前
Malicious Python Package Typosquats Popular 'fabric' SSH Library, Exfiltrates AWS Credentials
Socket
The Socket Research Team uncovered a malicious Python package typosquatting the popular 'fabric' SSH library, silently exfiltrating AWS credentials from unsuspecting developers.
13日前
JSR Working Group Kicks Off with Ambitious Roadmap and Plans for Open Governance
Socket
At its inaugural meeting, the JSR Working Group outlined plans for an open governance model and a roadmap to enhance JavaScript package management.
14日前