Socket

フィード

記事のアイキャッチ画像
GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government
Socket
GemStuffer abuses RubyGems as an exfiltration channel, packaging scraped UK council portal data into junk gems published from new accounts.
14時間前
記事のアイキャッチ画像
Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups
Socket
Socket was named to the Rising in Cyber 2026 list, recognizing 30 private cybersecurity startups selected by CISOs and security executives.
1日前
記事のアイキャッチ画像
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack
Socket
Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.
2日前
記事のアイキャッチ画像
fsnotify Maintainer Dispute Sparks Supply Chain Concerns
Socket
A dispute over fsnotify maintainer access set off supply chain alarms around one of Go’s most widely used filesystem libraries.
5日前
記事のアイキャッチ画像
Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape
Socket
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
5日前
記事のアイキャッチ画像
5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer
Socket
Five malicious NuGet packages impersonate Chinese .NET libraries to deploy a stealer targeting browser credentials, crypto wallets, SSH keys, and local files.
7日前
記事のアイキャッチ画像
pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies
Socket
pnpm 11 turns on a 1-day Minimum Release Age and blocks exotic subdeps by default, adding safeguards against fast-moving supply chain attacks.
9日前
記事のアイキャッチ画像
PyPI Fixes High-Severity Access Control Issues Found in Security Audit
Socket
The remediated findings include organization permission bugs, stale project access after transfers, OIDC replay edge cases, audit logging gaps, and an IDOR in API token deletion.
12日前
記事のアイキャッチ画像
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
Socket
GitHub account BufferZoneCorp published sleeper packages that later added credential theft, GitHub Actions tampering, fake go wrappers, and SSH persistence.
13日前
記事のアイキャッチ画像
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
Socket
Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.
13日前