You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
socket.dev/blog/spearph...
socket.dev/blog/spearph...
cc: @campuscodi.risky.biz @cisoseries.bsky.social @zackwhittaker.com
socket.dev/blog/spearph...
cc: @campuscodi.risky.biz @cisoseries.bsky.social @zackwhittaker.com
Full research → socket.dev/blog/malicio...
Full research → socket.dev/blog/malicio...
Full research → socket.dev/blog/malicio...
This fake “VPN” ran for years and charged users for the privilege of silently intercepting their traffic.
cc: @campuscodi.risky.biz @zackwhittaker.com @cisoseries.bsky.social
Full research → socket.dev/blog/malicio...
This fake “VPN” ran for years and charged users for the privilege of silently intercepting their traffic.
cc: @campuscodi.risky.biz @zackwhittaker.com @cisoseries.bsky.social
In case you missed this detail: with Docker Hardened Images teams get secure application dependencies by default. @socket.dev Firewall is built in.
@thenewstack.io breaks down why we made Docker Hardened Images free. Featuring Docker's VP of Product, Mike Donovan, on security, open source, and what comes next.
🔗 https://bit.ly/3N4DXt6
#DHI #OpenSource
In case you missed this detail: with Docker Hardened Images teams get secure application dependencies by default. @socket.dev Firewall is built in.
Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection for @nodejs.org, @python.org, and @rust-lang.org
socket.dev/blog/socket-...
Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection for @nodejs.org, @python.org, and @rust-lang.org
socket.dev/blog/socket-...
Check out the full episode → socket.dev/blog/softwar...
Check out the full episode → socket.dev/blog/softwar...
Full report →
socket.dev/blog/malicio... #dotnet
Full report →
socket.dev/blog/malicio... #dotnet
In this @softwaredaily.bsky.social episode, @feross.bsky.social joins @joshuakgoldberg.com to talk about why that’s so risky.
Check it out→ socket.dev/blog/softwar...
In this @softwaredaily.bsky.social episode, @feross.bsky.social joins @joshuakgoldberg.com to talk about why that’s so risky.
Check it out→ socket.dev/blog/softwar...
socket.dev/blog/npm-rev... #NodeJS #JavaScript
@feross.bsky.social
bit.ly/4iMDU14
@feross.bsky.social
bit.ly/4iMDU14
We're looking for stellar frontend developers. DM me
We're looking for stellar frontend developers. DM me
cc: @thisweekinrust.bsky.social @rustaceans.bsky.social @theembeddedrust.bsky.social @campuscodi.risky.biz
Details + IOCs: socket.dev/blog/malicio... #Rustlang
42,697 CVEs through Nov 30, running 16.9 percent higher than 2024.
The chart makes it obvious how steady the upward curve has been all year. The overall trend is sustained growth in disclosures.
42,697 CVEs through Nov 30, running 16.9 percent higher than 2024.
The chart makes it obvious how steady the upward curve has been all year. The overall trend is sustained growth in disclosures.
📖 Read more: www.helpnetsecurity.com/2025/12/04/m...
#cybersecurity #Cybersecuritynews @socket.dev #web3 #Rust
📖 Read more: www.helpnetsecurity.com/2025/12/04/m...
#cybersecurity #Cybersecuritynews @socket.dev #web3 #Rust
"What got you from zero to one is not what's going get you from one to 10. So you have to constantly evolve the way you run your business." -
@feross.bsky.social on the Vlad Kachur Show
🧨 Full Interview: socket.dev/blog/scaling...
"What got you from zero to one is not what's going get you from one to 10. So you have to constantly evolve the way you run your business." -
@feross.bsky.social on the Vlad Kachur Show
🧨 Full Interview: socket.dev/blog/scaling...
socket.dev/blog/elves-o... #NodeJS
cc: @campuscodi.risky.biz @thisweekinrust.bsky.social @theembeddedrust.bsky.social @rustaceans.bsky.social @weeklyrust.substack.com.web.brid.gy
socket.dev/blog/malicio... #Rustlang
cc: @campuscodi.risky.biz @thisweekinrust.bsky.social @theembeddedrust.bsky.social @rustaceans.bsky.social @weeklyrust.substack.com.web.brid.gy
Check out the full interview → socket.dev/blog/scaling... #appsec #infosec
Check out the full interview → socket.dev/blog/scaling... #appsec #infosec
Stay vigilant!
Full analysis → socket.dev/blog/malicio... #Solana
Stay vigilant!
(Compromised package count was updated to 834 from 533 in the latest @socket.dev update)
We’ve confirmed 834 malicious packages and now see spillover into Maven Central. The package org.mvnpm:posthog-node:4.18.1 contains the same Bun-based payload used in the npm compromise.
Updated analysis →
socket.dev/blog/shai-hu... #Java
(Compromised package count was updated to 834 from 533 in the latest @socket.dev update)