| Date | Title | Description |
| 16.08.2026 | AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push | Amazon Web Services is threading its AI-powered security infrastructure directly into the coding environments built by two of its fiercest rivals — and in doing so, it is making a bold bet that controlling the security layer matters more th... |
| 01.08.2026 | npm Closes Skeleton-Key Attack Surface: Bypass Tokens Lose Account Control | By Shannon Harwood
Published: Aug 01 2026, 1:33 PM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 20.07.2026 | GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window | By Kyle Belmonte
Published: Jul 20 2026, 6:41 AM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 04.07.2026 | North Korea’s Lazarus Group Hid a Full RAT in Six Rollup Polyfill npm Packages | By Clayton Lewis
Published: Jul 04 2026, 7:01 AM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 01.07.2026 | AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It | By Kyle Belmonte
Published: Jul 01 2026, 1:24 PM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 18.06.2026 | Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next | Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary.
On June 15, Varonis disclosed... |
| 16.06.2026 | Cyber Leaders Warn Anthropic Ban Could Weaken Defenders | More than 50 cybersecurity professionals have publicly called on the US government to lift export controls restricting access to Anthropic’s latest frontier large language models, warning that the move risks weakening defenders while advers... |
| 13.06.2026 | npm v12 Security Overhaul Blocks Install Scripts by Default: July Deadline for CI Migration | By Shannon Harwood
Published: Jun 13 2026, 10:14 AM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 13.06.2026 | Malware cita armas nucleares, engana IA e invade servidores | O Hades burla varreduras para roubar credenciais e chaves de servidores (ilustração: Vitor Pádua/Tecnoblog) Resumo
O malware Hades utiliza técnica de injeção de prompt para invadir servidores, inserindo textos sobre armas nucleares para con... |
| 26.05.2026 | npm Supply Chain Attacks Hit GitHub: 2FA Approval Gate Now Blocks Stolen CI Tokens | By Adrian Parham
Published: May 26 2026, 08:10 AM EDT
Share on Facebook Share on Twitter Share on LinkedIn Share on Reddit Share on Flipboard |
| 23.05.2026 | Cybersecurity Unicorn Socket Raises $60M for AI Software Supply Chain Defense | Socket secures $60M Series C, achieving a $1B valuation. The firm battles escalating software supply chain risks. AI fuels rapid code generation. This increases open-source dependency exposure. Socket's platform offers real-time analysis. I... |
| 21.05.2026 | AI security startup Socket hits $1B valuation after $60M raise to stop software supply chain attacks | AI-generated code is flooding into enterprise software faster than security teams can review it, and investors are betting that startups capable of spotting threats before they reach production could become one of the hottest categories in ... |
| 21.05.2026 | Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI | Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI
Led by Thrive Capital, the round brings Socket to unicorn status as enterprises race to adopt AI coding tools and look for ways to secure the third-pa... |
| 21.05.2026 | Socket Raises $60M to Strengthen AI Security | Socket has a $60 million Series C funding round, catapulting the company into unicorn territory with a $1 billion valuation. The huge round arrives at a time of increasing enterprise fear of the deluge of unvetted, open-source code arriving... |
| 21.05.2026 | Socket: $60 Million Series C Raised At $1 Billion Valuation To Help Enterprises Secure AI-Generated Code | Socket announced it has raised $60 million in Series C funding at a $1 billion valuation as enterprises accelerate adoption of AI coding tools and seek better ways to secure third-party open source dependencies entering production environme... |
| 20.05.2026 | Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI | Socket Logo
Series C
Socket Team
Socket is scaling to defend open source against supply chain attacks as AI accelerates software development. SAN FRANCISCO, CA, UNITED STATES, May 20, 2026 /EINPresswire.com/ -- Socket Raises $60M Series C a... |
| 12.05.2026 | Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps | Any development environment that installed or imported one of the 172 compromised npm or PyPI packages published since May 11 should be treated as potentially compromised. On affected developer workstations, the worm harvests credentials fr... |
| 28.04.2026 | Socket Acquires Secure Annex to Expand Extension Security Across Browsers and Developer Tools | Socket acquires Secure Annex
Socket CEO Feross Aboukhadijeh and Secure Annex founder John Tuckner
Founder John Tuckner, the company’s sole employee, joins Socket as it broadens its platform across another part of the software supply chain
M... |
| 15.04.2026 | Massive Chrome Extension Scam Exposes 20,000 Users to Data Theft | Image: Generated via Google Nano Banana
About 20,000 people have had their data stolen by a single hacking group that weaponized 108 Chrome Extensions in a numbers game.
Discovered by Socket, a security research organization, these Chrome e... |
| 01.04.2026 | Hackers slipped a trojan into the code library behind most of the internet. Your team is probably affected | Attackers stole a long-lived npm access token belonging to the lead maintainer of axios, the most popular HTTP client library in JavaScript, and used it to publish two poisoned versions that install a cross-platform remote access trojan. Th... |
| 16.02.2026 | ТОП-5 ИБ-событий недели по версии Jet CSIRT | Сегодня в ТОП-5 — ботнет SSHStalker взломал 7000 машин под управлением Linux, расширение Chrome крадет корпоративные данные, фальшивый 7-Zip превращает ПК в скрытый прокси-узел, вредоносная надстройка для Outlook похитила более 4000 учетных... |
| 04.02.2026 | Chrome Add-On Caught Stealing Amazon Commissions | image: envato by Image-Source
A Chrome browser extension advertised as a way to hide sponsored ads on Amazon has been caught quietly hijacking affiliate links in the background, redirecting commissions to its developer without users’ knowle... |
| 14.12.2025 | Opine: $5 Million Raised To Expand Unified AI Workspace For Technical Sales Teams | Opine, a Raleigh, North Carolina-based startup building an AI-native workspace for complex B2B technical sales, has raised $5 million in financing, including $3 million in new funding led by S3 Ventures. The company said the round also incl... |
| 27.11.2025 | Crypto Thieves Steal Solana via Hidden Chrome Extensions | Crypto Copilot. Source: Chrome Web Store
The latest threat targeting cryptocurrency users has emerged with surgical precision, and it’s happening in your browser.
This is a sophisticated attack method where malicious Chrome extensions are i... |
| 25.11.2025 | ТОП-5 ИБ-событий недели по версии Jet CSIRT | Сегодня в ТОП-5 — вредоносные пакеты npm используют Adspect для кражи криптовалюты, новый дефект SonicWall SonicOS, новый ботнет на базе Node.js с управлением через блокчейн Ethereum, новый банковский троян Sturnus для Android, хакеры Plush... |
| 24.04.2025 | Socket Acquires Coana | Socket, a San Francisco, CA-based software supply chain security company, acquired Coana, an Aarhus, Denmark-based static analysis and reachability engine provider.
The amount of the deal was not disclosed.
Led by CEO Anders Søndergaard, Co... |
| 23.04.2025 | Endor Labs raises $93M to secure AI-generated code from vulnerabilities
Your vote of support is important to us and it helps us keep the content FREE.
One click below supports our mission to provide f... | Code and application security startup Endor Labs Inc. today announced it has closed another big funding round, raising $93 million in a Series B funding led by DFJ Growth.
New investor Salesforce Ventures and existing backers including Ligh... |
| 18.04.2025 | The Double-Edged Sword of AI: Nvidia's Export Dilemma and Slopsquatting Threats | In the fast-paced world of technology, two narratives are unfolding that highlight the complexities of artificial intelligence (AI). On one side, Nvidia grapples with the fallout from U.S. export restrictions on its AI chips. On the other, ... |
| 16.04.2025 | Developers Beware: Slopsquatting & Vibe Coding Can Increase Risk of AI-Powered Attacks | Security researchers and developers are raising alarms over “slopsquatting,” a new form of supply chain attack that leverages AI-generated misinformation commonly known as hallucinations. As developers increasingly rely on coding tools like... |
| 24.12.2024 | The Rising Tide of Cyber Threats: Navigating the New Landscape | In the digital age, cyber threats are like shadows lurking in the corners of our online lives. They evolve, adapt, and strike when least expected. Recent reports highlight a surge in sophisticated attacks, driven by advanced technologies li... |
| 23.12.2024 | ТОП-5 ИБ-событий недели по версии Jet CSIRT | Сегодня в ТОП-5 — стиллер CoinLurker, создающий новое поколение вредоносных обновлений, уязвимость OpenAI Calendar Notification ByPass, атака Link Trap с быстрым внедрением GenAI, атака цепочки поставок на пакеты Rspack npm, а также методы ... |
| 20.12.2024 | Исследователи: на GitHub есть около 4,5 млн фейковых оценок, которые путают разработчиков | Исследователи Университета Карнеги Меллон, Университета штата Северной Каролины и компании Socket Inc выяснили, что на GitHub есть более 4,5 млн фейковых оценок репозиториев. Это путает разработчиков, а злоумышленникам помогает продвигать в... |
| 19.12.2024 | Атаки на GitHub-разработчика в 2024 году | Тренд «Platform Engineering», предложенный аналитическими агентствами, стал интересен не только компаниям, которые трансформируют свои процессы, команды и инструменты согласно новым подходам. Этот тренд также интересует и злоумышленников, к... |
| 28.10.2024 | Socket: Software Supply Chain Security Company Raises $40 Million (Series B) | Socket, a company protecting software from supply chain attacks, announced a $40 million funding round. The company monitors open-source packages for malicious behaviors like backdoors, typo-squatting, and obfuscated code.
The Socket Series... |
| 23.10.2024 | The Rise of Cryptocurrency Wallets: Navigating the Digital Currency Landscape | In the world of finance, a wallet is essential. It holds your cash, your cards, your identity. In the digital realm, cryptocurrency wallets serve a similar purpose. They are the gatekeepers of your digital assets. Without them, navigating t... |
| 23.10.2024 | Socket Raises $40M in Funding | Socket, a San Francisco, CA-based provider of a security platform that protects your most critical apps from software supply chain attacks, raised $40M in funding.
The round, which brought the total amount to $65M, was led by Abstract Ventu... |
| 22.10.2024 | Socket secures $40M to strengthen open-source software security
Your vote of support is important to us and it helps us keep the content FREE.
One click below supports our mission to provide free, dee... | Supply chain security startup Socket Inc. announced today that it has raised $40 million in new funding to fuel its mission to modernize security for open-source software and expand its team across engineering, product and design.
Founded i... |
| 01.10.2024 | Cloudflare запустила мастер настройки для управления файлом security.txt | Cloudflare запустила мастер настройки, позволяющий пользователям легко создавать и управлять файлом security.txt для раскрытия уязвимостей на своих веб-сайтах. Этот формат файла был предложен в качестве стандарта для помощи в раскрытии уязв... |
| 22.05.2024 | Corepack в Node.js: возможности и перспективы | Привет!
Меня зовут Алексей Голодников, я фронтенд-разработчик в ЮMoney. Недавно я рассказывал на митапе Frontend Mix про обновление наших веб-приложений до Node.js 20. После доклада в секции вопросов подняли тему Corepack, и я решил рассказ... |
| 31.03.2024 | Деструктивный пакет everything напомнил об уязвимостях реестра npm | Пакетный менеджер npm попал в неприятную историю, которая снова возродила споры о принципах работы реестра с микрозависимостями для JavaScript (и Node.js).
Критики утверждают, что уровень зависимостей в npm слишком большой. Многие помнят ис... |
| 06.02.2024 | Malicious NPM package disguises itself to steal Roblox data | A new threat to Roblox players comes in the form of a malicious impersonator of official Noblox.js and Noblox.js open-source downloads.
Noblox.js is an open-source Roblox API wrapper written in JavaScript that interacts with the game’s webs... |
| 06.10.2023 | Дорогая, я уменьшил пакет npm | Вы когда-нибудь задумывались, что скрывается за пакетом npm?
По сути, это не что иное, как сжатый gzip'ом архив. При разработке программного обеспечения исходный код почти всегда поставляется в виде файлов .tar.gz или .tgz. Сжатие gzip подд... |
| 01.08.2023 | Socket lands $20M investment to help companies secure open source software | Socket, a startup that provides a scanning tool to detect security vulnerabilities in open source code, today announced that it raised $20 million in a Series A round led by Andreessen Horowitz (a16z).
The tranche had participation from Abs... |
| 01.08.2023 | Socket Raises $20M in Series A Funding | Socket, a San Francisco, CA-based startup that fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript and Python dependencies, raised $20M in Series A funding round.
The round ... |
| 01.08.2023 | Investing in Socket | Open source is the bedrock upon which all modern applications are built. But here’s the elephant in the room: There is a huge attack surface hidden within this seemingly solid foundation, and the proliferation of open source usage has opene... |
| 16.12.2022 | Лучшие практики безопасности Node.js | Назначение
Этот документ призван расширить текущую модель угроз и предоставить подробные рекомендации по обеспечению безопасности приложения Node.js.Содержание документа
Лучшие практики: Простой и сжатый способ ознакомиться с лучшими практи... |
| 27.07.2022 | Protestware on the rise: Why developers are sabotaging their own code | Ax Sharma Contributor
Share on Twitter
Ax Sharma is a security researcher and reporter. His areas of interest include open source software security, malware analysis, data breaches and scam investigations.
If combating attacks and hijacking... |
| 12.05.2022 | Google launches ‘open-source maintenance crew’ | We are excited to bring Transform 2022 back in-person July 19 and virtually July 20 - 28. Join AI and data leaders for insightful talks and exciting networking opportunities. Register today!
Today, at the White House Open Source Security Su... |
| 11.05.2022 | Socket lands $4.6M to audit and catch malicious open source code | Securing the software supply chain is admittedly somewhat of a dry topic, but knowing which components and code go into your everyday devices and appliances is a critical part of the software development process that billions of people rely... |
| - | Socket | “Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.” |
| - | Socket | - |
| - | Socket | “Secure your JavaScript supply chain. Depend on Socket to protect your app from malicious dependencies lurking in your open source supply chain.” |