RSS Amplifier

Blog

Socket

Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.

socket.devSource feed ↗12 posts

Live Last read · last published · next check

Written by

Latest posts

PHP and Composer Support Is Now in Beta

Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Socket Now Protects the Firefox Extension Ecosystem

Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Popular Rust Crates Compromised in Build-Time Supply Chain Attack

Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.

77 Firefox Extensions Linked to Crypto Wallet and Credential Theft

Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment

NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

How AI Agents Expand the Software Supply Chain Attack Surface

In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.

White House Authorizes Private Companies to Conduct Offensive Cyber Operations

A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Free Business Plan Upgrades for Open Source Maintainers

Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache

The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware

During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

AWS Security Hub Adds Socket for Supply Chain Security

Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.