Flux
Toutes les sources

Socket

142 articles Flux RSS
Cybersécurité Programmation
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing Récent

GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing

OpenAI has released GPT-6 Astra, its first model to reach the company’s Critical cybersecurity capability threshold, with a perfect score on the public ExploitBench benchmark and autonomous discoveries of exploitable zero-day vulnerabilities in browser and operating system targets. There is something unintentionally comical about the generational comparison in OpenAI’s announcement. Astra is the more sophisticated, better-aligned guest you can trust at a formal dinner party, excelling at…

Socket
Microsoft Teams Notifications Are Now Available in Socket

Microsoft Teams Notifications Are Now Available in Socket

Today, we’re excited to add Microsoft Teams as a notification channel in Socket. Security and engineering teams can now send organization alerts and supply chain attack campaign notifications directly to the Teams channels they already monitor, with filters that control exactly which events reach each destination. When Socket finds something that needs attention, teams shouldn’t have to keep another dashboard open to find out. Microsoft Teams notifications bring relevant security activity into…

Socket
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%

pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%

pnpm 12 is now stable, replacing the package manager’s Node.js and TypeScript foundation with a Rust rewrite while preserving the commands, settings, and lockfile format used by pnpm 11. Early results from a large production monorepo show install times falling by as much as 90%, although a dispute over flawed and outdated package manager benchmarks has complicated broader claims about where pnpm now ranks against Bun and other rivals. Released August 26, pnpm 12 is designed to be a major…

Socket
6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat

6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat

Socket CTO Ahmad Nassri recently sat down with five other AppSec leaders on The Secure Disclosure podcast for an unfiltered discussion on the state of software supply chain security. Hosting six competing CTOs and security researchers in one room provided a candid look at how upstream threats are evolving, the operational limits of package registries, and why commercial threat intelligence siloing leaves engineering teams exposed. A few of the highlights: Vulnerabilities vs. Active Malicious…

Socket
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed…

Socket
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Ten malicious versions were published with valid npm provenance after a threat actor abused a comment-triggered GitHub Actions publishing workflow, with the latest release still compromised at the time of writing. The Socket Threat Research Team is investigating an ongoing Mini Shai-Hulud compromise, affecting the npm package @7nohe/openapi-react-query-codegen. On August 28, 2026, ten malicious versions were published in two waves roughly twenty minutes apart, spanning every maintained release…

Socket
When Autonomous Agents Escape: Why Socket Signed the Cyber Defense Open Letter

When Autonomous Agents Escape: Why Socket Signed the Cyber Defense Open Letter

OpenAI is mobilizing a collective response to the rapidly increasing capabilities of AI models and the rising threat of autonomous, machine-speed cyberattacks. In an effort to rally global defenses, a coalition of more than 100 technology, cybersecurity, and financial organizations, including Google, Microsoft, Anthropic, AWS, Cloudflare, and CrowdStrike, has signed an open letter calling for a surge in defenses. Socket signed because software supply chain security requires industry-wide…

Socket
Socket Now Protects the Microsoft Edge Extension Ecosystem

Socket Now Protects the Microsoft Edge Extension Ecosystem

Today, Socket is expanding browser extension security to Microsoft Edge. Enterprise security teams can now evaluate extensions published through Microsoft Edge Add-ons and monitor new releases for malicious behavior, excessive permissions, data collection, suspicious infrastructure, and changes that introduce new risk. This brings the same code and behavioral analysis already available for Chrome and Firefox to Microsoft’s extension ecosystem. Socket examines what an extension can access, what…

Socket
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads

Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server. Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is…

Socket
Socket for ClickUp Is Now Available

Socket for ClickUp Is Now Available

Today, we’re excited to launch Socket for ClickUp in beta. On the heels of our Socket for Asana release, the new integration gives teams another way to send Socket alerts directly into the tools they already use to manage work. ClickUp brings tasks, docs, whiteboards, and chat into one highly customizable platform. If your organization uses it to organize work, Socket alerts can now become assigned, trackable tasks in the same Lists and workflows your teams already use. Create tasks manually…

Socket
Socket for Asana Is Now Available

Socket for Asana Is Now Available

Today, we’re excited to launch Socket for Asana. The new integration turns Socket alerts into assigned, trackable Asana tasks, either one at a time or automatically using ticketing rules. Teams can route each task to the right project, add tags and an assignee, and keep the task and its linked Socket alert in sync as the work moves forward. The integration removes the manual work of recreating findings in Asana and updating both systems separately, while giving teams control over how alerts…

Socket
Open VSX Unblocks Extension IDs Used in Malware Campaign

Open VSX Unblocks Extension IDs Used in Malware Campaign

Over a five-day period from August 16 through August 20, the registry unblocked AlDuncanson.react-hooks-snippets, magne-sjaastad.opm-flow-editor-support, and rumbledb.jsoniq-vscode. All three IDs had been used by impostors in the 77-extension evil-twin campaign documented by Manifold Security earlier this month. Legitimate versions of the OPM and RumbleDB extensions are now live. React Hooks Snippets has been unblocked, but its legitimate Open VSX listing had not appeared as of publication. The…

Socket
PHP and Composer Support Is Now in Beta

PHP and Composer Support Is Now in Beta

Today, Socket’s PHP and Composer support is moving from Experimental to Beta and is now enabled for all customers. PHP reachability analysis is also generally available, helping teams determine which vulnerabilities in their dependencies can be reached from their application code. We introduced PHP and Composer support earlier this year with package search, dependency scanning, SBOM generation, CVE detection, and AI-powered analysis for Packagist packages. Moving to Beta makes that protection…

Socket
Socket Now Protects the Firefox Extension Ecosystem

Socket Now Protects the Firefox Extension Ecosystem

Today, Socket is expanding its browser extension security coverage to Firefox, giving security teams visibility into the extensions used across their organizations and helping them identify malicious behavior, excessive permissions, data collection, suspicious infrastructure, and risky changes between versions. Socket now proactively scans every Firefox extension listed in Mozilla's official addons.mozilla.org directory. At the time of publication, Mozilla's public API lists 97,100…

Socket
Popular Rust Crates Compromised in Build-Time Supply Chain Attack

Popular Rust Crates Compromised in Build-Time Supply Chain Attack

A threat actor compromised legitimate Rust crates and injected a malicious proc-macro1 dependency that executed cross-platform malware automatically during Cargo builds. Socket’s Threat Research Team analyzed a coordinated supply chain attack affecting three legitimate Rust crates maintained by David Roundy (droundy): arrayref@0.3.10 internment@0.8.7 append-only-vec@0.1.9 Socket’s AI Scanner independently detected the malicious proc-macro1 crate on August 20, 2026 at 07:29:50 UTC. At that point…

Socket