Heykuki News

TopNewBestAskShowJobs
TopNewBestAskShowJobs
211.
NPM Phishing Email Targets Developers with Typosquatted Domain (socket.dev)
3 points
feross
a year ago
discuss
212.
Open Source Maintainers Feeling the Weight of the EU's Cyber Resilience Act (socket.dev)
3 points
feross
a year ago
discuss
213.
Crates.io Implements Trusted Publishing Support (socket.dev)
3 points
feross
a year ago
discuss
214.
Socket at Black Hat and DEF Con 2025 in Las Vegas (socket.dev)
3 points
feross
a year ago
discuss
215.
Browserslist-Rs Gets Major Refactor, Cutting Binary Size by over 1MB (socket.dev)
3 points
feross
a year ago
discuss
216.
Malicious Python Package Typosquats Popular Passlib Library, Shuts Down Windows (socket.dev)
3 points
feross
a year ago
discuss
217.
Pnpm 10.12 Introduces Global Virtual Store and Expanded Version Catalogs (socket.dev)
3 points
feross
a year ago
discuss
218.
Malicious Ruby Gems Exfiltrate Telegram Tokens, Messages Following Vietnam Ban (socket.dev)
3 points
campuscodi
a year ago
discuss
219.
Malicious NPM Package Wipes Codebases with Remote Trigger (socket.dev)
3 points
feross
a year ago
discuss
220.
Malicious NPM Packages (socket.dev)
3 points
Tomte
a year ago
discuss
221.
Malicious NPM Packages Use Telegram to Exfiltrate BullX Credentials (socket.dev)
3 points
feross
a year ago
discuss
222.
Wget to Wipeout: Malicious Go Modules Fetch Destructive Payload (socket.dev)
3 points
6581
a year ago
discuss
223.
A New Overview in Our Dashboard (socket.dev)
3 points
feross
a year ago
discuss
224.
Module Reachability: Focus on the Vulnerabilities That Matter (socket.dev)
3 points
feross
a year ago
discuss
225.
The Bad Seeds: Malicious NPM and PyPI Packages Pose as Developer Tools to Steal (socket.dev)
3 points
feross
a year ago
discuss
226.
Malicious NPM Package Disguised as Advcash Integration Triggers Reverse Shell (socket.dev)
3 points
feross
a year ago
discuss
227.
Malicious PyPI Package Targets WooCommerce Stores with Automated Carding Attacks (socket.dev)
3 points
feross
a year ago
discuss
228.
OpenGrep Restores Fingerprinting in JSON and Sarif Outputs (socket.dev)
3 points
feross
a year ago
discuss
229.
NVD Concedes Inability to Keep Pace with Surging CVE Disclosures in 2025 (socket.dev)
3 points
feross
a year ago
discuss
230.
GitHub Actions Supply Chain Attack Puts Projects at Risk (socket.dev)
3 points
feross
a year ago
discuss
231.
Tick Tock, Your Credentials Are Gone: The Maven Package with a Monthly Theft (socket.dev)
3 points
feross
a year ago
discuss
232.
The Pair Program Podcast: Feross Aboukhadijeh on Preserving Trust in Open Source (socket.dev)
3 points
feross
a year ago
discuss
233.
Malicious Go Package Exploits Go Module Proxy Caching for Persistence (socket.dev)
3 points
feross
a year ago
discuss
234.
OpenSSF Launches Open Source Project Security Baseline to Strengthen Software (socket.dev)
3 points
feross
a year ago
discuss
235.
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy (socket.dev)
3 points
feross
a year ago
discuss
236.
Create React App Officially Deprecated Amid React 19 Compatibility Issues (socket.dev)
3 points
feross
a year ago
discuss
237.
Maven Central Adds Sigstore Signature Validation (socket.dev)
3 points
feross
a year ago
discuss
238.
PyPI's New Archival Feature Closes a Major Security Gap (socket.dev)
3 points
feross
a year ago
discuss
239.
Node.js EOL Versions CVE Dubbed the Worst CVE of the Year by Security Experts (socket.dev)
3 points
feross
a year ago
discuss
240.
Malicious PyPI Package 'Pycord-Self' Targets Discord Developers with Token Theft (socket.dev)
3 points
feross
a year ago
discuss
More