Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain (socket.dev)
3 points by tosh 2 minutes ago | past | discuss
Malicious Checkmarx Artifacts Found in Official KICS Docker Repo and Code Ext (socket.dev)
3 points by orkj 8 hours ago | past | discuss
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository (socket.dev)
3 points by justsomehuman 20 hours ago | past | discuss
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via C2 (socket.dev)
6 points by jbegley 9 days ago | past | discuss
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline (socket.dev)
3 points by salkahfi 12 days ago | past | 1 comment
North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems (socket.dev)
2 points by pier25 15 days ago | past
Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering (socket.dev)
3 points by pier25 19 days ago | past | 2 comments
Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise (socket.dev)
5 points by feross 20 days ago | past
The Hidden Blast Radius of the Axios Compromise (socket.dev)
6 points by feross 21 days ago | past
Supply Chain Attack on Axios Pulls Malicious Dependency from NPM (socket.dev)
2 points by dsr12 23 days ago | past
TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem (socket.dev)
5 points by pier25 29 days ago | past
Trivy Supply Chain Attack Expands to Compromised Docker Images (socket.dev)
5 points by feross 31 days ago | past | 3 comments
Trivy under attack again: Widespread GitHub Actions tag compromise secrets (socket.dev)
250 points by jicea 32 days ago | past | 83 comments
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes (socket.dev)
3 points by tamnd 33 days ago | past | 1 comment
CanisterWorm: NPM Publisher Compromise Deploys Backdoor Across 29 Packages (socket.dev)
3 points by pier25 33 days ago | past
Widespread Trivvy GitHub Actions Tag Compromise Exposes CI/CD Secrets (socket.dev)
7 points by donutshop 34 days ago | past | 1 comment
Enisa Technical Advisory on Secure Use of Package Managers (socket.dev)
6 points by pier25 34 days ago | past
Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer (socket.dev)
2 points by feross 54 days ago | past
Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor (socket.dev)
3 points by feross 55 days ago | past
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains (socket.dev)
10 points by jicea 60 days ago | past
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains (socket.dev)
8 points by feross 61 days ago | past
Socket brings supply chain security to skills.sh (socket.dev)
2 points by ryoidong 63 days ago | past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach (socket.dev)
3 points by puppion 64 days ago | past
AI Agent Lands PRs in Major OSS Projects (socket.dev)
1 point by bradyholt 65 days ago | past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach (socket.dev)
2 points by choult 67 days ago | past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach (socket.dev)
16 points by cdrnsf 67 days ago | past | 1 comment
AI Agent Lands PRs in Major OSS Projects (socket.dev)
2 points by junon 68 days ago | past
Lodash's Security Reset and Maintenance Reboot (socket.dev)
5 points by todsacerdoti 80 days ago | past
GlassWorm Loader Hits Open VSX via Developer Account Compromise (socket.dev)
3 points by feross 81 days ago | past
Temporal API Ships in Chrome 144, Marking a Shift for JavaScript Date Handling (socket.dev)
1 point by thunderbong 3 months ago | past

Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: