🔥 Python's uv has inspired rv for #Ruby: installs precompiled Ruby 3.4.x in ~0.22s and combines version + dependency management in a single Rust-powered tool.
socket.dev/blog/rv-is-a-n…@shortrubynews
🚨 Socket’s Threat Research Team found a malicious npm package impersonating Nodemailer. It modifies Windows #crypto wallets to redirect transactions to attacker-controlled addresses.
socket.dev/blog/wallet-dr…#nodejs#javascript
The Nx team’s investigation into last week’s supply chain attack found the compromise came from a GitHub Actions workflow injection on an outdated branch, exposing the npm token & enabling malicious publishes. All Nx packages now use Trusted Publishing.
socket.dev/blog/nx-supply…
🤖 Developers are rallying around AGENTS.md, a fast-emerging standard for giving instructions to AI coding agents. Already adopted in 20k+ repos and now supported by GitHub Copilot.
Read more: socket.dev/blog/agents-md…
Reminder if you might have been affected, rotate all tokens IMMEDIATELY, especially the GitHub CLI Authorized OAuth, which isn't as straightforward. Our team is here to help via the community discord or [email protected].
Reminder if you might have been affected, rotate all tokens IMMEDIATELY, especially the GitHub CLI Authorized OAuth, which isn't as straightforward. Our team is here to help via the community discord or [email protected].
Scanners overwhelm teams with CVE alerts but most aren’t exploitable. On the @riskybusiness podcast, @feross explains how reachability analysis cuts 90% of the noise. This episode is a deep dive into one of the hardest problems in vulnerability management. socket.dev/blog/risky-biz…
🚨 If you think you might be effected by the nx compromise please revoke the GitHub CLI Authorized OAuth App: github.com/settings/conne…
Notably, this is the only way to revoke/rotate the tokens made by/known to that app. The next time you `gh login` you can reauth.
Attackers are now experimenting with weaponizing AI developer tools to accelerate reconnaissance and data theft. By expressing goals in prompts, they skip writing custom code and tap into cross-platform expertise instantly, cutting development time for supply chain attacks.
Attackers are now experimenting with weaponizing AI developer tools to accelerate reconnaissance and data theft. By expressing goals in prompts, they skip writing custom code and tap into cross-platform expertise instantly, cutting development time for supply chain attacks.
📢 CISA’s 2025 SBOM guidance moves beyond simple software inventories, adding hashes, licenses, tool metadata & context to make SBOMs operationally actionable. Public comment is open until Oct 3.
Read more: socket.dev/blog/cisa-2025…@CISAgov@CISACyber
⚠️ A “hacking tool” on Go isn’t what it seems.
The package pretends to brute-force SSH—but secretly sends stolen logins to a Telegram bot controlled by a Russian actor.
The package is still on pkg.go.dev.
Full report → thehackernews.com/2025/08/malici…
ESLint is about to ship parallel linting, closing a 10-year-old feature request. 🚀
Benchmarks show 30–60% faster runs, with some projects seeing 3x+ improvements.
Our write-up on the shifting linter landscape: socket.dev/blog/eslint-ad…@geteslint
🚨 A malicious Go module, disguised as an SSH brute-forcing tool, is sending stolen SSH logins to a hardcoded Telegram bot that is still active.
Full analysis: socket.dev/blog/malicious…#GoLang
473 Followers 4K FollowingA Creative Engineer (for @Gillette, @GSK, @Vodacom, and more) who also builds free security tools for the whole world to use: meet @DataLeakDan...
92 Followers 265 Following"Focus on your game first."
Don't ever be intimidated by other dudes who have more MONEY than you.
Lots of people have money,
But dudes having GOOD GAME is rare
76 Followers 309 FollowingI am die hard 💔 fan Rebel star ♥️ prabhas...Stars Stars Stars I Don't like star But Stars Like darling Prabahs I am Not aboved it So I like it & #Prabhas🤴
379 Followers 1K FollowingFormer NCAA Baseball - currently Director of DevOps - New Jersey, right by the beach , Co-founder of https://t.co/Dy52RajKgz Rocket League
874K Followers 52 Followingwe invest in software eating the world
https://t.co/A9eTFq6plZ
https://t.co/MXGUBJoesw
Watch "The Ben & Marc Show": https://t.co/eRuDhx7kpe
46K Followers 90 FollowingThe AI development platform - From idea to AI, Lightning fast ⚡️. Creators of AI Studio, PyTorch Lightning... Get help: https://t.co/a69wnEARV9
567K Followers 1K FollowingWelcome to the new way to cloud.
Questions? ➡️ https://t.co/BFKBu3t6xk
For do-ers & makers ➡️ @GoogleCloudTech
Watch #GoogleCloudNext on demand ⬇️
242K Followers 869 FollowingThe only magazine dedicated to the strategy and technology of information security, delivering critical business and technical information for IT professionals.
342K Followers 48 FollowingOne of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
396K Followers 50 FollowingTypeScript is a language for application-scale JavaScript development. It's a typed superset of JavaScript that compiles to plain JavaScript.
2K Followers 1K FollowingSenior Security Research Engineer, Threat Research and Detection Development @Elastic, 179CPT Cyber Operations Technician 170A @MOARNG
8K Followers 0 FollowingHigh-performance developer tools for the Python ecosystem, starting with Ruff, an extremely fast Python linter, written in Rust.
6K Followers 420 Followingzh/en / https://t.co/kruSrNDMxo / https://t.co/l3iv4nHg3A / Senior FE dev / Cloud Native / Contributing to OSS and creating PRs for fun / All opinions are my own, literally all of them.
3K Followers 203 FollowingSecurity Engineer at big tech | Part Time Security Researcher | Build Pipeline Menace | All thoughts and opinions are my own.
284K Followers 71 FollowingPart of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
2K Followers 1 FollowingThe best way to stay on top of the cloud security landscape without having to be overwhelmed by all the noise | Curated by @lancinimarco
No recent Favorites. New Favorites will appear here.