GeneralTwo npm Packages Hijacked to Deploy Blockchain C2
On December 17, 2024, Socket identified two compromised packages in the @joyfill namespace: @joyfill/ [email protected] and @joyfill/ [email protected] . These versions deliver
Expert perspectives on application security, compliance, and emerging threats
GeneralOn December 17, 2024, Socket identified two compromised packages in the @joyfill namespace: @joyfill/ [email protected] and @joyfill/ [email protected] . These versions deliver
GeneralWhen OpenAI s AI agent escaped its sandbox environment, the security community s reaction split into two camps. One group saw it as proof that AI demands entirely new security paradigms. The other rec
GeneralThe conventional wisdom Security teams often treat AI agent vulnerabilities like application bugs. A researcher finds a prompt injection that leaks secrets, the vendor patches the specific exploit, yo
GeneralYou ve probably heard about dependency firewalls in the context of supply chain security, but you might have dismissed them as unnecessary. That skepticism made sense two years ago. Today, with AI cod
Get weekly security insights and compliance updates delivered to your inbox.
GeneralScope - What This Guide Covers This guide shows you how to embed security decision-making and remediation directly into your pull request (PR) workflow. You ll learn which security controls belong in
GeneralYou ve secured your APIs. Your authentication is solid. Your least-privilege model works. Then you deploy an AI agent that can execute arbitrary code based on user prompts, and suddenly none of that m
GeneralThe Conventional Wisdom Security vendors and analysts often recommend a unified platform. Application Security Posture Management (ASPM) promises to solve alert fatigue by consolidating your SAST, DAS
GeneralThe Cloud Native Computing Foundation launched its Kubernetes AI conformance program in November 2025, and the timing is more significant than you might think. By the end of 2026, two-thirds of comput
GeneralThe open-source community is sounding the alarm for enterprise teams. Jazzband, which manages numerous Python projects, shut down because maintainers couldn t handle AI-generated spam PRs. The Godot g
GeneralAccording to a 2024 Salesforce survey, 55% of employees reported using AI tools that hadn t been approved by their organization. This isn t just a governance gap; it s a security incident waiting to h
GeneralYou ve probably heard the pitch: AI will find vulnerabilities faster than humans can exploit them, automatically generate patches, and deploy fixes before attackers even know what hit them. It s a com
GeneralAutomated dependency updates are often seen as risky, and GitHub s new three-day cooldown period in Dependabot suggests we need to slow down. The idea is to wait before adopting new package versions,
GeneralScope This guide focuses on AI-powered penetration testing systems that use large language models (LLMs) to analyze application behavior and identify context-dependent vulnerabilities. You ll discover
GeneralYour compliance team just approved AI agents for customer support. Two weeks later, one starts hallucinating PII into responses. You need to shut it down without breaking the other twelve agents handl
GeneralYour compliance team might think AI observability is just another term for monitoring. That s not quite right, and this misconception can lead to audit risks. These myths persist because AI workloads
GeneralAI-generated code is often seen as less reliable than human-written code, leading security teams to add extra review processes and treat AI-generated pull requests with suspicion. This approach misses