• Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly
Facebook Twitter Instagram
Wednesday, May 11
Facebook Twitter Instagram
The Zine Weekly
  • Zine

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022

    KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

    May 11, 2022

    FACTBOX-The cyber war between Ukraine and Russia

    May 11, 2022
  • Anonymous

    FACTBOX-The cyber war between Ukraine and Russia

    May 11, 2022

    CIA Expert Decodes Why Russia Which Even Hacked Into US Power Grids Is Failing In Cyber War In Ukraine

    May 10, 2022

    Anti-War Activists Stage ‘Guerrilla’ Protests on Victory Day

    May 9, 2022

    Deepfakes and espionage, but no cyber apocalypse from Vladimir Putin’s invasion

    May 9, 2022

    Who is Rebekah Vardy’s barrister Hugh Tomlinson in libel case against Coleen Rooney?

    May 8, 2022
  • Green

    Microgrid demo to lend a helping hand in India’s green energy transition

    May 9, 2022

    California prepares for energy shortfalls in hot, dry summer

    May 7, 2022

    Cryptocurrency’s dirty secret: Energy consumption

    May 5, 2022

    Stellantis pours billions more into Canada, electric

    May 3, 2022

    PortMiami, cruise lines pledge to expand technology to cut emissions from ships

    May 1, 2022
  • IT

    WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

    May 11, 2022

    How will VR collaboration transform meetings?

    May 10, 2022

    New Windows 11 preview makes Microsoft accounts mandatory for (almost) all

    May 9, 2022

    Announcing Reliable VPS Server Hosting Provider with Malaysia, Kuala Lumpur, Teluk Intan based IP – TheServerHost

    May 9, 2022

    Cal Poly Pomona pursues digital student experience

    May 8, 2022
  • Gadgets

    KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

    May 11, 2022

    New tool shows homeowners and renters the true cost of disasters

    May 10, 2022

    iPhone 12, iPhone 12 Mini on Sale With Up to Rs. 11,910 Discount via Amazon India, Flipkart

    May 9, 2022

    Portable fluorescent probe identifies bad cooking oil

    May 9, 2022

    Farhan Akhtar to Appear in Ms Marvel Series, Out June 8 on Disney+ Hotstar

    May 8, 2022
  • Tech

    4D composite printing could improve the wings of drones

    May 11, 2022

    How to delete unused styles using VBA in Word

    May 9, 2022

    Best Gas Credit Cards in May 2022

    May 6, 2022

    Eshoo faces rivals from left, right and center in bid to retain Congress seat | News

    May 4, 2022

    Netflix cancels Meghan Markle animated series Pearl

    May 2, 2022
  • Cloud

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ministry working to mitigate Merauke-Timika sea cable disruption

    May 10, 2022

    Cisco releases its Cloud Controls Framework to the public

    May 10, 2022

    Data Governance Market Collaborations Provide Effective And Impactful Solutions – IT Industry Today

    May 9, 2022

    Dell Technologies expands multi-cloud experiences

    May 8, 2022
  • Data

    Asia-Africa-Europe-1 submarine cable system to add Infinera’s ICE6

    May 10, 2022

    Russia’s invasion of Ukraine could hurt Europe IT outsourcing

    May 10, 2022

    Insider Tips for Automating Analytics

    May 9, 2022

    CSPi to Announce Fiscal Second Quarter Financial Results on

    May 8, 2022

    AAON (NASDAQ:AAON) Posts Quarterly Earnings Results, Beats Estimates By $0.06 EPS

    May 8, 2022
  • Network

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Keto Start ACV Gummies -WARNING: Shocking Reported About Side Effects? Job – 101 ARW ANG

    May 10, 2022

    Visualization analysis of sEMG | JPR

    May 10, 2022

    Beware: This cheap and ‘homemade’ malware is surprisingly effective

    May 9, 2022

    How to set a default gateway with Netplan, now that gateway4 has been deprecated

    May 8, 2022
  • Security

    Alberta Court of Appeal to rule whether federal assessment law is unconstitutional

    May 10, 2022

    Manchin says he’d pass parts of Biden’s agenda. But Democrats may have to write the bill for him.

    May 8, 2022

    Work from home hack to make your cat think it can distract you, is a must-watch | Trending

    May 8, 2022

    Accolades for local cyber team

    May 7, 2022

    India, Italy Express Concern On Ongoing Humanitarian Crisis In Ukraine

    May 6, 2022
  • Hosting
    1. Sunset Host Co
    2. Radio Host Co
    Featured

    Ransomware attack prompts response from Oregon election officials

    By Sunset Host CoMay 11, 20220
    Recent

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022

    Announcing Reliable VPS Server Hosting Provider with Netherlands, NL, Amsterdam based IP – TheServerHost – IT Industry Today

    May 10, 2022

    Asure Announces First Quarter 2022 Financial Results

    May 10, 2022
  • Media
    1. WSCA News
    2. Sunset Crypto
    3. Sustainable Action Now
    4. Life.Style Magazine
    5. Sunset Daily
    6. Sunset Music News
    7. Pro Merch Sports News
    8. Explore New Jersey
    9. Explore NJ News
    10. The Zine Weekly
    Featured
    Recent

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022
The Zine Weekly
You are at:Home » Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch
Network

Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

Sunset Host CoBy Sunset Host CoMay 11, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Securing the software supply chain is admittedly somewhat of a dry topic, but knowing what components and code go into your everyday devices and appliances is a critical part of the software development process that billions of people rely on every day.

Software is just like any other product you build and ship; it relies on using components that others have built, often in the form of source code, and making sure that it doesn’t break or have weaknesses that compromise the final product. Most of the world’s software relies on open-source code that’s written by developers who publish their work for anyone to use. That also means a reliance on trusting that the developers will always act in good faith. But projects get abandoned and picked up by others who plant backdoors or malware, or as seen recently since Russia’s invasion of Ukraine, a rise in “protestware,” in which open source software developers alter their code to wipe the contents of Russian computers in protest at the Kremlin’s incursion.

Feross Aboukhadijeh, a prolific open source maintainer and the founder of Socket, told TechCrunch in a recent call that development teams often put too much trust in open source code, which can be catastrophic if a deliberate vulnerability is introduced into the supply chain and goes unnoticed.

Software is generally easier to fix than autonomous cars and other hardware that have to be recalled. But the consequences of a software compromise can be dire and widespread. Tainted software updates have led to the mass compromise of U.S. federal government networks, ransomware attacks, and the targeting of enterprise password managers aimed at stealing sensitive corporate secrets.

Aboukhadijeh founded Socket earlier this year alongside a team of fellow open-source maintainers who have seen firsthand some of the worst software supply chain attacks in the wild. And so the team began work on building an app that developers can use to detect and block introducing potentially malicious code into their projects from millions of open source code repositories

The app plugs in to a GitHub developer’s account and runs through dozens of known behaviors, looking for package issues like potentially suspicious changes to the code, such as if an open source package you depend on suddenly starts trying to communicate over the network or getting shell access, which might indicate that the package has been compromised.

Aboukhadijeh described Socket as offering a nutrition-fact label of an open source package’s capabilities by illuminating what access, permissions and behaviors a package has, like install scripts, which many kinds of malware use to hook into a victim’s system.

“We can’t tell you with certainty whether a package is talking to the network is a bad sign or not, because what if it’s a web server — then it’s obviously going to need to do that!” said Aboukhadijeh. But having that visibility integrated into the software building process is what developers need to prevent a supply chain attack. “This isn’t some complicated AI or machine learning thing,” he said, speaking of his own product. “There’s no way to hide that a package runs an install script, it’s declared as part of the package. So why not raise that to a developer’s attention?”

Socket is still in its early days and enters a crowded market, but is already attracting investment. The early stage startup has raised $4.6 million in seed round funding from over a dozen angel investors and security leaders, including ex-GitHub CEO Nat Friedman, Keybase co-founder Max Krohn, as well as Unusual Ventures, Village Global, and South Park Commons.

Aboukhadijeh told TechCrunch that the funding will help grow the startup’s engineering, security analysis and research teams to build out its tools to developers.

Read more:

Share this:

  • Twitter
  • Facebook

Related

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAlkira launches free tool to tame cloud bloat
Sunset Host Co
  • Website
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • Tumblr
  • LinkedIn

Related Posts

Keto Start ACV Gummies -WARNING: Shocking Reported About Side Effects? Job – 101 ARW ANG

May 10, 2022

Visualization analysis of sEMG | JPR

May 10, 2022

Beware: This cheap and ‘homemade’ malware is surprisingly effective

May 9, 2022

Comments are closed.

Categories
  • Anonymous (91)
  • Cloud (145)
  • Data Center (128)
  • Gadgets (166)
  • Green Tech (36)
  • Hosting solutions (89)
  • IT News (90)
  • Network (135)
  • Security (127)
  • Tech (95)
  • Web hosting (58)
  • Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly

Subscribe to Updates

Get the latest tech news from the Zine at the Sunset Host Co. and the Radio Host Co.

Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

May 11, 2022

Alkira launches free tool to tame cloud bloat

May 11, 2022

Ransomware attack prompts response from Oregon election officials

May 11, 2022

KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

May 11, 2022

FACTBOX-The cyber war between Ukraine and Russia

May 11, 2022

WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

May 11, 2022

4D composite printing could improve the wings of drones

May 11, 2022

Keto Start ACV Gummies -WARNING: Shocking Reported About Side Effects? Job – 101 ARW ANG

May 10, 2022
Copyright © 2022. The Zine Weekly, an SCA Entertainment & Media Company. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.