Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
feross
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
feross
12d ago
Thanks for pointing this out. Socket is building our own vulnerability database to reduce dependence on the increasingly unreliable GHSA database.
2.
▲
Malicious Chrome VPN Extensions Discovered That Do Traffic Redirection
(socket.dev)
2 points
by
feross
1mo ago
|
0 comments
3.
▲
by
feross
2mo ago
Founder/CEO of Socket here. If you have a suggestion for how to scope down the permissions of our app, we’re all ears. But based on our research, it’s not possible. More info documenting each permission: https://docs.socket.
4.
▲
PyPI Fixes High-Severity Access Control Issues Found in Security Audit
(socket.dev)
1 points
by
feross
5mo ago
|
0 comments
5.
▲
by
feross
5mo ago
Thanks for the mention!
6.
▲
Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise
(socket.dev)
5 points
by
feross
6mo ago
|
0 comments
7.
▲
The Hidden Blast Radius of the Axios Compromise
(socket.dev)
6 points
by
feross
6mo ago
|
0 comments
8.
▲
Trivy Supply Chain Attack Expands to Compromised Docker Images
(socket.dev)
5 points
by
feross
6mo ago
|
3 comments
9.
▲
by
feross
6mo ago
Lots more technical research about the actual attack and how it worked here: https://socket.dev/blog/trivy-under-attack-again-github-acti... Disclosure: I’m the founder of Socket.
10.
▲
Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer
(socket.dev)
2 points
by
feross
7mo ago
|
0 comments
11.
▲
Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor
(socket.dev)
3 points
by
feross
7mo ago
|
0 comments
12.
▲
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains
(socket.dev)
8 points
by
feross
7mo ago
|
0 comments
13.
▲
First Brands Did Some Round Trips
(bloomberg.com)
1 points
by
feross
8mo ago
|
0 comments
14.
▲
15 Years of Blogging
(nolanlawson.com)
2 points
by
feross
8mo ago
|
1 comments
15.
▲
When will CSS Grid Lanes arrive?
(webkit.org)
50 points
by
feross
8mo ago
|
27 comments
16.
▲
2026.05: The Chip Fly in the AI Ointment
(stratechery.com)
1 points
by
feross
8mo ago
|
0 comments
17.
▲
Put a Pin in It
(signal.org)
1 points
by
feross
8mo ago
|
0 comments
18.
▲
Building a browser API in one shot
(nolanlawson.com)
3 points
by
feross
8mo ago
|
0 comments
19.
▲
Kimwolf Botnet Lurking in Corporate, Govt. Networks
(krebsonsecurity.com)
19 points
by
feross
8mo ago
|
0 comments
20.
▲
Michael Ovitz: The Business of Relationships
(fs.blog)
1 points
by
feross
8mo ago
|
0 comments
21.
▲
Best of Moltbook
(astralcodexten.com)
92 points
by
feross
8mo ago
|
37 comments
22.
▲
GlassWorm Loader Hits Open VSX via Developer Account Compromise
(socket.dev)
3 points
by
feross
8mo ago
|
0 comments
23.
▲
Ads in ChatGPT, Why OpenAI Needs Ads, the Long Road to Instagram
(stratechery.com)
1 points
by
feross
8mo ago
|
0 comments
24.
▲
Turbopack: Building faster by building less
(nextjs.org)
47 points
by
feross
8mo ago
|
23 comments
25.
▲
2026.03: Technology Doings
(stratechery.com)
1 points
by
feross
8mo ago
|
0 comments
26.
▲
Temporal API Ships in Chrome 144, Marking a Major Shift for JavaScript Date
(socket.dev)
3 points
by
feross
8mo ago
|
1 comments
27.
▲
Stablecoin Narrow Banking
(bloomberg.com)
1 points
by
feross
8mo ago
|
0 comments
28.
▲
An Interview with United CEO Scott Kirby About Tech Transformation
(stratechery.com)
1 points
by
feross
8mo ago
|
1 comments
29.
▲
New Safari developer tools provide insight into CSS Grid Lanes
(webkit.org)
123 points
by
feross
8mo ago
|
74 comments
30.
▲
Meta Compute, the Meta-OpenAI Battle, the Reality Labs Sacrifice
(stratechery.com)
2 points
by
feross
8mo ago
|
0 comments
More ›