Podcast appearances and mentions of feross aboukhadijeh

  • 38PODCASTS
  • 102EPISODES
  • 51mAVG DURATION
  • ?INFREQUENT EPISODES
  • Feb 22, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about feross aboukhadijeh

Latest podcast episodes about feross aboukhadijeh

Risky Business News
Sponsored: The smouldering trashfire of AI and open source

Risky Business News

Play Episode Listen Later Feb 22, 2026 24:59


In this Risky Business sponsor interview, Casey Ellis and Feross Aboukhadijeh discuss how AI is affecting open source, chat about a few attacks the company has seen in the wild and introduce Socket's answer to the smouldering trashfire: Socket Firewall. Show notes

ai open source risky business socket trash fire casey ellis feross aboukhadijeh
Software Engineering Daily
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

Software Engineering Daily

Play Episode Listen Later Dec 9, 2025 47:48


Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.

JavaScript – Software Engineering Daily
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

JavaScript – Software Engineering Daily

Play Episode Listen Later Dec 9, 2025 47:48


Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security platform designed to protect software projects from open source supply chain attacks. In this episode he joins Josh Goldberg to talk about his career in open source, open source supply chain attacks, practical security lessons, the expanding attack surface in software development, and more. Josh Goldberg is an independent full time open source developer in the TypeScript ecosystem. He works on projects that help developers write better TypeScript more easily, most notably on typescript-eslint: the tooling that enables ESLint and Prettier to run on TypeScript code. Josh regularly contributes to open source projects in the ecosystem such as ESLint and TypeScript. Josh is a Microsoft MVP for developer technologies and the author of the acclaimed Learning TypeScript (O'Reilly), a cherished resource for any developer seeking to learn TypeScript without any prior experience outside of JavaScript. Josh regularly presents talks and workshops at bootcamps, conferences, and meetups to share knowledge on TypeScript, static analysis, open source, and general frontend and web development. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.

Open Source – Software Engineering Daily
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

Open Source – Software Engineering Daily

Play Episode Listen Later Dec 9, 2025 47:48


Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security platform designed to protect software projects from open source supply chain attacks. In this episode he joins Josh Goldberg to talk about his career in open source, open source supply chain attacks, practical security lessons, the expanding attack surface in software development, and more. Josh Goldberg is an independent full time open source developer in the TypeScript ecosystem. He works on projects that help developers write better TypeScript more easily, most notably on typescript-eslint: the tooling that enables ESLint and Prettier to run on TypeScript code. Josh regularly contributes to open source projects in the ecosystem such as ESLint and TypeScript. Josh is a Microsoft MVP for developer technologies and the author of the acclaimed Learning TypeScript (O'Reilly), a cherished resource for any developer seeking to learn TypeScript without any prior experience outside of JavaScript. Josh regularly presents talks and workshops at bootcamps, conferences, and meetups to share knowledge on TypeScript, static analysis, open source, and general frontend and web development. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.

Cloud Engineering – Software Engineering Daily
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

Cloud Engineering – Software Engineering Daily

Play Episode Listen Later Dec 9, 2025 47:48


Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security platform designed to protect software projects from open source supply chain attacks. In this episode he joins Josh Goldberg to talk about his career in open source, open source supply chain attacks, practical security lessons, the expanding attack surface in software development, and more. Josh Goldberg is an independent full time open source developer in the TypeScript ecosystem. He works on projects that help developers write better TypeScript more easily, most notably on typescript-eslint: the tooling that enables ESLint and Prettier to run on TypeScript code. Josh regularly contributes to open source projects in the ecosystem such as ESLint and TypeScript. Josh is a Microsoft MVP for developer technologies and the author of the acclaimed Learning TypeScript (O'Reilly), a cherished resource for any developer seeking to learn TypeScript without any prior experience outside of JavaScript. Josh regularly presents talks and workshops at bootcamps, conferences, and meetups to share knowledge on TypeScript, static analysis, open source, and general frontend and web development. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.

Podcast – Software Engineering Daily
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

Podcast – Software Engineering Daily

Play Episode Listen Later Dec 9, 2025 47:48


Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.

All JavaScript Podcasts by Devchat.tv
Guarding the JavaScript Supply Chain: Preventing NPM Attacks with Feross Aboukhadijeh - JSJ 695

All JavaScript Podcasts by Devchat.tv

Play Episode Listen Later Nov 1, 2025 60:01 Transcription Available


Hey everyone—it's Steve Edwards here, and in this episode of JavaScript Jabber, I'm joined by returning guest Feross Aboukhadijeh, founder of Socket.dev, for a deep dive into the dark and fascinating world of open source supply chain security. From phishing campaigns targeting top NPM maintainers to the now-infamous Chalk library compromise, we unpack the latest wave of JavaScript package attacks and what developers can learn from them.Feross explains how some hackers are even using AI tools like Claude and Gemini as part of their payloads—and how defenders like Socket are fighting back with AI-powered analysis of their own. We also dive into GitHub Actions vulnerabilities, the role of two-factor authentication, and the growing need for “phishing-resistant 2FA.” Whether you're an open source maintainer or just someone who runs npm install a little too often, this episode will open your eyes to how much happens behind the scenes to keep your code safe.

The Changelog
npm under siege (what to do about it) (Friends)

The Changelog

Play Episode Listen Later Oct 3, 2025 95:20


Over the past two months, we've seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.

friends siege adam stacoviak feross aboukhadijeh jerod santo
Changelog Master Feed
npm under siege (what to do about it) (Changelog & Friends #111)

Changelog Master Feed

Play Episode Listen Later Oct 3, 2025 95:20 Transcription Available


Over the past two months, we've seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.

friends siege changelog adam stacoviak feross aboukhadijeh jerod santo
PodRocket - A web development podcast from LogRocket
Unpacking the NPM supply chain attacks with Feross Aboukhadijeh

PodRocket - A web development podcast from LogRocket

Play Episode Listen Later Sep 23, 2025 40:09


Feross Aboukhadijeh, founder of Socket, joins us to break down the recent wave of NPM supply chain attacks hitting the JavaScript ecosystem, including how attackers used phishing to target developers, snuck malware into popular packages like Prettier and "is", and even abused tools like Claude, Gemini, and TruffleHog. We dig into how GitHub Actions vulnerabilities were exploited, what makes postinstall scripts risky, and and what you can do to protect yourself from future attacks. Links Website: https://feross.org X: https://x.com/feross GitHub: https://github.com/feross LinkedIn: https://www.linkedin.com/in/feross YouTube: https://www.youtube.com/channel/UCHM4OEvQDUq8UszyUrdov-w Resources npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack: https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack Compromised files replace npm packages with a combined 2 billion weekly downloads: https://www.techradar.com/pro/security/compromised-files-replace-npm-packages-with-a-combined-2-billion-weekly-downloads Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware: https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack Chapters 00:00 Intro: NPM supply chain attacks explained 01:10 What is a software supply chain attack? 02:00 NPM phishing campaign: Fake login pages 03:00 Prettier ecosystem compromised 04:00 The “is” package malware incident 05:30 NX package breach (August 27 attack) 06:40 AI-powered supply chain exploit 08:00 GitHub Actions misconfiguration 12:00 Lessons from recent NPM attacks 20:00 How malicious packages get published 25:00 Why install scripts are so risky 30:00 Limitations of banning install scripts 35:00 Open source maintainer challenges 40:00 Smarter approaches to dependency updates 44:00 The future of open source supply chain security 47:00 Closing thoughts and resources We want to hear from you! How did you find us? Did you see us on Twitter? In a newsletter? Or maybe we were recommended by a friend? Fill out our listener survey (https://t.co/oKVAEXipxu)! Let us know by sending an email to our producer, Em, at emily.kochanek@logrocket.com (mailto:emily.kochanek@logrocket.com), or tweet at us at PodRocketPod (https://twitter.com/PodRocketpod). Follow us. Get free stickers. Follow us on Apple Podcasts, fill out this form (https://podrocket.logrocket.com/get-podrocket-stickers), and we'll send you free PodRocket stickers! What does LogRocket do? LogRocket provides AI-first session replay and analytics that surfaces the UX and technical issues impacting user experiences. Start understanding where your users are struggling by trying it for free at LogRocket.com. Try LogRocket for free today. (https://logrocket.com/signup/?pdr) Special Guest: Feross Aboukhadijeh.

Risky Business
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal

Risky Business

Play Episode Listen Later Sep 10, 2025 51:42


On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Apple ruins exploit developers' week with fresh memory corruption mitigations Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack Salesloft says its GitHub was the initial entry point for its compromise Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day” Rogue certs for 1.1.1.1 appear to be just (stupid) testing Jaguar Land Rover ransomware attackers are courting trouble This week's episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint! This episode is also available on Youtube. Show notes Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research Venezuela's president thinks American spies can't hack Huawei phones | TechCrunch 18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security Software packages with more than 2 billion weekly downloads hit in supply-chain attack - Ars Technica Salesloft platform integration restored after probe reveals monthslong GitHub account compromise | Cybersecurity Dive CISA orders federal agencies to patch Sitecore zero-day following hacking reports | The Record from Recorded Future News SAP warns of high-severity vulnerabilities in multiple products - Ars Technica The number of mis-issued 1.1.1.1 certificates grows. Here's the latest. - Ars Technica Cyberattack on Jaguar Land Rover threatens to hit British economic growth | The Record from Recorded Future News Cyberattack forces Jaguar Land Rover to tell staff to stay at home | The Record from Recorded Future News Bridgestone Americas continues probe as it looks to restore operations | Cybersecurity Dive Qantas penalizes executives for July cyberattack | The Record from Recorded Future News Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat' | The Record from Recorded Future News GOP Cries Censorship Over Spam Filters That Work – Krebs on Security Risky Bulletin: APT report? No, just a phishing test! - Risky Business Media Post by @patrick.risky.biz — Bluesky

Risky Business
Risky Biz Soap Box: How to measure vulnerability reachability

Risky Business

Play Episode Listen Later Aug 14, 2025 35:48


In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. It's great to know there's a CVE in a library you're using, but it's even better if you can say whether or not that vulnerability actually impacts your application. They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days it's playing the CVE game as well. This episode is also available on Youtube. Show notes

The Tech Trek
The Security Gap No One's Talking About

The Tech Trek

Play Episode Listen Later Aug 5, 2025 28:26


Feross Aboukhadijeh, founder and CEO of Socket, joins The Tech Trek to pull back the curtain on software supply chain security, why legacy tools are failing, and what it really takes to build trust into modern development. Feross explains how Socket is tackling vulnerabilities most vendors can't even detect and shares why they made a rare early-stage acquisition—and how it's reshaping their roadmap.Whether you're an engineering leader, security pro, or founder eyeing M&A moves, this episode offers sharp insights into product strategy, AI implications, and the real work behind the scenes.Key Takeaways:Socket proactively secures the software supply chain by detecting malicious code injections and not just known vulnerabilitiesLegacy tools rely on outdated databases and can't keep up with real-time threats or malicious actorsThe explosion of AI-generated code is expanding the attack surface and introducing new vectors like “slop squatting”Socket's acquisition of Kawana was driven by tight product fit, culture alignment, and shared technical DNA—not just business rationaleReachability analysis reduced Socket's security alert noise by 80 percent, boosting signal and developer trustTimestamped Highlights:01:00 — What Socket actually does and why open source dependency risk is a blind spot for most companies06:40 — Why most tools in this space haven't solved the real security problem—and how Socket is different11:50 — AI's unexpected impact on software security and the rise of hallucinated packages16:30 — Behind Socket's acquisition of Kawana and how academic research drove product synergy22:58 — How integrating the acquisition is evolving Socket's roadmap and deepening its technical edge25:00 — What Feross learned from the legal side of M&A and how his past experience at Yahoo helped shape this oneQuote of the Episode:“We care way more about first-party code than third-party code, even though it all runs in one app. That has to change.”Resources Mentioned:Socket: https://socket.devCall to Action:Enjoyed the episode? Follow The Tech Trek to catch conversations with the builders shaping the future. And if you're deep in security or scaling a dev team, check out socket.dev or reach out to Feross directly—he's happy to share lessons learned.

ceo ai dna security yahoo socket feross aboukhadijeh feross tech trek
AI + a16z
How to Vibe Code Securely

AI + a16z

Play Episode Listen Later Jul 25, 2025 26:35


In this episode, a16z partner Joel de la Garza sits down with Socket founder and CEO Feross Aboukhadijeh to dive into the intersection of vibe coding and security. As one of the earliest security founders to fully embrace LLMs, Feross shares firsthand insights into how these technologies are transforming software engineering workflows and productivity — and where there are sharp edges that practitioners need to avoid.The TL;DR: Treat AI-assisted programming the same way you'd treat other programming, by vetting packages, reviewing code, and generally make sure you're not sacrificing security for speed. As he explained, LLMs can make developers more productive and even make their software more secure, but only if developers do their part by maintaining a safe supply chain.Follow everyone on social media: Feross AboukhadijehJoel de la Garza Check out everything a16z is doing with artificial intelligence here, including articles, projects, and more podcasts.

Risky Business News
Sponsored: Socket CEO Feross Aboukhadijeh on how tracking vulnerabilities isn't enough for open source repositories

Risky Business News

Play Episode Listen Later Jul 21, 2024 14:42


In this Risky Business News sponsored interview, Tom Uren talks to Feross Aboukhadijeh, CEO and Founder of Socket about how open source repositories are riddled with horrible software. Feross explains why it makes a difference if a package is vulnerable, malicious or just unwanted and how current transparency mechanisms such as CVEs and the NVD just aren't suitable for the challenge of open source repositories.

a16z
Cybersecurity's Past, Present, and AI-Driven Future

a16z

Play Episode Listen Later Jun 26, 2024 43:43


Is it time to hand over cybersecurity to machines amidst the exponential rise in cyber threats and breaches?We trace the evolution of cybersecurity from minimal measures in 1995 to today's overwhelmed DevSecOps. Travis McPeak, CEO and Co-founder of Resourcely, kicks off our discussion by discussing the historical shifts in the industry. Kevin Tian, CEO and Founder of Doppel, highlights the rise of AI-driven threats and deepfake campaigns. Feross Aboukhadijeh, CEO and Founder of Socket, provides insights into sophisticated attacks like the XZ Utils incident. Andrej Safundzic, CEO and Founder of Lumos, discusses the future of autonomous security systems and their impact on startups.Recorded at a16z's Campfire Sessions, these top security experts share the real challenges they face and emphasize the need for a new approach. Resources: Find Travis McPeak on Twitter: https://x.com/travismcpeakFind Kevin Tian on Twitter: https://twitter.com/kevintian00Find Feross Aboukhadijeh on Twitter: https://x.com/ferossFind Andrej Safundzic on Twitter: https://x.com/andrejsafundzic Stay Updated: Find a16z on Twitter: https://twitter.com/a16zFind a16z on LinkedIn: https://www.linkedin.com/company/a16zSubscribe on your favorite podcast app: https://a16z.simplecast.com/Follow our host: https://twitter.com/stephsmithioPlease note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. 

Legacy Code Rocks
Quality-Check of External Dependencies with Feross Aboukhadijeh

Legacy Code Rocks

Play Episode Listen Later Jun 5, 2024 45:41


Many of the largest companies rely on third-party code to run critical parts of their software. However, there's often little focus on ensuring the quality of these external dependencies. Today we speak with Feross Aboukhadijeh, CEO and founder of Socket, a developer-first security platform. Socket helps developers and security teams release software faster and reduce time spent on security busywork. Feross is also a lecturer at Stanford, where he teaches CS233 Web Security. We discuss why the quality of third-party dependencies matters, when to start addressing this issue, how to handle unmaintained dependencies, and what tools are available for managing third-party dependencies. After listening to the episode, be sure to visit the Socket website, connect with Feross on Twitter, and check out his personal website. Mentioned in this episode: Socket at https://socket.dev/  Feross on X at https://x.com/feross  Feross website at: https://feross.org/ 

ceo stanford external socket dependencies quality check feross aboukhadijeh feross
AI + a16z
Securing the Software Supply Chain with LLMs

AI + a16z

Play Episode Listen Later May 3, 2024 38:57


Socket Founder and CEO Feross Aboukhadijeh joins a16z's Joel de la Garza and Derrick Harris to discuss the open-source software supply chain. Feross and Joel share their thoughts and insights on topics ranging from the recent XZutils attack to how large language models can help overcome understaffed security teams and overwhelmed developers. Despite some increasingly sophisticated attacks making headlines and compromising countless systems, they're optimistic that LLMs, in particular, could be a turning point for security blue teams. As Feross sums up one possibility:"The way we think about gen AI on the defensive side is that it's not as good as a human looking at the code, but it's something. . . . Our challenge is that we want to scan all the open source code that exists out there. That is not something you can pay humans to do. That is not scalable at all. But, with the right techniques, with the right pre-filtering stages, you can actually put a lot of that stuff through LLMs and out the other side will pop a list of of risky packages."And then that's a much smaller number that you can have humans take a look at. And so we're using it as a tool . . . to find the needle in the haystack, what is worth looking at. It's not perfect, but it can help cut down on the noise and it can even make this problem tractable, which previously wasn't even tractable."More about Socket and  cybersecurity:SocketInvesting in SocketHiring a CISOFollow everyone :Feross AboukhadijehJoel de la GarzaDerrick Harris Check out everything a16z is doing with artificial intelligence here, including articles, projects, and more podcasts.

Risky Business News
Sponsored: Open source software's increasing vulnerability

Risky Business News

Play Episode Listen Later Apr 28, 2024 18:48


In this Risky Business News sponsored interview, Tom Uren talks to CEO and founder of Socket, Feross Aboukhadijeh about the open source software and supply chain security. Feross says the software ecosystem has evolved in ways that make it more vulnerable to trust-based attacks (such as seen in XZ Utils) and discusses what can be done to defend against this type of supply chain subversion.

Chinchilla Squeaks
Software supply chain security with Socket.dev

Chinchilla Squeaks

Play Episode Listen Later Apr 4, 2024 33:07


I speak with Feross Aboukhadijeh of Socket.dev about their smarter and more considered solution for securing software supply chains.

security supply chains socket software supply chain security feross aboukhadijeh sssc
Risky Business
Risky Business #736 -- Azure misconfigurations are 2024's looming threat

Risky Business

Play Episode Listen Later Feb 14, 2024 53:18


In this week's show Patrick Gray and Adam Boileau discuss the week's security news. They talk about: Somehow there are still more Ivanti and Fortinet exploits Volt Typhoon have been at it for years Starlink in Ukraine gets complicated Canadians hate poor Flipper Much, much more… In this week's sponsor interview Feross Aboukhadijeh from Socket joins the show to talk about the sheer volume of malicious packages being committed to code repositories and why older SCA tools aren't well equipped to deal with them. Show notes Microsoft Azure customers hit by phishing, account takeover attacks | Cybersecurity Dive Ivanti publishes urgent warning about new vulnerability How is Pulse Secure Formed Attackers hit more networking gear, this time a critical Fortinet CVE | Cybersecurity Dive End Of General Availability of the free vSphere Hypervisor (ESXi 7.x and 8.x) (2107518) Coker: ONCD is studying ‘liability regimes' for software flaws Chinese hackers spent 5 years in US infrastructure, ready to attack CISA, FBI warn of China-linked hackers pre-positioning for ‘destructive cyberattacks against US critical infrastructure' Russia using Starlink Canada declares Flipper Zero public enemy No. 1 in car-theft crackdown | Ars Technica Health insurance data breach affects nearly half of France's population, privacy regulator warns Hackers attack 25 Romanian hospitals Catalin on the Rhysider ransomware decrypter going public A password manager LastPass calls “fraudulent” booted from App Store | Ars Technica From Cybercrime Saul Goodman to the Russian GRU – Krebs on Security

Risky Business
Risky Business #736 -- Azure misconfigurations are 2024's looming threat

Risky Business

Play Episode Listen Later Feb 14, 2024


In this week's show Patrick Gray and Adam Boileau discuss the week's security news. They talk about: Somehow there are still more Ivanti and Fortinet exploits Volt Typhoon have been at it for years Starlink in Ukraine gets complicated Canadians hate poor Flipper Much, much more… In this week's sponsor interview Feross Aboukhadijeh from Socket joins the show to talk about the sheer volume of malicious packages being committed to code repositories and why older SCA tools aren't well equipped to deal with them. Show notes Microsoft Azure customers hit by phishing, account takeover attacks | Cybersecurity Dive Ivanti publishes urgent warning about new vulnerability How is Pulse Secure Formed Attackers hit more networking gear, this time a critical Fortinet CVE | Cybersecurity Dive End Of General Availability of the free vSphere Hypervisor (ESXi 7.x and 8.x) (2107518) Coker: ONCD is studying ‘liability regimes' for software flaws Chinese hackers spent 5 years in US infrastructure, ready to attack CISA, FBI warn of China-linked hackers pre-positioning for ‘destructive cyberattacks against US critical infrastructure' Russia using Starlink Canada declares Flipper Zero public enemy No. 1 in car-theft crackdown | Ars Technica Health insurance data breach affects nearly half of France's population, privacy regulator warns Hackers attack 25 Romanian hospitals Catalin on the Rhysider ransomware decrypter going public A password manager LastPass calls “fraudulent” booted from App Store | Ars Technica From Cybercrime Saul Goodman to the Russian GRU – Krebs on Security

The Security Podcast of Silicon Valley
Feross Aboukhadijeh, Founder and CEO of Socket.dev, a startup improving security and privacy on the web

The Security Podcast of Silicon Valley

Play Episode Listen Later Feb 1, 2024 53:40


In this episode of The Security Podcast of Silicon Valley, host Jon McLachlan of YSecurity.io invites Feross Aboukhadijeh, Founder and CEO of Socket.dev, a supply-chain cybersecurity company, to share his compelling journey as he tackles some of the most pressing challenges in software development security. Feross, a Stanford graduate and former intern at Intel, Facebook, and Quora, shares his journey from developing PeerCDN, a pioneering peer-to-peer content network, to his current venture, Socket.dev. Discover how Socket.dev is addressing critical software supply chain vulnerabilities by utilizing innovative technologies, including heuristic analysis and the latest LLMs. This episode offers valuable insights into the evolving cybersecurity landscape and Feross's unique approach to tackling some of the most pressing challenges in software development security. Join us for a captivating discussion that's a must-listen for anyone interested in the future of cybersecurity.

devtools.fm
Feross Aboukhadijeh - Socket

devtools.fm

Play Episode Listen Later Jan 16, 2024 68:11


This week we talk to the open source legend Feross Aboukhadijeh about his journey into open source, the challenges of open source funding, and his new company Socket.Socket is a tool that aims to make OSS security level up by providing a way to audit your dependencies for security vulnerabilities.They are able to detect much more complex vulnerabilities than the current tools on the market by using a combination of static analysis, dynamic analysis, and even some LLMs!Come get scared with us as we delve into the world of open source security. - https://feross.org/ - https://github.com/feross - https://twitter.com/feross - https://twitter.com/SocketSecurity - https://socket.dev/ Episode sponsored By Raycast (https://www.raycast.com/)Become a paid subscriber our patreon, spotify, or apple podcasts for the full episode. - https://www.patreon.com/devtoolsfm - https://podcasters.spotify.com/pod/show/devtoolsfm/subscribe - https://podcasts.apple.com/us/podcast/devtools-fm/id1566647758 - https://www.youtube.com/@devtoolsfm/membership

oss socket feross aboukhadijeh
The Changelog
The I in LLM stands for intelligence

The Changelog

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands daniel stenberg rob pike feross aboukhadijeh jerod santo
Changelog News
The I in LLM stands for intelligence

Changelog News

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands daniel stenberg rob pike feross aboukhadijeh jerod santo
Changelog Master Feed
The I in LLM stands for intelligence (Changelog News #76)

Changelog Master Feed

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands changelog daniel stenberg rob pike feross aboukhadijeh jerod santo
Decipher Security Podcast
Feross Aboukhadijeh

Decipher Security Podcast

Play Episode Listen Later Dec 19, 2023 36:36


Feross Aboukhadijeh, founder and CEO of Socket, joins Dennis Fisher to talk about the challenges of securing open-source projects, supply chain security, and the fragility of the open-source software ecosystem. 

ceo socket feross aboukhadijeh dennis fisher
Syntax - Tasty Web Development Treats
705: Is Running Random Code From npm Safe? With Feross Aboukhadijeh

Syntax - Tasty Web Development Treats

Play Episode Listen Later Dec 15, 2023 67:17 Very Popular


In this Supper Club episode of Syntax, Wes and Scott talk with Feross Aboukhadijeh about his work on Socket which helps to make sure the code you get from npm is safe and secure. They also touch on his work on Wormhole and Web Torrent. Show Notes 00:30 Welcome 00:57 Who is Feross Aboukhadijeh? 01:33 What is Socket? [Socket.dev](https://socket.dev dominictarr (Dominic Tarr) pull-stream/pull-stream: minimal streams 03:59 Introducing AI package summaries Example of the AI summaries Introducing AI Package Summaries 07:04 Is Socket's focus on visibility of a open source project? 10:01 What was the inspiration for Socket? Introducing “safe npm”, a Socket npm Wrapper - Socket 16:22 How does Socket detect possible security issues? Removed packages event-source-polyfill protestware attack john wick spam attack 18:55 How many projects are you injesting for Socket to scan? 26:00 What kinds of things are people trying to inject in code? CS253 Web Security 29:54 How do I hook Socket up to my project or GitHub? 32:08 Do we still need to use shrink wrap? 36:34 How did you implement the torrent spec in JavaScript for WebTorrent? WebTorrent Desktop WebTorrent FAQ 43:11 Why did you build Wormhole? Wormhole 47:33 How expensive is it to maintain Wormhole? Riverside.fm - Record Podcasts And Videos From Anywhere 50:37 What do you think of decentralized code repos? Radicle Project Fugu Fugu Tracker 54:29 Understanding passkeys 56:15 Supper Club questions GitHub Theme - Visual Studio Marketplace Web Serial API - Web APIs | MDN 01:03:04 Sick Picks Sick Picks Harry Potter audio books Shameless Plugs ChatGPT Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads

JS Party
The massive bug at the heart of npm

JS Party

Play Episode Listen Later Jul 7, 2023 63:03


Darcy Clarke, former GitHub Staff Engineering Manager and founder of vlt, joins us to discuss a major bug in the npm ecosystem that he recently disclosed. We cover the bug's timeline, nuances, and impact, all while setting some important context on npm packages, clients, and registries. Tune in to learn how to protect your codebase and gain a deeper understanding of this crucial part of the JavaScript ecosystem.

Changelog Master Feed
The massive bug at the heart of npm (JS Party #282)

Changelog Master Feed

Play Episode Listen Later Jul 7, 2023 63:03 Transcription Available


Darcy Clarke, former GitHub Staff Engineering Manager and founder of vlt, joins us to discuss a major bug in the npm ecosystem that he recently disclosed. We cover the bug's timeline, nuances, and impact, all while setting some important context on npm packages, clients, and registries. Tune in to learn how to protect your codebase and gain a deeper understanding of this crucial part of the JavaScript ecosystem.

Software Engineering Daily
Software Supply Chain with Feross Aboukhadijeh

Software Engineering Daily

Play Episode Listen Later May 16, 2023 44:16


The software supply chain refers to the process of creating and distributing software products. This includes all of the steps involved in creating, testing, packaging, and delivering software to end-users or customers. Socket is a new security company that can protect your most critical apps from supply chain attacks. They are taking an entirely new The post Software Supply Chain with Feross Aboukhadijeh appeared first on Software Engineering Daily.

software supply chains socket software engineering daily feross aboukhadijeh
Security – Software Engineering Daily
Software Supply Chain with Feross Aboukhadijeh

Security – Software Engineering Daily

Play Episode Listen Later May 16, 2023 38:32


The software supply chain refers to the process of creating and distributing software products. This includes all of the steps involved in creating, testing, packaging, and delivering software to end-users or customers. Socket is a new security company that can protect your most critical apps from supply chain attacks. They are taking an entirely new The post Software Supply Chain with Feross Aboukhadijeh appeared first on Software Engineering Daily.

software supply chains socket software engineering daily feross aboukhadijeh
Podcast – Software Engineering Daily
Software Supply Chain with Feross Aboukhadijeh

Podcast – Software Engineering Daily

Play Episode Listen Later May 16, 2023 38:32


The software supply chain refers to the process of creating and distributing software products. This includes all of the steps involved in creating, testing, packaging, and delivering software to end-users or customers. Socket is a new security company that can protect your most critical apps from supply chain attacks. They are taking an entirely new The post Software Supply Chain with Feross Aboukhadijeh appeared first on Software Engineering Daily.

software supply chains socket software engineering daily feross aboukhadijeh
JS Party
Making "safe npm"

JS Party

Play Episode Listen Later Apr 21, 2023 62:06 Transcription Available


Feross and his team at Socket recently shipped a wrapper library for the ubiquitous npm package manager's command-line interface that brings enhanced security when you need it most: before executing any code Bradly Farias lead this effort, so Jerod & Chris invited him on the show to learn all about it.

Changelog Master Feed
Making "safe npm" (JS Party #272)

Changelog Master Feed

Play Episode Listen Later Apr 21, 2023 62:06 Transcription Available


Feross and his team at Socket recently shipped a wrapper library for the ubiquitous npm package manager's command-line interface that brings enhanced security when you need it most: before executing any code Bradly Farias lead this effort, so Jerod & Chris invited him on the show to learn all about it.

JS Party
New Year's Party

JS Party

Play Episode Listen Later Jan 6, 2023 77:49 Transcription Available


It's our 4th annual New Year's party! Jerod & the gang review our (failed) resolutions from last year, discuss what's trending in the web world, make a few predictions of our own & even set some new (probably failed) resolutions for this year.

Changelog Master Feed
New Year's Party

Changelog Master Feed

Play Episode Listen Later Jan 6, 2023 77:49


It's our 4th annual New Year's party! Jerod & the gang review our (failed) resolutions from last year, discuss what's trending in the web world, make a few predictions of our own & even set some new (probably failed) resolutions for this year.

Real Talk JavaScript
Episode 214: Securing Your Web Apps and Source Code with Feross Aboukhadijeh

Real Talk JavaScript

Play Episode Listen Later Dec 15, 2022 46:04


Recording date: 12/1/2022John Papa @John_PapaWard Bell @WardBellDan Wahlin @DanWahlinCraig Shoemaker @craigshoemakerFeross Aboukhadijeh @FerossBrought to you byAG GridIdeaBladeResources:Feross Aboukhadijeh's websiteFeross Aboukhadijeh's GitHubLog4jThe Federal Trade Commission's (FTC) note on Log4jSocket – Secure your JavaScript supply chainWhat's really going on in your node_modules folder?Vulnerability scanning isn't enough to protect your appAuditing npm packages for security vulnerabilitiesGitHub DependabotList of package security issues that Socket detectsList of npm packages that have been removed from npm for security reasonsFeross's Web Security class at Stanford UniversityDarknet DiariesDEFCON conferenceHave I Been Pwned?Troy Hunt1% of CMS-Powered Sites Expose Their Database PasswordsTimejumps00:44 World Cup welcome02:08 Security in applications03:20 Guest introduction04:41 Why should you worry about your software supply chain?07:41 Sponsor: Ag Grid08:50 What's the attack vector like and what's the threat?15:54 Depending on dependancies to find security issues22:16 Sponsor: IdeaBlade23:13 Make it easy to do the right thing29:16 What was log4j?33:45 How does Socket work?34:36 Final thoughtsPodcast editing on this episode done by Chris Enns of Lemon Productions.

The Changelog
A new batch of web frameworks emerge!

The Changelog

Play Episode Listen Later Oct 7, 2022 94:58 Very Popular


This week we're talking fresh, faster, and new web frameworks by way of JS Party. Yes, today's show is a web framework sampler because a new batch of web frameworks have emerged. There's always something new happening in the front-end world and JS Party does an amazing job of keeping us up to date. So…what's fresh, faster, and new? The first segment of the show focuses on Deno's Fresh new web framework. Luca Casonato joins Jerod & Feross to talk about Fresh – a next generation web framework, built for speed, reliability, and simplicity. In segment two, AngularJS creator Miško Hevery joins Jerod and KBall to talk about Qwik. He says Qwik is a fundamental rethinking of how a web application should work. And he's attempting to convince Jerod & KBall that the implications of that are BIG. In the last segment, Amal talks with Fred Schott about Astro 1.0. They go deep on how Astro is built to pull content from anywhere and serve it fast with their next-gen island architecture. Plus there's an 8 minute bonus for our ++ subscribers (changelog.com/++). Fred Schott explains Astro Islands and how Astro extracts your UI into smaller, isolated components on the page, and the unused JavaScript gets replaced with lightweight HTML — leading to faster loads and time-to-interactive.

ShopTalk » Podcast Feed
524: Package Security with Feross Aboukhadijeh from Socket

ShopTalk » Podcast Feed

Play Episode Listen Later Jul 18, 2022 60:39


Feross Aboukhadijeh talks with us about web security, what Socket aims to help with, how Socket compares to Depandabot or Sync, how they analyze all the data for Socket, and what things developers should be thinking about with regards to security in their apps.

JS Party
Deno's Fresh new web framework

JS Party

Play Episode Listen Later Jul 15, 2022 47:47 Transcription Available


Deno team member Luca Casonato joins Jerod & Feross to tell us about Fresh – a next generation web framework, built for speed, reliability, and simplicity.

Console DevTools
Security & Software Supply Chain, with Feross Aboukhadijeh (Socket) - S03E05

Console DevTools

Play Episode Listen Later Jul 7, 2022 31:46


In this episode we speak to Feross Aboukhadijeh, CEO of Socket.dev, a software supply chain security company. We discuss the risks of using third party dependencies, how JS and NPM could improve their approach to security, whether trust in open source is eroding, and how to improve the overall security posture of your application. About Feross AboukhadijehFeross is the founder and CEO of Socket, where he's working on a new approach to open source supply chain security. Feross is the author and maintainer of WebTorrent, StandardJS, and 100s of other open source projects which are downloaded 500+ million times per month. Feross is a lecturer at Stanford University where he teaches CS 253 Web Security. Socket, the company Feross started, is auditing every package on npm to detect suspicious changes and block software supply chain attacks. Hundreds of companies use Socket to protect their software applications and critical services from malware and security threats originating in open source code.Other things mentioned:SocketWebTorrentStandard JSnpmJSTypescriptPrettierDependabotMacBook Pro M1Studio displayLogitech mouseLet us know what you think on Twitter:https://twitter.com/consoledotdevhttps://twitter.com/davidmyttonhttps://twitter.com/ferossOr by email: hello@console.devAbout ConsoleConsole is the place developers go to find the best tools. Our weekly newsletter picks out the most interesting tools and new releases. We keep track of everything - dev tools, devops, cloud, and APIs - so you don't have to. Sign up for free at: https://console.devRecorded: 2022-04-06.

JS Party
Nick's big rewrite

JS Party

Play Episode Listen Later Apr 29, 2022 50:56 Transcription Available


Nick rewrote our JS Danger game board app from Dojo to React for his talk at React Global Online Summit about componentizing application state with React and XState. On this episode Jerod, KBall, and Feross chat with Nick about the entire process and what he learned along the way. Oh, we also play an epic round of Pro Tip Time!

Software Engineering Daily
JavaScript Supply Chain with Feross Aboukhadijeh

Software Engineering Daily

Play Episode Listen Later Apr 23, 2022 45:18 Very Popular


The JavaScript supply chain includes numerous vulnerabilities due to its expansive nature and the long dependency chains. Socket is a new security company that can protect your most critical apps from supply chain attacks. They are taking an entirely new approach to one of the hardest problems in security in a stagnant part of the The post JavaScript Supply Chain with Feross Aboukhadijeh appeared first on Software Engineering Daily.

supply chains javascript socket software engineering daily feross aboukhadijeh
JS Party
This is JS Party!

JS Party

Play Episode Listen Later Apr 13, 2022 1:30


JS Party is a weekly celebration of JavaScript and the web so fun is at the heart of every episode. We play games like Frontend Feud… (clip from episode #192) Discuss and analyze the news… (clip from episode #213) Explain technical concepts to each other like we're 5… (clip from episode #195) Debate hot topics like should websites work without JS? (clip from episode #87) Interiew amazing devs like Rich Harris and Una Kravets… (clip from episode #167) This is JS Party! Listen and subscribe today. We'd love to have you with us.

debate web explain programming animation robotics iot javascript html css node js backend frontend divya changelog interiew rich harris kevin ball feross aboukhadijeh ali spittel jerod santo una kravets mikeal rogers nick nisi
JS Party
Making moves on supply chain security

JS Party

Play Episode Listen Later Apr 1, 2022 63:51 Transcription Available


Feross has been working on something big. He joins Chris and Nick, along with guests Bret Comnes and Mik Lysenko to discuss Socket, what it is, and its focus on the security of the JavaScript supply chain.

PodRocket - A web development podcast from LogRocket
Open-source supply chain security with Feross Aboukhadijeh

PodRocket - A web development podcast from LogRocket

Play Episode Listen Later Mar 22, 2022 44:08


Feross Aboukhadijeh is the creator of WebTorrent, StandardJS, and Wormhole. We talked to Feross about Wormhole back in June and he joins us now to talk about Socket.dev, a new security company that can protect your most critical apps from supply chain attacks. Links https://twitter.com/feross https://socket.dev https://socket.dev/npm/category/removed https://socketdev.notion.site/Join-the-Socket-Team https://webtorrent.io https://standardjs.com https://wormhole.app https://podrocket.logrocket.com/wormhole Review us Reviews are what help us grow and tailor our content to what you want to hear. Give us a review here (https://ratethispodcast.com/podrocket). Contact us https://podrocket.logrocket.com/contact-us @PodRocketpod (https://twitter.com/PodRocketpod) What does LogRocket do? LogRocket combines frontend monitoring, product analytics, and session replay to help software teams deliver the ideal product experience. Try LogRocket for free today. (https://logrocket.com/signup/?pdr) Special Guest: Feross Aboukhadijeh.

All JavaScript Podcasts by Devchat.tv
Supply Chain Security - Part 2 - JSJ 525

All JavaScript Podcasts by Devchat.tv

Play Episode Listen Later Mar 15, 2022 84:10


There's always more to learn about security, especially nowadays. In this episode, the Jabberers continue their conversation with Feross Aboukhadijeh about supply chain security. You can never be too careful! (Well…maybe.) “The most important thing you can do is have a mindset shift around dependencies.” _ _- Feross Aboukhadijeh In This Episode 1) How the BEST way to keep your security tight is NOT done on the computer 2) Why we're seeing a trend toward THESE kinds of packages in 2022 3) What you NEED to know about dependencies and their expiration dates Sponsors Top End Devs (https://topenddevs.com/) Raygun | Click here to get started on your free 14-day trial (https://raygun.com/?utm_medium=podcast&utm_source=jsjabber&utm_campaign=devchat&utm_content=homepage) Coaching | Top End Devs (https://topenddevs.com/coaching) Picks AJ- Download - The Go Programming Language (https://go.dev/dl/) AJ- xtz - npm (https://www.npmjs.com/package/xtz) Follow CoolAJ86 Live Streams: YouTube: https://youtube.com/coolaj86 Twitch: https://twitch.tv/coolaj86 Follow Beyond Code: YouTube: https://www.youtube.com/channel/UC2KJHARTj6KRpKzLU1sVxBA Twitter: https://twitter.com/@_beyondcode Charles- Pandemic | Board Game | BoardGameGeek (https://boardgamegeek.com/boardgame/30549/pandemic) Charles- Meetups | Top End Devs (https://topenddevs.com/meetups) Charles- Get involved with your local community Dan- Uprooted by Naomi Novik (https://www.goodreads.com/en/book/show/22544764-uprooted) Dan- Interview with Senior JS Developer in 2022 (https://www.youtube.com/watch?v=Uo3cL4nrGOk) Feross- Socket (https://socket.dev/) Feross- Wormhole (https://wormhole.app/) Feross- Chakra UI (https://chakra-ui.com/) Steve- This Unicorn Changed the Way I Poop - #SquattyPotty (https://www.youtube.com/watch?v=YbYWhdLO43Q) Steve- Girls Don't Poop - PooPourri.com (https://www.youtube.com/watch?v=ZKLnhuzh9uY) Steve- Twitter: Dad Jokes ( @Dadsaysjokes ) (https://twitter.com/Dadsaysjokes) Special Guest: Feross Aboukhadijeh.

twitch supply chains naomi novik steve edwards supply chain security charles wood feross aboukhadijeh raygun click coaching top end devs
All JavaScript Podcasts by Devchat.tv
Supply Chain Security - Part 1 - JSJ 524

All JavaScript Podcasts by Devchat.tv

Play Episode Listen Later Mar 8, 2022 75:47


Malware attacks are scary, so preparation is keys. In this episode, the Jabberers talk with Feross Aboukhadijeh, a developer who's redefining malware detection to help you prepare for the next assault. “It's awesome that such small teams can make complex code, but it's not enough to just scan for vulnerabilities.” -Feross Aboukhadijeh In This Episode 1) This SCARY trend in supple chain malware attacks (and how to prepare) 2) Why tools like Socket are VERY different from common malware detection 3) How companies in 2022 are addressing their security (and what they're looking for in developers to help them) Sponsors Top End Devs (https://topenddevs.com/) Coaching | Top End Devs (https://topenddevs.com/coaching) Links Socket – protect your OSS supply chain (https://socket.dev/) Feross's Talk at CascadiaJS 2021 “It's a Jungle Out There! – Open Source Supply Chain Attacks” (https://www.youtube.com/watch?v=Cl7WVN4168M) Picks Aimee- Kubernetes Chaos Engineering Aimee- Normatec 2.0 Pro Legs | Hyperice (https://hyperice.com/products/normatec-2-pro-legs/) AJ- Socket (https://socket.dev/) AJ- Bundlephobia (https://bundlephobia.com/) AJ- NPMGraph (https://npmgraph.js.org/) Follow CoolAJ86 Live Streams: YouTube: https://youtube.com/coolaj86 Twitch: https://twitch.tv/coolaj86 Follow Beyond Code: YouTube: https://www.youtube.com/channel/UC2KJHARTj6KRpKzLU1sVxBA Twitter: https://twitter.com/@_beyondcode Charles- 7 Wonders Board Game (https://amzn.to/3IU78by) Charles- Airmeet (https://www.airmeet.com/) Charles- Events | Top End Devs (https://topenddevs.com/events) Feross- Node.js Fetch Feross- Darknet Diaries – True stories from the dark side of the Internet (https://darknetdiaries.com/) Feross- Risky Business news recap Steve- passWORDLE (https://rsk0315.github.io/playground/passwordle.html) Special Guest: Feross Aboukhadijeh.

internet talk twitch supply chains malware oss socket supply chain security charles wood feross aboukhadijeh jungle out there aimee knight feross coaching top end devs