Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure
Most users have no real visibility into what their browser extensions are doing. This week, we uncovered a campaign spanning 108 extensions and roughly 20,000 Chrome Web Store installs, all tied to the same C2 infrastructure. These extensions stole Google account data, hijacked Telegram Web sessions, and gave operators a backdoor into victims’ browsers.
MORE NEWS
NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets
NIST has officially stopped enriching most CVEs in the National Vulnerability Database, conceding it can no longer keep up with the volume of submissions. Going forward, the NVD will focus on vulnerabilities tied to CISA’s KEV catalog, federal government systems, and software deemed critical under Executive Order 14028. Most other CVEs will be dumped into a “Not Scheduled” bucket without the CVSS and CPE data security teams need to prioritize and map affected software.
OpenAI Announces GPT-5.4-Cyber for Defensive Security Work
OpenAI says it is preparing for more capable models in the months ahead by fine-tuning systems specifically for defensive cybersecurity use cases, starting with GPT-5.4-Cyber, a more cyber-permissive variant of GPT-5.4. The announcement also introduced new Cybersecurity Grant Program recipients, including Socket, Semgrep, Calif, and Trail of Bits, with grant support paired with access to more cyber-permissive frontier models for qualified defenders.
MORE WORTH READING
Vercel April 2026 security incident
GitHub: Secret scanning pattern updates and product improvements
OpenSSF: Using Runtime Context to Win the Vulnerability Management Battle
Europol-supported global operation targets over 75,000 users engaged in DDoS attacks
AI Companies to Play Bigger Role in CVE Program, Says CISA
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe