Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
Contagious Interview has gone cross-ecosystem. This new cluster shows the same staged malware loader pattern now appearing across npm, PyPI, Go Modules, crates, and Packagist. The packages impersonate common developer tools to fetch second-stage RAT payloads that steal credentials and wallets and enable remote access.
MORE NEWS
Anthropic Introduces Project Glasswing, an AI-Powered Push to Secure Critical Software
Anthropic’s Project Glasswing announcement sent the security world into overdrive, as researchers and vendors scrambled to react to a model that can autonomously find and exploit vulnerabilities at a level approaching top human experts. The headline: its Mythos Preview model is already uncovering thousands of serious vulns and posting big benchmark gains (83% on CyberGym vs. 66% for its predecessor, and ~94% on SWE-bench Verified), while Anthropic is committing $100M in usage credits plus $4M in funding to bring those capabilities to defenders and open source maintainers.
Attackers Are Impersonating a Linux Foundation Leader in Slack to Target Open Source Developers
Attackers are targeting open source maintainers through the tools they rely on, including Slack and other trusted community channels. In the latest campaign, a threat actor impersonated a Linux Foundation leader to lure developers into a multi-stage attack that ends in malware and credential theft. We’re increasingly seeing social engineering used as a direct path into the software supply chain.
MORE WORTH READING
npm trusted publishing now supports CircleCI
AI Cybersecurity After Mythos: The Jagged Frontier
Cybercrime losses jumped 26% to $20.9 billion in 2025
Microsoft Releases Open Source Toolkit for AI Agent Runtime Security
What’s coming to our GitHub Actions 2026 security roadmap
AI Tools Are Eroding Your Zero Trust Foundations
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe