惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
B
Blog
F
Fortinet All Blogs
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
A
About on SuperTechFans
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
B
Blog RSS Feed

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
Andrew Becherer Joins Socket as Chief Information Securit...
Sarah Gooding · 2026-06-12 · via Socket

AI now writes as much as 90% of code at top engineering organizations, and the developers downstream of that code pull in open source they've never reviewed. Package hijackings and maintainer compromises that were once a handful of incidents a year now happen weekly. Modern engineering organizations depend on open source to ship faster, and they need security partners who can keep pace with that shift.

Today, we're welcoming Andrew Becherer as Socket's first Chief Information Security Officer.

Socket now protects more than 27,000 organizations, including enterprises that depend on us to secure the software supply chain behind their most important products. Security has always been central to how Socket builds, shaped by a team with deep experience maintaining critical open source infrastructure. At our current scale, that work needs dedicated executive leadership across security, compliance, and risk.

Andrew joins us after building security programs at some of the most consequential SaaS companies of the last decade. He began his security career at iSEC Partners, working with hyperscalers on infrastructure security. He went on to serve as CISO at Datadog during its hypergrowth years, then served as CISO at Iterable. Most recently he was CISO at Sublime Security. Between Iterable and Sublime he founded Staris AI, where he worked on the security and trust questions that come with building production AI systems. Andrew brings experience leading security at companies that move quickly, serve demanding customers, and operate in environments where trust is part of the product.

"Hiring our first CISO was always going to be one of the highest-stakes decisions we make," Socket CEO Feross Aboukhadijeh said. "Andrew has built and run security at every scale, and he understands the supply chain problem from both sides. He's a defender who's lived through it, and a builder who knows what tools actually help. He's the right person to own how Socket protects itself and how Socket shows up for the security teams we serve."

Andrew will help guide how Socket builds security into the company, the product, and our work with the broader community of defenders.

"I joined Socket because the supply chain is where the fight is right now, and Socket is doing some of the hardest, most important work in this space," Andrew said. "Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package. That’s the problem Socket exists to solve, and the team here has been ahead of it from the beginning, before the risk became painfully obvious to the rest of the industry."

This is a big moment for Socket. Andrew’s experience will help us strengthen the security program behind the products we build, the infrastructure we operate, and the open source ecosystem we’re here to protect.

We’re hiring across engineering, product, design, security, and go-to-market. Come build with us.