惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
小众软件
小众软件
D
Docker
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
V2EX
博客园 - 叶小钗
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
IT之家
IT之家
博客园 - 司徒正美
M
MIT News - Artificial intelligence
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
Andrew Becherer Joins Socket as Chief Information Securit...
Sarah Gooding · 2026-06-12 · via Socket

AI now writes as much as 90% of code at top engineering organizations, and the developers downstream of that code pull in open source they've never reviewed. Package hijackings and maintainer compromises that were once a handful of incidents a year now happen weekly. Modern engineering organizations depend on open source to ship faster, and they need security partners who can keep pace with that shift.

Today, we're welcoming Andrew Becherer as Socket's first Chief Information Security Officer.

Socket now protects more than 27,000 organizations, including enterprises that depend on us to secure the software supply chain behind their most important products. Security has always been central to how Socket builds, shaped by a team with deep experience maintaining critical open source infrastructure. At our current scale, that work needs dedicated executive leadership across security, compliance, and risk.

Andrew joins us after building security programs at some of the most consequential SaaS companies of the last decade. He began his security career at iSEC Partners, working with hyperscalers on infrastructure security. He went on to serve as CISO at Datadog during its hypergrowth years, then served as CISO at Iterable. Most recently he was CISO at Sublime Security. Between Iterable and Sublime he founded Staris AI, where he worked on the security and trust questions that come with building production AI systems. Andrew brings experience leading security at companies that move quickly, serve demanding customers, and operate in environments where trust is part of the product.

"Hiring our first CISO was always going to be one of the highest-stakes decisions we make," Socket CEO Feross Aboukhadijeh said. "Andrew has built and run security at every scale, and he understands the supply chain problem from both sides. He's a defender who's lived through it, and a builder who knows what tools actually help. He's the right person to own how Socket protects itself and how Socket shows up for the security teams we serve."

Andrew will help guide how Socket builds security into the company, the product, and our work with the broader community of defenders.

"I joined Socket because the supply chain is where the fight is right now, and Socket is doing some of the hardest, most important work in this space," Andrew said. "Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package. That’s the problem Socket exists to solve, and the team here has been ahead of it from the beginning, before the risk became painfully obvious to the rest of the industry."

This is a big moment for Socket. Andrew’s experience will help us strengthen the security program behind the products we build, the infrastructure we operate, and the open source ecosystem we’re here to protect.

We’re hiring across engineering, product, design, security, and go-to-market. Come build with us.