
Sarah Gooding
@pollyplummer
Followers
11K
Following
4K
Media
274
Statuses
16K
Head of Content Marketing @socketsecurity (https://t.co/T0hRfvAzU0) Open source and open web advocate, runner, knitter. Also at https://t.co/kPAv4D4kxU
Saint Johns, FL
Joined April 2008
I'm excited to share that @SocketSecurity has raised $40M in Series B funding led by @AbstractVC! We're securing open source software at scale and have so much more to achieve on our mission. A big thank you to the 1M+ developers who trust our platform to secure your code!.
🚀 We’re thrilled to announce Socket’s $40M Series B led by @AbstractVC with participation from @eladgil and @a16z!
1
4
11
RT @david_perell: It seems like there’s an overwhelming amount of good content on the Internet, but every time somebody publishes something….
0
11
0
RT @SocketSecurity: 🚨 Attackers have hijacked the npm 'is' package (~2.8M weekly downloads), adding a malicious JS loader. This compromise….
socket.dev
The ongoing npm phishing campaign escalates as attackers hijack the popular 'is' package, embedding malware in multiple versions.
0
4
0
RT @SocketSecurity: 🚨 A critical vulnerability in the widely used npm form-data package could allow HTTP Parameter Pollution, potentially i….
socket.dev
A critical flaw in the popular npm form-data package could allow HTTP parameter pollution, affecting millions of projects until patched versions are a...
0
1
0
RT @SocketSecurity: Bun 1.2.19 introduces isolated installs for monorepos, smarter package management, and 5x faster Bun.sql. 🎉 Congrats to….
socket.dev
Bun 1.2.19 introduces isolated installs for smoother monorepo workflows, along with performance boosts, new tooling, and key compatibility fixes.
0
12
0
RT @HackRead: 🚨 A fake npm website tricked a maintainer into giving up their token, letting attackers push malware into popular JS packages….
hackread.com
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
0
5
0
RT @SocketSecurity: 🚨 Active supply chain attack on #npm: Multiple Prettier tooling packages were compromised through the phishing campaign….
socket.dev
Popular npm packages like eslint-config-prettier were compromised after a phishing attack stole a maintainer’s token, spreading malicious updates.
0
16
0
RT @SocketSecurity: 🦀 Rust is the latest open source ecosystem to adopt Trusted Publishing, joining PyPI and RubyGems in moving away from l….
socket.dev
Crates.io adds Trusted Publishing support, enabling secure GitHub Actions-based crate releases without long-lived API tokens.
0
3
0
RT @SocketSecurity: 🚨 UPDATE: Socket's Threat Research Team continues tracking the spread of protestware targeting Russian language users.….
socket.dev
Undocumented protestware found in 28 npm packages disrupts UI for Russian-language users visiting Russian and Belarusian domains.
0
2
0
RT @SocketSecurity: 🚨 New research: North Korea’s Contagious Interview campaign is back, with 67 new malicious npm packages, a new malware….
socket.dev
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
0
2
0
RT @feross: Socket revenue 3x’d in the last year. We’re growing like crazy. And this is the best engineering team I’ve ever worked with — b….
0
7
0
RT @SocketSecurity: In Vegas for Black Hat or DEF CON? We're hosting 1:1s with @feross and the next edition of the much-loved Campfire Stor….
0
3
0
Awesome research from the team at @AliasRobotics!.
🚨 New open source AI #cybersecurity framework outperforms humans in both speed and cost. It handles pen testing tasks like scanning and exploitation 3,600× faster and reduces costs by 156×. #AI #opensource #bugbounty.
0
2
2
RT @RaisinTen: CI Reliability is becoming a @nodejs Strategic Initiative. Interested in leading it? Volunteer here:.
github.com
The CI situation nodejs/TSC#1614 has been discussed in many TSC meetings. To help it move forward pragmatically, the TSC has agreed to make it a strategic initiative. If you're interested in le...
0
6
0
AI models just don't understand what they're talking about via @TheRegister.
theregister.com
: Researchers find models' success at tests hides illusion of understanding
0
1
2
RT @SocketSecurity: 🦀 Rust continues to reshape #JavaScript frontend tooling. @Browserslist-rs just got a major performance optimization: i….
socket.dev
Browserslist-rs now uses static data to reduce binary size by over 1MB, improving memory use and performance for Rust-based frontend tools.
0
6
0
This paper captured my curiosity. "Potemkin Understanding" aptly describes a frustration we all experience daily: an LLM sounds like it understands but can't apply what it knows. A few years from now, we’ll look back on these early days with a better lexicon for what was missing.
🏘️ "Potemkin Understanding" - a failure mode where LLMs appear to grasp a concept but only create the illusion of understanding. New research shows models get definitions right 94% of the time but fail to use those same concepts 40-55% of the time. →.
0
1
1