
Security News
Critical Security Vulnerability in React Server Components
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.


Anders Søndergaard
November 11, 2025
This December, the Socket team will be in London for two of Europe’s biggest security events: Black Hat Europe (December 10–11) and BSides London (December 13).
If you’re attending either event, we’d love to connect, talk about software supply chain security, and show how Socket helps security and engineering teams take control of their open source dependencies.
Our European team will be taking meetings Wednesday through Friday during Black Hat and BSides week.
In the past year, we've seen supply chain attacks increasingly target developers, using poisoned dependencies and malicious install scripts to compromise systems during development, often through something as simple as an npm install. Attackers aren’t waiting for code to reach production anymore.
To counter these earlier-stage threats, Socket has expanded beyond our best-in-class malware detection to make open source security more actionable:
If you’re attending Black Hat or BSides, this is a great opportunity to see the latest Socket features in action and talk directly with our team. Book a meeting →

We’re looking forward to connecting with the European security community, exchanging ideas, and showing how Socket helps organizations protect their open source supply chain from the inside out.
Spots are limited! Book your meeting today to meet the Socket team at Black Hat or BSides London.
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Try it now

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.

Security News
TypeScript 6.0 will be the last JavaScript-based major release, as the project shifts to the TypeScript 7 native toolchain with major build speedups.