
Socket raised $60 million in a Series C round led by Thrive Capital, bringing total funding to $125 million and valuation to $1 billion. The California-based company, founded in 2020, provides a platform that analyzes open source dependencies to identify malicious behavior before it impacts enterprise products. The platform uses AI-assisted analysis with human verification to detect supply chain compromises, prioritize vulnerability patching based on confirmed exploitation, and address dependency risks. The funding will improve Socket Firewall to block malicious packages before they reach developer environments or CI pipelines and expand certified patches for exploited vulnerabilities. Socket will also extend protection to browser extensions, code editor extensions, AI tools, and MCP servers, while investing in new product development and hiring.
"Socket has announced raising $60 million in a Series C funding round that brings the total raised by the company to $125 million and its valuation to $1 billion."
"Founded in 2020, California-based Socket has built a platform that analyzes open source dependencies to identify malicious behavior before affecting enterprise products. The platform relies on AI-assisted analysis, combined with human verification, to detect potential supply chain compromises, prioritize vulnerability patching based on confirmed exploitation, and address dependency risks."
"The new funding will allow Socket to improve its recently released Socket Firewall, designed to block malicious packages before they can reach developer environments or CI pipelines, and to expand its certified patches, which fix exploited vulnerabilities. Additionally, the company is expanding its protection coverage to browser extensions, code editor extensions, AI tools, and MCP servers."
""AI is changing how software gets built at every level. Teams are moving faster, more code is being generated, and more of what ends up in production now comes from outside the company. The hard part is keeping that speed without losing visibility into what's actually getting shipped, and that's where Socket comes in," Socket founder and CEO Feross Aboukhadijeh said."
#supply-chain-security #open-source-dependencies #ai-powered-security #vulnerability-patching #developer-tooling
Read at SecurityWeek
Unable to calculate read time
Collection
[
|
...
]