Ahmad Nassri
@ahmadnassri.com
📤 750
📥 44
📝 17
Syrian-Canadian 🇸🇾🇨🇦, Fractional CTO, Developer Accelerator. past: npm, Telus, Kong, CBC, BlackBerry
reposted by
Ahmad Nassri
Socket
3 days ago
Check out Socket CTO
@ahmadnassri.com
at
@workos.bsky.social
' Enterprise Ready Conf: Ahmad joined a panel discussing how enterprise security is adapting, as AI speeds up both software development and attacks targeting developer machines.
socket.dev/blog/how-ent...
loading . . .
How Enterprise Security Is Adapting to AI-Accelerated Threat...
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.
https://socket.dev/blog/how-enterprise-security-is-adapting-to-ai-accelerated-threats
0
1
1
nothing beats a Syrian breakfast 🤤 @ Damaski Palace
maps.app.goo.gl/NWZatN3mgves...
7 days ago
1
3
0
reposted by
Ahmad Nassri
Socket
15 days ago
🚀 Socket Launch Week Day 5! Malicious packages are infiltrating development environments before they ever reach production. Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.
1
2
1
reposted by
Ahmad Nassri
Feross
19 days ago
1️⃣ AI models aren’t just math -- they’re code. And just like npm or PyPI, they can get hacked. Today we’re launching malware scanning for the Hugging Face ecosystem. 🤖🔍 Socket can now detect backdoors and malicious payloads inside AI models themselves. 👇
www.youtube.com/watch?v=9FQy...
loading . . .
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
YouTube video by Socket Security
https://www.youtube.com/watch?v=9FQyaICd2iM
2
10
6
for better security: I use 1password cli with direnv to dynamically load env values (ssh keys, tokens, secrets, etc ...) AWS outage -> 1password thinks it's offline -> can't run anything locally which requires secrets🥲
19 days ago
1
1
0
reposted by
Ahmad Nassri
Peter van der Zee
23 days ago
Recognition for Sarah! So deserved!
@sarahgooding.bsky.social
2
9
4
Join me next week at the
@workos.bsky.social
Enterprise Ready Conf. will be speaking on a panel on all things security & how developers can take back control of their software supply chain. If you're attending, lchat with me & the
@socket.dev
team IRL!
enterprise-ready.com
24 days ago
0
1
1
@bun.sh
users can now install any package with confidence, knowing that
@socket.dev
got their back! Free from malicious packages, typosquatting, and other supply chain attacks.
socket.dev/blog/socket-...
loading . . .
Socket Integrates With Bun 1.3’s Security Scanner API - Sock...
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local de...
https://socket.dev/blog/socket-integrates-with-bun-1-3-security-scanner-api
29 days ago
0
1
0
Supply chain attacks are evolving and so should your security practices. case-in-point: Beamglea - a campaign that turns npm 💔 into a phishing-as-a-service platform This isn't your typical supply chain attack. It's infrastructure weaponization.
socket.dev/blog/175-mal...
loading . . .
175 Malicious npm Packages Host Phishing Infrastructure Targ...
175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...
https://socket.dev/blog/175-malicious-npm-packages-host-phishing-infrastructure
29 days ago
1
4
1
Happy to share I'm getting back to my roots in open source, this time around on the side of protecting software development! If you haven't yet, you should install
@socket.dev
for your team!
about 1 month ago
0
16
3
reposted by
Ahmad Nassri
Socket
4 months ago
🚨 npm phishing alert! Attackers are sending emails from spoofed
[email protected]
addresses linking to a typosquatted clone site (
npnjs.com
) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links:
socket.dev/blog/npm-phi...
#nodejs
#JavaScript
1
21
15
get some perspective. 2 million people, surrounded by walls and the sea, under a 17+ year blockade. what if it was in your city?
#GazaAttack
#Gaza
#GazaEverywhere
ahmadnassri.github.io/gaza-everywh...
about 2 years ago
0
2
0
what's with the recent explosion of PMP certification spam on LinkedIn ????
about 2 years ago
0
1
0
I'm starting to document some of my fundamental learnings in this industry in writing ... took a first stab at some of it in a guesr post at Unified's blog (disclaimer: I'm an advisor) next post will be about TCO & MVP architecture needs for startups
loading . . .
Ask a CTO - Building your technology investment strategy
August 10, 2023
https://unified.to/blog/ask_a_cto_building_your_technology_investment_strategy
about 2 years ago
0
0
0
the staggering amount of over-engineering, horrible leadership, and clueles product owners I've seen after ~3 years of being a Fractional CTO really makes me question this entire career / industry... if I had to do it all over again, I'd probably go into banking or law ...
over 2 years ago
1
0
0
normal 🧠: need to update a single DNS record for my domain dev 🧠: now is the right time to migrate 50+ domains from Google Domains to CloudFlare AND do a full Terraform automation pipeline on GH Actions to manage them all!
over 2 years ago
1
0
0
I AM HERE!
over 2 years ago
0
3
0
you reached the end!!
feeds!
log in