Node.js
Game engineWikipedia
130
MENTIONS
52
EPISODES
41
PODCASTS
Search complete. 130 mentions across 52 episodes found for "Node.js".
Sep 11, 2026
Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats
A
20:57Ashish RajanHOST
Yeah.
A
20:57Ashish RajanHOST
Do you find that people are building cloud infrastructure with lovable apps as well? Like, does it extend from GitHub to infra, all of that as well? Because I imagine an app being production ready has to now extend not just to, hey, my code gets pushed out to GitHub, It doesn't really matter, Node.js, TypeScript, whatever, but I also need the backend to host it on.
A
21:18Ashish RajanHOST
Are people even connecting that onto Lovable as well?
M
21:21Marcus HallbergGUEST
So there's multiple deployments models that we provide.
The Hidden Cost of Flat Logs in AI Agent Development
H
3:08HackerNoon AINARRATOR
Passing identifiers manually works, but one forgotten field can break the trail.
H
3:14HackerNoon AINARRATOR
Node.js provides the stable async local storage, https://nodejs.org/api/async_context.html, API for carrying execution scoped values across many asynchronous boundaries.
H
3:30HackerNoon AINARRATOR
This helps with in-process context.
H
3:32HackerNoon AINARRATOR
Crossing queues, services, or processes still requires explicit propagation through an appropriate carrier.
Record-Shattering September Patch Tuesday as Microsoft Fixes 974 CVEs Including Two Exploited Zero-Days, Adobe Patches Over 170 Vulnerabilities, 220 Million Traveler Records Exposed in Vietnam
J
0:00James AzarHOST
Hey everyone, it's Patch Tuesday and Microsoft setting an all-time record nine hundred and seventy-four vulnerabilities, two already exploited in the wild.
J
0:07James AzarHOST
FortiGate firewalls are actively compromised with a Node.js RAT that's decrypting your VPN credentials and exfiltrating Exchange mailboxes.
J
0:16James AzarHOST
White Hat hackers draining three hundred and twenty million dollars from the Liquid Bitcoin network via a software bug.
J
0:23James AzarHOST
Now, they got most of it back, but they're keeping forty-seven million, and the network is still offline.
7 MINS LATER
J
7:49James AzarHOST
All right, we're gonna continue today's shows with CVE-2025-25249 or a niner point eight CVSS heap buffer overflow in the CAPWAP control daemon in FortiOS and FortiSwitch Manager, which was patched by Fortinet back in January of this year.
J
8:03James AzarHOST
The campaign exploiting it now is not an opportunistic scanning one.
J
8:07James AzarHOST
Uh, it is a structured, automated operation targeting internet-facing FortiGate appliances with a purpose-built implant called Pivot C2, which is a custom Node.js post-exploitation framework designed specifically for FortiGate hardware.
J
8:24James AzarHOST
The exploit reaches the CAPWAP service on UDP port fifty-two forty-six.
447. Podcasting Lessons from the History of Podgagement
D
22:04Daniel J. LewisHOST
So at that time, my friend Angelo Mindato, who is from Blubrry in the past, and he's the guy who created PowerPress and has helped set the standard for many of the ways that we measure podcast downloads.
D
22:16Daniel J. LewisHOST
But he suggested to me, instead of my ideas of PHP or even a WordPress plugin to run this complete web app, he suggested I look into something called Node.js. Now, let's get a little geeky for a moment.
D
22:30Daniel J. LewisHOST
JavaScript is the thing in your web browser that makes websites essentially do something before the page refreshes or before it takes you to a different URL.
D
22:43Daniel J. LewisHOST
That's essentially JavaScript.
D
22:44Daniel J. LewisHOST
I know it can be a lot of other things too, but most of the time we see that as that's JavaScript doing that job.
D
22:51Daniel J. LewisHOST
And for so long, JavaScript could only do things in the browser.
D
22:55Daniel J. LewisHOST
Node.js puts JavaScript on a server, so it can run stuff in the background and run processes like a server.
D
23:04Daniel J. LewisHOST
So it became not just a front-end functionality language, it became a back-end programming language with Node.js. And Angelo Mindato suggested that I consider that because it would be faster for my particular needs.
Security Now 1095: AI-Driven Expertise Loss
S
57:12Steve GibsonHOST
And so they said, "We are in the process of disclosing these two vulnerabilities to the maintainers," meaning the Chromium guys.
S
57:20Steve GibsonHOST
Okay, so of course, V8 is Google's open source, high performance JavaScript and WebAssembly engine used internally by Chrome, uh, other Chromium, uh, browsers, Node.js, and other projects.
S
57:37Steve GibsonHOST
And as we also know, it recently received an extremely high volume of updates thanks to automated vulnerability disc- uh, discovery.
S
57:47Steve GibsonHOST
So this allowed OpenA...
482: Destination Linux 482: Rocco Returns & Red Hat’s Mike McGrath Sheds Light On Lightwell
M
74:34Mike McGrathGUEST
Well, and I think the other side of this coming, we're going to add some more ecosystem languages.
M
74:40Mike McGrathGUEST
We've got our eyes on Node.js, which is, if you've looked at the Node.js packages, there's like 5 trillion of them or something.
M
74:49Mike McGrathGUEST
So we'll get started on that.
M
74:52Mike McGrathGUEST
And we're looking at .NET as well.
Artifactory's Backdoor: Why Patching Isn't Enough
C
23:28CyberRiskHOST
That could be why, right? All right.
C
23:31CyberRiskHOST
In our last story for the night, Stealth Hit Info Stealer gets a Node.js makeover.
C
23:36CyberRiskHOST
Fake games and VPNs are now the bait.
C
23:40CyberRiskHOST
This is
C
23:43CyberRiskHOST
bit.
C
23:43CyberRiskHOST
Fortnite Research reported September 1st that Stealth Hit Info Stealer, a long...
C
23:51CyberRiskHOST
Black Market Password Stealer sold as malware as a service and rentable for a few hundred dollars has upgraded its delivery to Node.js Single Executable Applications or SEA.
C
24:04CyberRiskHOST
Node.js SEA is a legitimate developer feature that bundles code into a standalone executable so the implant looks like an ordinary developer build to many antivirus engines.
04-Sep-2026 Thomson Reuters Breach, Pegasus Spyware and Node.js Attacks
S
2:58speaker_0NARRATOR
The case matters because it shows AI era obfuscation methods crossing into mainstream phishing exposing potential blind spots in keyword, tokenization, and normalization pipelines.
S
3:11speaker_0NARRATOR
And finally for today, threat actors are abusing the trusted Node.js runtime in targeted attacks against government, technology, fintech, and hotel organizations using the signed tool to run malicious scripts, persist through registry keys, and deliver backdoors such as C2 Looper, Mystic, and Ask a Stealer.
S
3:32speaker_0NARRATOR
In one case, attackers pivoted from blocked Adaptix C2 and Cobalt Strike deployments to Node.js and Ether hiding after gaining access through ClickFix social engineering.
S
3:45speaker_0NARRATOR
The campaign matters because it blends legitimate developer tools, commodity malware and blockchain-based infrastructure to make detection and takedown far more difficult.
S
3:55speaker_0NARRATOR
this concludes your daily briefing this episode was created with ai by citadel cyber this is hacked daily the first ai driven cyber security podcast i'll be back tomorrow be sure to follow and subscribe thank you and good day this message will now self-destruct
Vibe Coding’s Security Debt
S
11:23Sam BowneHOST
And this is actually one that troubles me.
S
11:26Sam BowneHOST
Attackers are using Node.js to perform malicious activities.
S
11:30Sam BowneHOST
And the trick here is that signature enforcement, which is the main security control for running unauthorized executables on a Windows system, it checks to make sure it's signed.
S
11:39Sam BowneHOST
But Node.js is a commercial product, perfectly signed, perfectly fine.
S
11:44Sam BowneHOST
But it then takes commands for another file.
S
11:47Sam BowneHOST
And so it will pass signature verification on the executable, but then execute commands that come from another file that's just a data file.
BellSoft’s Catherine Edelveis on hardened runtime images, container security, and more
J
40:54Josh LongHOST
One second.
K
40:55Katherine EdelweissGUEST
Build applications for Java, right? So build back support Java, GraalVM native image, Python, Go, Node.js, and Ruby.
K
41:06Katherine EdelweissGUEST
So you can unify your stack on this builder.
J
41:10Josh LongHOST
So good.
42 more episodes mention Node.js.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.