Security News

Critical Vulnerabilities Uncovered in Open Source CasaOS Cloud Software
2023-10-17 14:37

Two critical security flaws discovered in the open-source CasaOS personal cloud software could be successfully exploited by attackers to achieve arbitrary code execution and take over susceptible...

Can open source be saved from the EU's Cyber Resilience Act?
2023-10-13 14:45

Opinion When I was in Bilbao recently for the Open Source Summit Europe event, the main topic of conversation was the European Union's Cyber Resilience Act. Why? Because pretty much everyone with an open source clue sees it as strangling open source software development.

The root cause of open-source risk
2023-10-05 03:00

One in eight open-source downloads today poses known and avoidable risks. Only 11% of open-source projects are 'actively maintained'.

Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack
2023-10-04 11:16

A new deceptive package hidden within the npm package registry has been uncovered deploying an open-source rootkit called r77, marking the first time a rogue package has delivered rootkit...

Microsoft Edge, Teams get fixes for zero-days in open-source libraries
2023-10-03 14:54

Microsoft released emergency security updates for Edge, Teams, and Skype to patch two zero-day vulnerabilities in open-source libraries used by the three products. The libwebp library is used by a large number of projects for encoding and decoding images in the WebP format, including modern web browsers like Safari, Mozilla Firefox, Microsoft Edge, Opera, and the native Android web browsers, as well as popular apps like 1Password and Signal.

Chalk: Open-source software security and infrastructure visibility tool
2023-10-03 03:30

Chalk is a free, open-source tool that helps improve software security. You add a single line to your build script, and it will automatically collect and inject metadata into every build artifact: source code, binaries, and containers.

Network Flight Simulator: Open-source adversary simulation tool
2023-09-27 03:30

Network Flight Simulator is a lightweight utility that generates malicious network traffic and helps security teams evaluate security controls and network visibility. The tool performs tests to simulate DNS tunneling, DGA traffic, requests to known active C2 destinations, and other suspicious traffic patterns.

BinDiff: Open-source comparison tool for binary files
2023-09-25 09:58

BinDiff is a binary file comparison tool to find differences and similarities in disassembled code quickly. You can also port symbols and comments between disassemblies of multiple versions of the same binary or use BinDiff to gather evidence for code theft or patent infringement.

LLM Guard: Open-source toolkit for securing Large Language Models
2023-09-19 04:30

LLM Guard is a toolkit designed to fortify the security of Large Language Models. It provides extensive evaluators for both inputs and outputs of LLMs, offering sanitization, detection of harmful language and data leakage, and prevention against prompt injection and jailbreak attacks.

CISA Aims For More Robust Open Source Software Security for Government and Critical Infrastructure
2023-09-18 18:23

CISA also plans to create a guide to best practices in open source security for government entities and critical infrastructure organizations, according to the roadmap. CISA notes that open source software can lead to great innovation; however, CISA said, vulnerabilities like the widespread Log4shell vulnerability in 2021 mean open source software can introduce insidious flaws in widely-used code.