Security News

Cisco, Sonatype and Others Join Open Source Security Foundation
2021-08-02 13:07

The Open Source Security Foundation, the cross-industry forum focused on improving open source software security, has expanded its member list with the addition of names such as Accurics, Anchore, Bloomberg Finance, Cisco Systems, Codethink, Cybertrust Japan, OpenUK, ShiftLeft, Sonatype and Tidelift. With open source software becoming a central pillar of the application development lifecycle, ensuring the security of open source code is essential to securing modern software, regardless of whether it is used on end-user devices or in enterprise environments.

Dynatrace’s enhancements deliver analytics capabilities to more open-source services
2021-08-01 01:00

Dynatrace announced customers can extend Smartscape, the Dynatrace platform's real-time and continuously updated topology, to bring Dynatrace's powerful AIOps and analytics capabilities to more open-source services, including OpenTelemetry, FluentD, and Prometheus. As a result, DevOps and SRE teams can easily curate and analyze data streams from any source, at scale.

Several Bugs Found in 3 Open-Source Software Used by Several Businesses
2021-07-29 20:32

Cybersecurity researchers on Tuesday disclosed nine security vulnerabilities affecting three open-source projects - EspoCRM, Pimcore, and Akaunting - that are widely used by several small to medium businesses and, if successfully exploited, could provide a pathway to more sophisticated attacks. All the security flaws in question, which impact EspoCRM v6.1.6, Pimcore Customer Data Framework v3.0.0, Pimcore AdminBundle v6.8.0, and Akaunting v2.1.12, were fixed within a day of responsible disclosure, researchers Wiktor S?dkowski of Nokia and Trevor Christiansen of Rapid7 noted.

GitLab Releases Open Source Tool for Hunting Malicious Code in Dependencies
2021-07-26 12:23

GitLab last week announced the release of a new open source tool designed to help software developers identify malicious code in their projects' dependencies. Code reuse is a central approach to today's programming, but implementing open-source libraries in software comes with inherent risks.

The Audacity! How to wreck an open-source project and anger a community
2021-07-06 14:57

Now, prior to this, you may or may not have heard that the Audacity developers were toying around with adding telemetry to collect data from users. "All your personal data is stored on our servers in the European Economic Area. However, we are occasionally required to share your personal data with our main office in Russia and our external counsel in the USA.".

New Google Scorecards Tool Scans Open-Source Software for More Security Risks
2021-07-02 02:56

Google has launched an updated version of Scorecards, its automated security tool that produces a "Risk score" for open source initiatives, with improved checks and capabilities to make the data generated by the utility accessible for analysis. "With so much software today relying on open-source projects, consumers need an easy way to judge whether their dependencies are safe," Google's Open Source Security Team said Thursday.

Regula: Open source policy engine for IaC security
2021-06-29 06:00

Fugue announced Regula 1.0, an open source policy engine for infrastructure as code security. Available at GitHub, the tool includes support for common IaC tools such as Terraform and AWS CloudFormation, prebuilt libraries with hundreds of policies that validate AWS, Microsoft Azure, and Google Cloud resources, and new developer tooling to support custom rules development and testing with Open Policy Agent.

Google Expands Open Source Vulnerabilities Database
2021-06-24 13:52

Google today announced the expansion of the Open Source Vulnerabilities database to include information on bugs identified in Go, Rust, Python, and DWF open source projects. Launched in February 2021 with details on thousands of vulnerabilities from Google's OSS-Fuzz project, the OSV database is meant to provide automated, improved vulnerability triage for both developers and users of open source software.

Google pushes bug databases to get on the same page for open-source security
2021-06-24 13:00

Google on Thursday introduced a unified vulnerability schema for open source projects, continuing its current campaign to shore up the security of open source software. The as-yet-unnamed vulnerability interchange schema aspires to bridge gaps that make it difficult to connect current, fragmented vulnerability databases by providing a common interchange format.

'Set it and forget it' attitude to open-source software has become a major security problem, says Veracode
2021-06-22 21:30

There's a minefield of security problems bubbling under the surface of modern software, Veracode has claimed in its latest report, thanks to developers pulling third-party open-source libraries into their code bases - then never bothering to update them again. "The vast majority of today's applications use open source code. The security of a library can change quickly, so keeping a current inventory of what's in your application is crucial," Chris Eng, Vercode's chief research officer, said.