Security News

Babuk ransomware readies 'shut down' post, plans to open source malware
2021-04-29 17:54

After just a few months of activity, the operators of Babuk ransomware briefly posted a short message about their intention to quit the extortion business after having achieved their goal. Earlier today, the Babuk ransomware gang said in a message titled "Hello World 2" on their leak site that they had achieved their goal and decided to shut down the operation.

Sysdig raises $188M to invest in continued innovation in its open source foundation
2021-04-28 23:00

This round follows strong growth in 2020, a rapidly expanding customer base, a thriving open source community, and a massive growth opportunity with containers and cloud. Sysdig significantly expanded the total addressable market beyond container and Kubernetes security to include cloud security with the addition of continuous cloud security posture management in 2021.

Adobe Releases Open Source Anomaly Detection Tool "OSAS"
2021-04-27 13:29

Adobe this week announced the open-source availability of 'One-Stop Anomaly Shop', a new tool designed to help security teams discover anomalies in datasets. Building on previous research, white papers, and other projects from Adobe's Security Intelligence Team, OSAS out-of-the-box allows researchers to experiment with datasets, control data processing and feature combining, and help identify a solution for detecting security threats.

SniperPhish: An all-in-one open-source phishing toolkit
2021-04-26 05:00

SniperPhish is an all-in-one open-source phishing toolkit that pentesters and other security professionals can use for setting up and executing email and web-based spear phishing campaigns. "The idea to develop SniperPhish came to me in a period during which the company I previously worked with did many social engineering assessments. Most of the assessment included phishing campaigns, which means creating and hosting phishing websites and crafting email campaigns. The available tools had certain limitations and were not very effective at simultaneously tracking data from the phishing emails and websites," security consultant Gem George, the tool's creator, told Help Net Security.

How the open source community helped firms investigate their network activity following SolarWinds
2021-04-20 14:45

The open source community delivered vital help to companies affected by the SolarWinds attack. One underappreciated facet of the wide-ranging scandal that has engulfed much of the U.S. government and hundreds of major companies involves the powerful role the open source community played in helping enterprises respond to the crisis, according to Greg Bell, co-founder and CSO of cybersecurity company Corelight.

Infection Monkey: Open source tool allows zero trust assessment of AWS environments
2021-04-16 04:15

Guardicore unveiled new zero trust assessment capabilities in Infection Monkey, its open source breach and attack simulation tool. Available immediately, security professionals will now be able to conduct zero trust assessments of AWS environments to help identify the potential gaps in an organization's AWS security posture that can put data at risk.

Linux Foundation Research to broaden understanding of open source ecosystem and impact
2021-04-16 00:00

The Linux Foundation announced Linux Foundation Research, a new division that will broaden the understanding of open source projects, ecosystem dynamics, and impact, with never before seen insights on the efficacy of open source collaboration as a means to solve many of the world's pressing problems. Through a series of research projects and related content, Linux Foundation Research will leverage the Linux Foundation's vast repository of data, tools, and communities across industry verticals and technology horizontals.

Open source security, license compliance, and maintenance issues are pervasive in every industry
2021-04-15 05:30

The report highlights trends in open source usage within commercial applications and provides insights to help commercial and open source developers better understand the interconnected software ecosystem they are part of. It also details the pervasive risks posed by unmanaged open source, including security vulnerabilities, outdated or abandoned components, and license compliance issues.

Logz.io announces support for OpenSearch project, an open source fork of Elasticsearch and Kibana
2021-04-14 23:00

Logz.io announced its support for the OpenSearch project, the new fork of the Elasticsearch and Kibana codebases recently unveiled by AWS. Logz.io has been working closely with AWS and several other partners to help define the future path and roadmap for the project. Logz.io is confident that the community-based nature of the project will ensure users continue to have a secure, high-quality, fully open source based search and analytics suite with a rich roadmap of new and innovative functionality.

How open source security flaws pose a threat to organizations
2021-04-13 16:09

How do such products fare on security? Though the community-based approach toward open source means that security flaws should be identified quickly, patching those flaws and applying the patches is another matter. In a report released Tuesday, design automation company Synopsys looked at commercial applications that use open source code to see how they dealt with security flaws.