Security News

A new Linux Foundation open source signing tool could make secure software supply chains universal
2021-03-11 15:13

Sigstore could eliminate the headaches associated with current software signing technology through public ledgers. The Linux Foundation, in partnership with Red Hat, Google and Purdue University, has announced a new digital signing project, potentially eliminating many of the headaches that come with securing open source software, files, images and binaries.

Akash MAINNET 2 decentralized open-source cloud now available
2021-03-10 02:00

Akash Network, a project out of Overclock Labs, confirmed the successful launch of Akash MAINNET 2, the first open-source cloud and the only viable decentralized cloud alternative to centralized cloud providers like Amazon Web Services, Google Cloud, and Microsoft Azure. Akash MAINNET 2 empowers developers to break free from the limitations of traditional cloud infrastructure, and accelerates growth and scale in the blockchain ecosystem by enabling developers and companies to decentralize their cloud infrastructure, deploying applications faster, more efficiently, and at lower cost.

Infrastructure modernization remains the biggest use case for enterprise open source
2021-03-02 17:11

Infrastructure modernization remains the most important use case for enterprise open source for the third consecutive year, according to Red Hat's newly released State of Enterprise Open Source Report. "The two are closely related because new applications are a big part of digital transformation. Taken together, they clearly demonstrate that organizations are using enterprise open source for strategic purposes, not just for infrastructure 'plumbing,'" the report said.

Microsoft Releases Open Source Resources for Solorigate Threat Hunting
2021-02-26 13:42

Microsoft on Thursday announced the open source availability of CodeQL queries that it used during its investigation into the SolarWinds attack. The company has released the source code of CodeQL queries, which it used to analyze its code at scale and identify any code-level indicators of compromise associated with Solorigate.

You’ve got millions of open-source software components to choose from... and so do cybercriminals
2021-02-17 20:00

Perhaps the most troubling aspect of this tale is that this was the seventh such malicious package found on npm within a month, a stark illustration of the effort that cybercriminals are making to insert themselves into the open source software supply chain. According to Weeks, anywhere from 10 per cent to 40 percent of open source software components developers are downloading have known vulnerabilities.

Open Source Vulnerabilities database: Nice idea but too many Google-shaped hoops to jump through at present
2021-02-11 09:30

Hands On. Google has big ambitions for its new Open Source Vulnerabilities database, but getting started requires a Google Cloud Platform account and there are other obstacles that may add friction to adoption. The company wants to see more discipline and checks in critical open-source software, and revealed that it maintains its own private repositories for many projects to guard against compromised code or newly committed vulnerabilities.

IPCDump: Open-source tool for tracing interprocess communication on Linux
2021-02-11 04:00

Guardicore released IPCDump, a new open source tool for tracing interprocess communication on Linux. The tool covers most interprocess communication mechanisms, including pipes, fifos, signals, Unix sockets, loopback-based networking, and pseudoterminals, and is useful for debugging multi-process applications and gaining transparency into how they communicate with one another in their IT environment.

Codefresh promotes Dan Garfield to Chief Open Source Officer
2021-02-09 23:45

Dan Garfield, who joined founder and CEO Raziel Tabib to launch Codefresh in 2016, has been promoted to Chief Open Source Officer. In his new role, Garfield will lead the realignment of Codefresh as an open source company, with engineering time dedicated to open source contributions and providing enterprise solutions on top of open source projects for their customers.

Google Launches Database for Open Source Vulnerabilities
2021-02-08 14:52

Google last week announced the launch of OSV, which the internet giant has described as a vulnerability database and triage infrastructure for open source projects. OSV should make it easier for the users of open source software to find out which vulnerabilities impact them.

Open-source tool BlobHunter helps pinpoint public Azure blobs that might contain sensitive files
2021-02-08 12:07

CyberArk researchers have released BlobHunter, an open-source tool organizations can use to discover Azure blobs containing sensitive files they have inadvertently made public. Despite access to the files uploaded to cloud storages being by default private and cloud providers constantly sharing and reiterating best practices for securing them, misconfigurations happen all the time, making potentially sensitive information publicly accessible to anyone who knows how to find it.