Security News

StackRox Releases Open Source Tool for Finding Kubernetes Misconfigurations
2020-10-28 18:44

Container and Kubernetes security company StackRox on Wednesday announced the release of KubeLinter, an open source tool designed to help users identify misconfigurations in Kubernetes deployments. KubeLinter is a static analysis tool that checks YAML files, which store configuration data for Kubernetes applications, to ensure that security best practices are followed.

Open Source Management Firm FOSSA Raises $23 Million
2020-10-15 13:13

San Francisco, CA-based FOSSA - an open source management firm - has raised $23.2 million in a Series B funding round from Bain Capital Ventures, Canvas Ventures and Costanoa Ventures; bringing the total raised to $35 million. The company has simultaneously launched FOSSA Security Management, a product designed to help organizations secure their software supply chain - that is, the uncontrolled inclusion and use of open source software within their own software development.

Three best practices for responsible open source usage in the COVID-19 era
2020-10-15 05:00

Since well before the pandemic, software developers have leveraged open source code as a means to speed development cycles. Applications today are usually designed using hundreds of unique open source components, which then reside in their software and workspaces for years.

How to secure your open source supply chain
2020-10-09 17:09

Commentary: Open source has never been more popular, which means it's time to figure out how to effectively secure the open source you use. The world is made of software, and upwards of 99% of any software you use-open source or proprietary-includes open source components.

Fleek launches Space, an open source, private file storage and collaboration platform
2020-10-01 15:50

Fleek has announced the launch of Space, an open source, private file storage, sharing, and collaboration platform built on top of the distributed web stack, including Filecoin, IPFS, and Textile. Space's mission is to enable a fully private, peer to peer file and work collaboration experience for users.

Microsoft claims to love open source – this alleged leak of Windows XP code is probably not what it had in mind, tho
2020-09-25 18:39

The source code for Windows XP and other elderly Microsoft operating systems appears to have leaked online as the mega-corp's Ignite developer shindig came to an end. The source of the alleged code leak is unclear; a torrent for the archive popped up on internet armpit 4chan and contains what appears to be Windows XP Service Pack 1, as well as some other past-their-sell-by-date flavours of Microsoft's greatest hits.

Microsoft open-sources tool that enables continuous developer-driven fuzzing
2020-09-16 10:31

Microsoft has open-sourced OneFuzz, its own internal continuous developer-driven fuzzing platform, allowing developers around the world to receive fuzz testing results directly from their build system. Fuzzing is an automated software testing technique that involves entering random, unexpected, malformed and/or invalid data into a computer program.

Microsoft open-sources fuzzing tool it uses in-house to keep Windows so very secure
2020-09-16 06:33

Microsoft has open-sourced the fuzzing tool it uses to scour its own code for potential security vulnerabilities. The tool Microsoft has released is called "OneFuzz" and the company says it is "The testing framework used by Microsoft Edge, Windows, and teams across Microsoft is now available to developers around the world."

Microsoft Releases Open Source Fuzzing Framework for Azure
2020-09-15 16:17

Microsoft on Tuesday announced the release of Project OneFuzz, an open source fuzzing framework for Azure that the tech giant has been using internally for the past year to find and patch bugs. Project OneFuzz, which Microsoft describes as an extensible fuzz testing framework, is designed to address some of the challenges typically associated with fuzzing, enabling developers to conduct this type of testing themselves and allowing security engineers to focus on other important tasks.

RedCommander: Open source tool for red teaming exercises
2020-09-03 04:00

GuidePoint Security released a new open source tool that enables a red team to easily build out the necessary infrastructure. The RedCommander tool solves a major challenge for red teams around the installation and operationalization of infrastructure by combining automation scripts and other tools into a deployable package.