Security News

EU launches bug bounties on free and open source software
2019-01-07 11:28

After setting up a bug bounty program for VLC Media Player in late 2017, the European Commission (EC) has announced the launch of 14 new ones that will cover other free and open source software...

EU to offer nearly $1m in bug bounties for open-source software
2019-01-04 11:16

Rewards on 15 bug bounty programs start at $28,600 and include open source software such as KeePass, FileZilla, Drupal and VLC media player.

EU Offers Bug Bounties For 14 Open Source Projects
2019-01-02 15:59

As the bug bounty programs begin to roll out in January, security experts worry that the programs miss the mark on truly securing open source projects.

Open-source devs: Wget off your bloated festive behinds and patch this user cred-blabbing bug
2019-01-02 11:36

New year, new security fails, new CVE Happy New Year! Oh, and if you include GNU's wget utility in software you write, pull down the new version released on Boxing Day and push out updates to your users.…

Open Source Components: Managing the Risks
2018-12-21 21:48

Maria Loughlin of Veracode on Mitigation StrategiesOpen source components help developers build and deploy applications faster, but with increased speed comes greater risk. Maria Loughlin of...

Wipro and Alfresco expand partnership to offer open source based digital transformation capabilities
2018-12-11 02:00

Wipro Digital and Alfresco expanded global partnership to create, build and run open source based digital transformation programs for its clients, across the globe. The partnership will bring...

New Mac Malware Combines Open-Source Backdoor and Crypto-Miner
2018-12-10 16:04

A recently discovered piece of malware targeting Mac systems is a combination of two open-source programs, Malwarebytes security researchers warn.  read more

WhiteSource Bolt for GitHub: Free Open Source Vulnerability Management App for Developers
2018-12-05 11:48

Developers around the world depend on open source components to build their software products. According to industry estimates, open source components account for 60-80% of the code base in modern...

Unbound releases open source blockchain-crypto-mpc library for blockchain developers
2018-11-29 03:30

Unbound brings to the blockchain community a security solution via open source. The company’s blockchain-crypto-mpc library is available for free on Git Hub. It’s an open source library for...

Distributing Malware By Becoming an Admin on an Open-Source Project
2018-11-28 12:48

The module "event-steam" was infected with malware by an anonymous someone who became an admin on the project. Cory Doctorow points out that this is a clever new attack vector: Many open source...