Security News

Zip Slip Flaw Affects Thousands of Open-Source Projects
2018-06-06 20:58

An exploit allows attackers to remotely overwrite archive files with their own content, and from there pivot to achieving remote command execution on the machine.

Cryptocurrency: A Gold Mine For Open-Source Intelligence
2018-06-04 10:18

Expert Says Virtual Currency Systems Leak Useful Data To Track CriminalsExperts have long warned that bitcoin is not as private as it appears. The very design of bitcoin, as well as some other...

Open Source Tool From FireEye Helps Detect Malicious Logins
2018-05-29 19:16

FireEye has released GeoLogonalyzer, an open source tool that can help organizations detect malicious logins based on geolocation and other data. Many organizations need to allow their employees...

The percentage of open source code in proprietary apps is rising
2018-05-22 12:05

The number of open source components in the codebase of proprietary applications keeps rising and with it the risk of those apps being compromised by attackers leveraging vulnerabilities in them,...

Enterprise IT shouldn't blame open source for their own poor security practices
2018-05-16 19:02

Open source vulnerabilities will often get disclosed earlier than those in managed software, but its up to IT to apply the patches.

Flaws in Open Source Components Pose Increasing Risk to Apps: Study
2018-05-15 15:29

Open source components have been increasingly used by developers, but failure to patch vulnerabilities in this type of software can pose serious risks. read more

Asylo Open-Source Framework Tackles TEEs for Cloud
2018-05-07 17:14

The idea is to use trusted execution environments to build trust across various cloud-related use cases, including 5G, virtual network functions (VNFs), blockchain and more.

Microsoft Patches Critical Flaw in Open Source Container Library
2018-05-03 05:04

Microsoft informed users on Wednesday that an update for the Windows Host Compute Service Shim library patches a critical remote code execution vulnerability. read more

Slack Releases Open Source Secure Development Lifecycle Tool
2018-05-01 05:01

Team collaboration solutions provider Slack last week announced that one of the secure development lifecycle (SDL) tools used internally by the company has been released as open source. read more

Open-source library for improving security of AI systems
2018-04-18 19:50

IBM researchers have created the Adversarial Robustness Toolbox, an open-source library to help researchers improve the defenses of real-world AI systems. Attacks against neural networks have...