Security News

EU Offers Bug Bounties For 14 Open Source Projects
2019-01-02 15:59

As the bug bounty programs begin to roll out in January, security experts worry that the programs miss the mark on truly securing open source projects.

Open-source devs: Wget off your bloated festive behinds and patch this user cred-blabbing bug
2019-01-02 11:36

New year, new security fails, new CVE Happy New Year! Oh, and if you include GNU's wget utility in software you write, pull down the new version released on Boxing Day and push out updates to your users.…

Open Source Components: Managing the Risks
2018-12-21 21:48

Maria Loughlin of Veracode on Mitigation StrategiesOpen source components help developers build and deploy applications faster, but with increased speed comes greater risk. Maria Loughlin of...

Wipro and Alfresco expand partnership to offer open source based digital transformation capabilities
2018-12-11 02:00

Wipro Digital and Alfresco expanded global partnership to create, build and run open source based digital transformation programs for its clients, across the globe. The partnership will bring...

New Mac Malware Combines Open-Source Backdoor and Crypto-Miner
2018-12-10 16:04

A recently discovered piece of malware targeting Mac systems is a combination of two open-source programs, Malwarebytes security researchers warn.  read more

WhiteSource Bolt for GitHub: Free Open Source Vulnerability Management App for Developers
2018-12-05 11:48

Developers around the world depend on open source components to build their software products. According to industry estimates, open source components account for 60-80% of the code base in modern...

Unbound releases open source blockchain-crypto-mpc library for blockchain developers
2018-11-29 03:30

Unbound brings to the blockchain community a security solution via open source. The company’s blockchain-crypto-mpc library is available for free on Git Hub. It’s an open source library for...

Distributing Malware By Becoming an Admin on an Open-Source Project
2018-11-28 12:48

The module "event-steam" was infected with malware by an anonymous someone who became an admin on the project. Cory Doctorow points out that this is a clever new attack vector: Many open source...

OpenStack Foundation board expands mission to host new open source projects
2018-11-15 02:30

The board of directors of the OpenStack Foundation (OSF) adopted a resolution advancing a new governance framework supporting the organization’s investment in emerging use cases for OpenStack and...

The Linux Foundation launches Ceph Foundation to advance open source storage
2018-11-12 16:05

The Linux Foundation and over 30 global technology leaders are forming a new foundation to support the Ceph open source project community. The Ceph project develops a unified distributed storage...