A laptop user typing at their keyboard. (Getty Images) Malicious packages in open-source repositories are surging The open-source ecosystem is being overrun by malicious packages, a new report from Sonatype finds. Oct 10, 2024 By Christian Vasquez
Close-up server detail with KVM switches. (Getty Images) Printer bug sends researchers into uproar, affects major Linux distros The vulns would allow attackers to run any commands on targeted computers without user knowledge. But it would take a lot of work to get to that… Sep 26, 2024 By Christian Vasquez
Broken RGB screen close-up with a missing pixel on the bottom right. (Getty Images) Zero trust: How the ‘Jia Tan’ hack complicated open-source software The volunteers that maintain open-source software have always been knocked around by the tech community. The Jia Tan hack made it all so much worse. Aug 15, 2024 By Christian Vasquez
(Getty Images) White House to study open source software in critical infrastructure The Biden administration is looking to understand just how widespread open-source software is in critical infrastructure. Aug 9, 2024 By Christian Vasquez
A bridge at night. (Getty Images) Researchers uncover rare, difficult-to-exploit OpenSSH vulnerability The OpenSSH bug represents the latest high-profile vulnerability to affect the open-source software ecosystem. Jul 2, 2024 By Christian Vasquez
Aisle with messy cables in a server room. (Getty Images) Six-year old bug will likely live forever in Lenovo, Intel products A report from Binarly finds that a silently patched bug in a popular web server will likely live on in several major end-of-life products. Apr 11, 2024 By Christian Vasquez
A man in blue clothing holds a mask behind his bask in this photo illustration. (Getty Images) Supply chain attack sends shockwaves through open-source community An operation to undermine the software utility XZ Utils has exposed the fragile human foundations on which the modern internet is built. Apr 5, 2024 By Christian Vasquez
The White House. (Getty Images) ONCD releases report on the adoption of memory-safe languages The effort is aimed at reducing one of the most common vulnerabilities that plague software. Feb 26, 2024 By Christian Vasquez
Computer language script and coding on screen with a man reflection in the background. (Getty Images) White House releases report on securing open-source software End-of-year report highlights work from Open-Source Software Security Initiative and targets going forward. Jan 30, 2024 By Christian Vasquez
(Getty Images) CISA urges vendors to get rid of default passwords Cybersecurity officials also issued new guidance on open source software through secure-by-design practices. Dec 15, 2023 By Christian Vasquez