ICS/OT New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding A new project aims to make it easier for PLC programmers to implement secure coding practices by cataloging useful files and functions from each... Eduard KovacsOctober 25, 2023
Vulnerabilities Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers. Eduard KovacsOctober 13, 2023
Government US Government Releases Security Guidance for Open Source Software in OT, ICS CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS. Ionut ArghireOctober 11, 2023
Identity & Access Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol The Linux Foundation has announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security. Eduard KovacsOctober 5, 2023
Network Security Silverfort Open Sources Lateral Movement Detection Tool Silverfort has released the source code for its lateral movement detection tool LATMA, to help identify and analyze intrusions. Ionut ArghireOctober 2, 2023
Application Security CISA Releases Open Source Software Security Roadmap CISA details its plan to support the open source software ecosystem and secure the use of open source software within the federal government. Ionut ArghireSeptember 13, 2023
Supply Chain Security SBOMs – Software Supply Chain Security’s Future or Fantasy? If after eighteen months, meaningful use of SBOMs is unachievable, we need to ask what needs to be done to fulfill Biden’s executive order. Kevin TownsendJune 5, 2023
Application Security NCC Group Releases Open Source Tools for Developers, Pentesters NCC Group announces new open source tools for finding hardcoded credentials and for distributing cloud workloads. Ionut ArghireMay 26, 2023
Application Security Red Hat Pushes New Tools to Secure Software Supply Chain Red Hat rolls out a new suite of tools and services to help mitigate vulnerabilities across every stage of the modern software supply chain. Ryan NaraineMay 23, 2023
Application Security OpenSSF Receives $5 Million for Open Source Software Security Project OpenSSF has added four new members and is receiving $5 million in funding for its Alpha-Omega open source software security project. Ionut ArghireMay 11, 2023
Data Protection Satori Releases Open Source Data Permissions Scanner for Enterprises Data security firm Satori has released a free and open source tool designed to help organizations find out who has access to what data... Eduard KovacsMay 4, 2023
Supply Chain Security Top 10 Security, Operational Risks From Open Source Code Endor Labs has introduced an OWASP-style listing of the most important or impactful risks inherent in the use of open source software (OSS). Kevin TownsendMarch 1, 2023