Tag: open-source
-
New Scoring System Helps Secure the Open Source AI Model Supply Chain
AI models from Hugging Face can contain similar hidden problems to OSS downloads from repositories such as GitHub. The post New Scoring System Helps S… First seen on securityweek.com Jump to article: www.securityweek.com/new-scoring-system-helps-secure-the-open-source-ai-model-supply-chain/
-
Open Source Software unbestreitbare Vorteile sowie Risiken
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/open-source-software-unbestreitbar-vorteile-risiken
-
Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems
Cybersecurity researchers have found that entry points could be abused across multiple programming ecosystems like PyPI, npm, Ruby Gems, NuGet, Dart P… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/supply-chain-attacks-exploit-entry.html
-
New AI Tool To Discover 0-Days At Large Scale With A Click Of A Button
Vulnhuntr, a static code analyzer using large language models (LLMs), discovered over a dozen zero-day vulnerabilities in popular open-source AI proje… First seen on gbhackers.com Jump to article: gbhackers.com/ai-0-day-discovery-tool/
-
Socket Raises $40 Million for Supply Chain Security Tech
Socket has raised $40 million in a Series B funding round to work on open source software supply chain security technology. The post Socket Raises $40… First seen on securityweek.com Jump to article: www.securityweek.com/socket-raises-40-million-for-supply-chain-security-tech/
-
Unknown threat actors exploit Roundcube Webmail flaw in phishing campaign
Hackers exploited a now-patched Roundcube flaw in a phishing attack to steal user credentials from the open-source webmail software. Researchers from … First seen on securityaffairs.com Jump to article: securityaffairs.com/170055/hacking/roundcube-flaw-exploited-in-phishing-attack.html
-
Talos discovers denialservice vulnerability in Microsoft Audio Bus; Potential remote code execution in popular open-source PLC
First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/talos-discovers-denial-of-service-vulnerability-in-microsoft-audio-bus-potential-remote-code-execution-in-popular-open-source-plc/
-
Aranya: Open-source toolkit to accelerate secure by design concepts
SpiderOak launched its core technology platform as an open-source project called Aranya. This release provides the same level of security as the compa… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/10/21/aranya-open-source-toolkit-secure-by-design/
-
Socket Accelerates Open-Source Security With $40M Series B
Socket Plans to Triple Headcount After Big Growth, Deliver Open-Source Tools Faster. A $40 million Series B investment will support Socket in rapidly … First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/socket-accelerates-open-source-security-40m-series-b-a-26576
-
GhostStrike: Open-source tool for ethical hacking
GhostStrike is an open-source, advanced cybersecurity tool tailored for ethical hacking and Red Team operations. It incorporates cutting-edge techniqu… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/10/17/ghoststrike-open-source-tool-ethical-hacking/
-
Forscher finden Schwachstellen in Passwort-Managern
Bei einer Open-Source-Codeanalyse hat das BSI die Passwort-Manager Vaultwarden und KeePass auf Sicherheitseigenschaften untersucht mit ungleichen Erge… First seen on heise.de Jump to article: www.heise.de/news/Passwort-Manager-BSI-berichtet-ueber-kritische-Schwachstellen-in-Vaultwarden-9982427.html
-
Qualcomm Urges OEMs to Patch Critical DSP and WLAN Flaws Amid Active Exploits
Qualcomm has rolled out security updates to address nearly two dozen flaws spanning proprietary and open-source components, including one that has com… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/qualcomm-urges-oems-to-patch-critical.html
-
Open-Source Entry Points Targeted for Supply Chain Compromise
First seen on scworld.com Jump to article: www.scworld.com/brief/open-source-entry-points-targeted-for-supply-chain-compromise
-
Attackers deploying red teaming tool for EDR evasion
Threat actors are leveraging the open-source EDRSilencer tool to evade endpoint detection and response systems, Trend Micro researchers have noticed. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/10/15/edr-evasion-edrsilencer/
-
Command-jacking used to launch malicious code on open-source platforms
First seen on scworld.com Jump to article: www.scworld.com/news/command-jacking-used-to-launch-malicious-code-on-open-source-platforms
-
Forscher finden teils kritische Schwachstellen in Passwort-Managern
Bei einer Open-Source-Codeanalyse hat das BSI die Passwort-Manager Vaultwarden und KeePass auf Sicherheitseigenschaften untersucht mit ungleichen Erge… First seen on heise.de Jump to article: www.heise.de/news/Passwort-Manager-BSI-berichtet-ueber-kritische-Schwachstellen-in-Vaultwarden-9982427.html
-
Sonatype Reports 156% Increase in OSS Malicious Packages
A new Sonatype report reveals a 156% surge in open source malware, with over 704,102 malicious packages identified since 2019, as OSS adoption continu… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/156-increase-in-oss-malicious/
-
Open Source Package Entry Points May Lead to Supply Chain Attacks
Entry points in packages across multiple programming languages are susceptible to exploitation in supply chain attacks. The post Open Source Package E… First seen on securityweek.com Jump to article: www.securityweek.com/open-source-package-entry-points-may-lead-to-supply-chain-attacks/
-
Malicious packages in open-source repositories are surging
First seen on cyberscoop.com Jump to article: cyberscoop.com/open-source-security-supply-chain-sonatype/
-
Navigating the Cybersecurity Risks of Shadow Open-Source GenAI
Generative AI is no doubt the leading frontier in AI. Models have captured attention and driven exciting use cases across industries with their abilit… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/10/navigating-the-cybersecurity-risks-of-shadow-open-source-genai/
-
Ubuntu Fixes Multiple PHP Vulnerabilities: Update Now
Multiple security vulnerabilities were identified in PHP, a widely-used open source general purpose scripting language which could compromise the secu… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/10/ubuntu-fixes-multiple-php-vulnerabilities-update-now/
-
Open Source MFA-Software in neuer Version – privacyIDEA 3.10 ermöglicht Offline-Authentifizierung mit Push-Token
First seen on security-insider.de Jump to article: www.security-insider.de/netknights-veroeffentlicht-privacyidea-3-10-a-c7a945373cc2108f4b3e08b497763c7b/
-
Supply Chain Attacks Exploit Entry Points in Python, npm, and Open-Source Ecosystems
Cybersecurity researchers have found that entry points could be abused across multiple programming ecosystems like PyPI, npm, Ruby Gems, NuGet, Dart P… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/supply-chain-attacks-exploit-entry.html
-
Open-Source Security Risks Rise as Usage Expands
First seen on scworld.com Jump to article: www.scworld.com/brief/open-source-security-risks-rise-as-usage-expands
-
Open-source security threats surge amid increasing usage
First seen on scworld.com Jump to article: www.scworld.com/brief/open-source-security-threats-surge-amid-increasing-usage
-
YARA: Open-source tool for malware research
YARA is a powerful tool designed primarily to aid malware researchers in identifying and categorizing malware samples, though its applications are bro… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/10/09/yara-open-source-tool-malware-research/
-
23 Top Open Source Penetration Testing Tools
Security professionals heavily rely on penetration testing tools for network security. Review and compare 23 of the best open-source pen testing tools… First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/applications/open-source-penetration-testing-tools/
-
How open source SIEM and XDR tackle evolving threats
Evolving threats require security solutions that match the sophistication of modern threats. Learn more about how Wazuh, the open-source XDR and SIEM,… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-open-source-siem-and-xdr-tackle-evolving-threats/
-
JFrog and GitHub unveil open source security integrations
Secure software specialist JFrog is working with code development service GitHub to integrate the onboard capabilities of its Software Supply Chain Pl… First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366609897/JFrog-and-GitHub-unveil-new-open-source-security-integrations
-
Open-Source Scanner Released to Detect CUPS Vulnerability
A new open-source scanner has been released to detect a critical vulnerability in the Common Unix Printing System (CUPS), explicitly targeting CVE-202… First seen on gbhackers.com Jump to article: gbhackers.com/open-source-scanner-released-to-detect-cups-vulnerability/

