Legitimate vulnerabilities could face delays before they are reviewed and fixed.
Hidden dependencies, social engineering attacks, and the complexity of foundation models can all contribute tothe insecure use of open-source software in 2025. Open-source software is common ...
Google has paused product vulnerability submissions to its open-source bug bounty program after a surge in automated reports overwhelmed the process. The Open Source Software Vulnerability Reward ...
Two years ago, the joint government-private sector response to the Log4j vulnerability that spawned 800,000 attacks worldwide led to the Enduring Security Framework for federal agencies adopting open ...
The Linux Foundation, a nonprofit organization enabling mass innovation through open source, today announced the release of “Census III of Free and Open Source Software—Application Libraries” (Census ...
Earlier this year, a Microsoft developer realized that someone had inserted a backdoor into the code of open source utility XZ Utils, which is used in virtually all Linux operating systems. The ...
As cyber threats evolve, addressing known vulnerabilities quickly and consistently is increasingly important. OSERA provides ...
In February, The Linux Foundation’s Open Source Security Foundation (OpenSSF) initiated the Open Source Project Security Baseline (OSPS Baseline) to establish minimum security requirements for ...
Since Russian troops invaded Ukraine more than three years ago, Russian technology companies and executives have been widely sanctioned for supporting the Kremlin. That includes Vladimir Kiriyenko, ...
In the world of software development, the debate between open-source and proprietary software has been ongoing for years. While both have their merits, open-source software is increasingly being ...
Amidst ongoing reports of AI agents wreaking havoc on online infrastructure, chipmaker Nvidia is rallying tech companies to use its new open-source tool for AI security. OpenShell, one of the Nvidia’s ...