CISA warns about unsafe open source projects

'Most' projects are open memory corruption security flaws

clock • 3 min read
CISA warns about unsafe open source projects

CISA, the US Cybersecurity & Infrastructure Security Agency, has warned that the majority of critical open-source projects contain key memory-related security flaws.

In a new report [PDF] released this week, the Agency, together with counterpart organisations in Australia and Canada, examined 172 critical open source projects identified by the Open Source Secur...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
SolarWinds patches eight critical flaws in Access Rights Manager software

Threats and Risks

Disclosure raises fresh security concerns

clock 21 July 2024 • 3 min read
Malicious Python packages found exfiltrating user data to Telegram bot

Threats and Risks

Appears to be part of a wider operation by crime gang based in Iraq, say Checkmarx researchers

clock 15 July 2024 • 2 min read
New threat group CRYSTALRAY seen using variety of off-the-shelf tools to steal credentials

Threats and Risks

Sysdig researchers have been following the group since February

clock 11 July 2024 • 2 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Open Source

OpenUK launches The Open Manifesto

OpenUK launches The Open Manifesto

Three asks of the new government to support open-source technology to boost economy

Penny Horwood
clock 09 July 2024 • 6 min read
Nutanix: We're staying true to open source

Nutanix: We're staying true to open source

HCI vendor promises to support CNCF projects 'across all environments'

John Leonard
clock 23 May 2024 • 4 min read
'Levelling up cybersecurity is a team effort,' says Jacob DePriest of GitHub

'Levelling up cybersecurity is a team effort,' says Jacob DePriest of GitHub

But security starts with developers, and AI isn’t going to replace them

Penny Horwood
clock 09 May 2024 • 5 min read