Securing Open Source - Security Boulevard https://securityboulevard.com/category/editorial-calendar/securing-open-source/ The Home of the Security Bloggers Network Fri, 29 Mar 2024 17:19:26 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Securing Open Source - Security Boulevard https://securityboulevard.com/category/editorial-calendar/securing-open-source/ 32 32 133346385 PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ Fri, 29 Mar 2024 17:19:26 +0000 https://securityboulevard.com/?p=2013426 Closeup of person going “Shhh!”

Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup.

The post PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found appeared first on Security Boulevard.

]]>
2013426
China Steals Defense Secrets ‘on Industrial Scale’ https://securityboulevard.com/2024/03/china-steals-secrets-f5-connectwise-richixbw/ Mon, 25 Mar 2024 17:08:40 +0000 https://securityboulevard.com/?p=2012892 a PRC flag flies in a stiff breeze

UNC5174 ❤ UNC302: CVSS 10 and 9.8 vulnerabilities exploited by Chinese threat actor for People’s Republic.

The post China Steals Defense Secrets ‘on Industrial Scale’ appeared first on Security Boulevard.

]]>
2012892
Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys https://securityboulevard.com/2024/03/apple-m-gofetch-richixbw/ Fri, 22 Mar 2024 18:56:32 +0000 https://securityboulevard.com/?p=2012710 A green worm on a juicy red apple

GoFAIL: Researchers worm their way into broken cache-filling microcode in most Macs and iPads.

The post Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys appeared first on Security Boulevard.

]]>
2012710
EPA and White House Raise Alarm on Water Cybersecurity https://securityboulevard.com/2024/03/water-cybersecurity-richixbw/ Wed, 20 Mar 2024 16:22:50 +0000 https://securityboulevard.com/?p=2012433 Public washroom faucets

Iran and China fingered: Biden admin. chides governors: Water infra. lacks “even basic cybersecurity precautions.”

The post EPA and White House Raise Alarm on Water Cybersecurity appeared first on Security Boulevard.

]]>
2012433
Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date https://securityboulevard.com/2024/03/google-bug-bounty-vrp-richixbw/ Wed, 13 Mar 2024 16:57:09 +0000 https://securityboulevard.com/?p=2011800 Two stacks of money on top of a white table.

Wanna be a VRP VIP? Last year, $GOOG paid $10 million to ethical hackers for finding vulnerabilities.

The post Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date appeared first on Security Boulevard.

]]>
2011800
GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL https://securityboulevard.com/2024/02/github-repo-confusion-supply-chain-richixbw/ Thu, 29 Feb 2024 16:37:11 +0000 https://securityboulevard.com/?p=2010508 A fork, wrapped in delicious pasta

Forking hell: Scrotebots clone thousands of projects, injecting malware millions of times.

The post GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL appeared first on Security Boulevard.

]]>
2010508
CNCF Graduates Falco Project to Improve Linux Security https://securityboulevard.com/2024/02/cncf-graduates-falco-project-to-improve-linux-security/ Thu, 29 Feb 2024 15:00:20 +0000 https://securityboulevard.com/?p=2010494 Falco Edgio Salt Security APIs, organizations, Open APIs API CIS COVID-19 cybersecurity

The Cloud Native Computing Foundation (CNCF) announced today that Falco, an open source tool for defining security rules in Linux environments, has officially graduated.

The post CNCF Graduates Falco Project to Improve Linux Security appeared first on Security Boulevard.

]]>
2010494
US Will Fight Russian Disinformation — Hacks and Leaks and Deepfakes, Oh My! https://securityboulevard.com/2024/02/us-russian-disinformation-richixbw/ Tue, 27 Feb 2024 18:51:31 +0000 https://securityboulevard.com/?p=2010246 Coordinator of the Global Engagement Center Jamie Rubin at the U.S. Department of State in Washington, D.C., on January 3, 2023

Pay no attention to that man: State Dept. Global Engagement Centre chief James Rubin (pictured) follows the yellow brick road.

The post US Will Fight Russian Disinformation — Hacks and Leaks and Deepfakes, Oh My! appeared first on Security Boulevard.

]]>
2010246
PRC State Hacking: ‘Chinese Edward Snowden’ Spills I‑Soon Secrets in Huge Dump of TTPs https://securityboulevard.com/2024/02/china-hacking-i-soon-richixbw/ Thu, 22 Feb 2024 18:01:59 +0000 https://securityboulevard.com/?p=2009847 A PRC flag flies atop a metal flagpole

Underpaid, overworked and angry: Whistleblower in hacker contractor firm for Chinese government blows lid off tactics, techniques and procedures.

The post PRC State Hacking: ‘Chinese Edward Snowden’ Spills I‑Soon Secrets in Huge Dump of TTPs appeared first on Security Boulevard.

]]>
2009847
LockBit Takedown by Brits — Time for ‘Operation Cronos’ https://securityboulevard.com/2024/02/lockbit-op-cronos-richixbw/ Tue, 20 Feb 2024 14:04:30 +0000 https://securityboulevard.com/?p=2009323 This site is now under the control of The National Crime Agency of the UK, working in close cooperation with the FBI and the international law enforcement task force, “Operation Cronos”

RaaS nicked: 11-nation army led by UK eliminates ransomware-for-hire scrotes’ servers.

The post LockBit Takedown by Brits — Time for ‘Operation Cronos’ appeared first on Security Boulevard.

]]>
2009323