CISA warns about unsafe open source projects

'Most' projects are open memory corruption security flaws

clock • 2 min read
CISA warns about unsafe open source projects

CISA, the US Cybersecurity & Infrastructure Security Agency, has warned that the majority of critical open-source projects contain key memory-related security flaws.

In a new report [PDF] released this week, the Agency, together with counterpart organisations in Australia and Canada, examined 172 critical open source projects identified by the Open Source Secur...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

Threats and Risks

14 million internet-facing servers are vulnerable, says Qualys

clock 01 July 2024 • 2 min read
The prosumer problem: Explaining IT to users who think they get it

Management

‘There’s a consumer expectation on an enterprise platform’

clock 26 June 2024 • 3 min read
CISA confirms Windows privilege escalation flaw has been exploited

Threats and Risks

US cybersecurity agency also added a recently disclosed Google Pixel flaw to its list of exploited vulnerabilities

clock 17 June 2024 • 1 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Open Source

Nutanix: We're staying true to open source

Nutanix: We're staying true to open source

HCI vendor promises to support CNCF projects 'across all environments'

John Leonard
clock 23 May 2024 • 4 min read
'Levelling up cybersecurity is a team effort,' says Jacob DePriest of GitHub

'Levelling up cybersecurity is a team effort,' says Jacob DePriest of GitHub

But security starts with developers, and AI isn’t going to replace them

Penny Horwood
clock 09 May 2024 • 5 min read
Redis shifts to dual source-available licensing model

Redis shifts to dual source-available licensing model

CSPs hosting Redis solutions will now be required to enter into commercial agreements

clock 22 March 2024 • 3 min read