article thumbnail

Socket lands $4.6M to audit and catch malicious open source code

TechCrunch

Most of the world’s software relies on open source code that’s written by developers who publish their work for anyone to use. Aboukhadijeh founded Socket earlier this year alongside a team of fellow open source maintainers who have seen firsthand some of the worst software supply chain attacks in the wild.

article thumbnail

10 things to watch out for with open source gen AI

CIO

Even if you don’t have the training data or programming chops, you can take your favorite open source model, tweak it, and release it under a new name. According to Stanford’s AI Index Report, released in April, 149 foundation models were released in 2023, two-thirds of them open source.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

China-Backed ‘UNC5174’ Using Open Source Tools in Stealthy Attacks 

Ooda Loop

A Chinese state-sponsored actor, UNC5147, has been using open source tools to attack its victims. The attacker has been using a new command and control (C2) tool, the Vshell, in its campaign since January, as well as a variant of Snowlight malware.

article thumbnail

Google Play is an ‘order of magnitude’ better at blocking malware

The Parallax

During a month that’s seen Android malware new and old plague the world’s most popular mobile operating system, Google says its Play Store is becoming more civilized and less like the Wild West. You have a lower probability of being infected by malware from Play than being hit by lightning,” Ahn says. READ MORE ON ANDROID SECURITY.

Malware 184
article thumbnail

WhiteSource Acquires Diffend to Secure Open Source Supply Chains

DevOps.com

WhiteSource this week announced it has acquired Diffend as part of an expended effort to discover malware that has been deliberately injected into open source software by a contributor acting in bad faith. The post WhiteSource Acquires Diffend to Secure Open Source Supply Chains appeared first on DevOps.com.

article thumbnail

Stoked — Manifesting Innovation in Shared Threat Intelligence

Palo Alto Networks

Rodney Mullen About half way through his lecture he drew similarities between skaters, hackers and the open-source community. And yet, like skateboarding, open-source software (OSS) also carries substantial risks and vulnerabilities. But first, what exactly is open-source software? It’s a beautiful thing.

article thumbnail

Protestware on the rise: Why developers are sabotaging their own code

TechCrunch

His areas of interest include open source software security, malware analysis, data breaches, and scam investigations. A developer can, on a whim, change their mind and do whatever they want with their open source code that, most of the time, anyway comes “as is” without any warranty. Share on Twitter.