Executives concerned about secure applications but developers are not confident that they are writing secure code or the security of third party modules.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A new study from Tanium indicates that businesses overwhelmingly believe that cyber resilience and business resilience is fundamental, but have a great deal of trouble achieving it.
Thousands of companies using popular NPM libraries have just learned that the hidden price of free software is that the open source developer may withdraw their consent at any time.
Open source software has worked its way into the vast majority of organizations around the world. That makes open source security a universal business issue, and a new report from security firm Veracode presents some very troubling findings.
While it might be tempting to view a major vulnerability as an indication of open source somehow being deficient, the reality is far from that. Open source software is not more or less secure than commercial software, and in reality, most commercial software either includes or runs on open source technologies.
Software supply chain attacks have spiked significantly year-over-year. Sonatype logged over 245,032 malicious packages in open source projects available to public download in 2023, double the number seen from 2019 to 2022. In total, one in eight open source downloads poses a risk.
GitHub's State of the Octoverse report has found that open source vulnerabilities are continuing to go undetected for as long as four years on average and developers have an average patch time of roughly a month.
OpenAI is promising enhanced security safeguards and a pause on development for a period of "reinforcement" after internal findings indicate its upcoming model Astra has crossed "critical cybersecurity capability" thresholds.
OpenAI has attributed ChatGPT outages to a targeted distributed denial of service (DDoS) attack. A suspected Russian hacktivist group Anonymous Sudan has claimed responsibility.
What OpenAI described as a "short-lived experiment" is now over, as the company will no longer allow Google and other search engines to index certain types of ChatGPT conversations.










