Open source software has worked its way into the vast majority of organizations around the world. That makes open source security a universal business issue, and a new report from security firm Veracode presents some very troubling findings.
Software supply chain attacks have spiked significantly year-over-year. Sonatype logged over 245,032 malicious packages in open source projects available to public download in 2023, double the number seen from 2019 to 2022. In total, one in eight open source downloads poses a risk.
GitHub's State of the Octoverse report has found that open source vulnerabilities are continuing to go undetected for as long as four years on average and developers have an average patch time of roughly a month.
OpenAI is promising enhanced security safeguards and a pause on development for a period of "reinforcement" after internal findings indicate its upcoming model Astra has crossed "critical cybersecurity capability" thresholds.
OpenAI has attributed ChatGPT outages to a targeted distributed denial of service (DDoS) attack. A suspected Russian hacktivist group Anonymous Sudan has claimed responsibility.
What OpenAI described as a "short-lived experiment" is now over, as the company will no longer allow Google and other search engines to index certain types of ChatGPT conversations.
A complaint in Poland alleges GDPR violations by ChatGPT in the areas of lawful basis for data processing, data access, fairness, transparency and personal privacy.
Italy was one of the first EU nations to take OpenAI and ChatGPT to task over data privacy violations, even banning the app from the country briefly, and it has now issued the bloc's first GDPR fine of this nature to the company.
The Trump administration's "AI Action Plan" will likely shape every aspect of AI development going forward, and OpenAI has submitted its own set of proposals to the White House, one that unsurprisingly calls for light AI regulations.
A recent change to its EU terms of service and an email sent out to some ChatGPT users indicates that OpenAI is now formally under the watch of the Irish DPC in terms of its responsibility to EU data privacy regulations.










