Open-Source Security: How Digital Infrastructure Is Built on a House of Cards

General News

Summary

The advisory warned companies that hackers, including state-sponsored advanced persistent threat (APT) actors, continue to exploit organizations that failed to patch the Log4Shell vulnerability, gaining unfettered access to proprietary systems. Simply put, its primary beneficiaries save the cost of developing or purchasing proprietary code by using open source instead, allowing them to invest limited resources in other valuable endeavors. While Google and Intel might have the resources and security maturity to demand machine-readable SBOMs and regularly scan databases for new vulnerabilities that impact their systems, there are countless small businesses using open source that cannot. The Open Source Technology Improvement Fund (OSTIF) was founded recently to provide free security auditing services to open-source projects and continues to grow. CISA defines critical infrastructure as industry sectors “so vital to the United States that [its] incapacity or destruction would have a debilitating impact on our physical or economic security or public health or safety.” Efforts should target the open-source projects that share those features.

Classifications

industries
Fintech & Banking
applications
General BI

AskAI Classifications

Labels
Cloud Infrastructure Software Cybersecurity Software Developer Tools

Linked Companies

Cloudflare
$1B+
Google LLC
$100M to $250M
Protecode
$1M to $5M
Red Hat
$1B+
Webflow, Inc
$100M to $250M
OpenShift
$1M to $5M
Snyk
$250M to $500M