Venafi: Four Ways Open Source Libraries Leave Organizations at Risk
Summary
SALT LAKE CITY--(BUSINESS WIRE)--Organizations are becoming increasingly dependent on open source libraries (OSLs) to develop code for software and websites. However, Jing Xie, senior threat intelligence researcher for machine identity protection leader Venafi, warns that the growing reliance on OSLs for software development leaves many companies vulnerable to trust-based attacks. Cybercriminals use trust attacks to maliciously manipulate and insert code into open source libraries, taking advantage of organizations’ dependence on them. “In addition, we encourage organizations to track internal OSL code, recording library releases and any problems,” Xie concluded. Venafi protects machine identity types by orchestrating cryptographic keys and digital certificates for SSL/TLS, IoT, mobile and SSH.