Security Leftovers
-
CISA Releases Four Industrial Control Systems Advisories | CISA
CISA released four Industrial Control Systems (ICS) advisories on January 17, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
-
CISA Updates Best Practices for Mapping to MITRE ATT-CK® | CISA
Today, CISA updated Best Practices for MITRE ATT&CK® Mapping. The MITRE ATT&CK® framework is a lens through which network defenders can analyze adversary behavior and, as CISA Executive Assistant Director Eric Goldstein noted in his June 2021 blog post on the framework, it directly supports “robust, contextual bi-directional sharing of information to help strengthen the security of our systems, networks, and data.” CISA highly encourages the cybersecurity community to use the framework because it provides a common language for threat actor analysis.
-
Security updates for Tuesday [LWN.net]
Security updates have been issued by Debian (tor) and SUSE (python-setuptools, python36-setuptools, and tor).
-
Git 2.39.1 (and more) released [Ed: LWN links to a Microsoft site that shills an attack on Git... instead of the original from Git itself]
Git 2.39.1 has been released with a set of security fixes; there are also updated versions of many older Git releases available.
-
Consider Open Source Software While Evaluating The Security Of Cloud Applications
The pace of software development is accelerating. Devops teams are under more pressure to launch products rapidly, and they are able to do so in part because of open-source software (OSS) tools.
According to estimates, OSS now makes up between 80 and 90 percent of all current software. However, OSS produces a big surface area that needs to be controlled because there are millions of packages published anonymously that developers utilise to build software, even though it has been a fantastic accelerator for software development.