Security Leftovers
-
OpenSSF (Linux Foundation) ☛ OpenSSF publishes Mission, Vision, Values, and Strategy
The open source software (OSS) community is ever-changing, and the security of OSS rapidly evolves in parallel. This requires OpenSSF to regularly re-evaluate our focus and approach to intentionally improve OSS security. Today the Open Source Security Foundation (OpenSSF) releases an updated Mission, Vision, Values and Strategy (MVS) for the foundation as approved by the Governing Board.
> -
Security Week ☛ Sumo Logic Completes Investigation Into Recent Security Breach
Sumo Logic has completed its investigation into the recent security breach and found no evidence of impact to customer data.
-
Security Week ☛ CISA Offering Free Cybersecurity Services to Non-Federal Critical Infrastructure Entities
New CISA pilot program brings cutting-edge cybersecurity services to critical infrastructure entities that need support.
-
Security Week ☛ Canadian Military, Police Impacted by Data Breach at Moving Companies
Data breach at moving companies impacts Canadian government employees, and military and police personnel.
-
Scoop News Group ☛ Security trends public sector leaders are watching [Ed: More like a list of buzzwords and cargo cults]
Government and industry leaders share their thoughts on AI, supply chain security, open-source technology, and the greatest security risks to look out for.
-
OpenSSF (Linux Foundation) ☛ Sigstore: Simplifying Code Signing for Open Source Ecosystems [Ed: No, this is a pretext for censorship of applications on GNU/Linux desktops, laptops, and servers, brought to you by companies that work closely with the American government]
This month’s spotlight focuses on the Sigstore project.
-
Bruce Schneier ☛ Email Security Flaw Found in the Wild
Google’s Threat Analysis Group announced a zero-day against the Zimbra Collaboration email server that has been used against governments around the world.
TAG has observed four different groups exploiting the same bug to steal email data, user credentials, and authentication tokens. Most of this activity occurred after the initial fix became public on Microsoft's proprietary prison Microsoft's proprietary prison GitHub . To ensure protection against these types of exploits, TAG urges users and organizations to keep software fully up-to-date and apply security updates as soon as they become available.
The vulnerability was discovered in June. It has been patched...