Misguided Security Theatre

-
Attack on German companies through NPM packages [Ed: Microsoft is transmitting malware again, but guess who the media will blame (perpetrators and victims, not the carrier)]
A new portion of malicious NPM packages created for targeted attacks on the German companies Bertelsmann, Bosch, Stihl and DB Schenker have been uncovered. The attack uses the dependency mixing method, which manipulates the intersection of dependency names in public and internal repositories. In publicly available applications, attackers find traces of accessing internal NPM packages downloaded from corporate repositories, whereupon they place packages with the same names and newer version numbers in the public NPM repository. If, when building, internal libraries are not explicitly linked in the settings to their repository, the npm package manager considers the public repository to be a higher priority and downloads the package prepared by the attacker.
-
Linux, OpenSSF Champion Plan to Improve Open Source Security [Ed: Look what companies are in this thing. They relay everyone's data to the NSA. That itself is a data breach.]
-
Open Source Leaders Push WH for Security Action [Ed: Microsoft is not "Open Source Leader"]
The Linux Foundation and the Open Source Software Security Foundation (OpenSSF) brought together over 90 executives from 37 companies and government leaders from the NSC, ONCD, CISA, NIST, DOE, and OMB on Thursday to reach a consensus on key actions to take to improve the resiliency and security of open-source software.
-
White House joins OpenSSF and the Linux Foundation in securing open-source software [Ed: Steven Vaughan-Nichols is paid to have become a corporate writer for corporate front group, with his occasional defamation against the community]
-
The Linux Foundation and Open Source Software Security Foundation (OpenSSF) Gather Industry and Government Leaders for Open Source Software Security Summit II [Ed: Linux Foundation quotes Jim Zemlin on security like Zemlin is a technical person. He is not. Charade, theatre, kakistocracy for FUD. If you are a Linux user, Linux Foundation does not represent you. If you are a Microsoft fan, then maybe Linux Foundation does speak for you.]
-
How much will it cost to secure open-source software? OpenSSF says $147.9M | VentureBeat [Ed: Linux Foundation is a source of FUD against Linux. Well, look who controls the organisation. This report cites Microsoft proxies as "sources" regarding "Open Source" security...]
In recent years there have been multiple vulnerabilities in open-source software that have been exploited, leaving organizations of all sizes at risk.
-

- Login or register to post comments
Printer-friendly version- 3141 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago