Open Source: It’s All Fun and Games Until Millions of People Have Their Data Stolen

Photo credit Flickr/Alan Levine

A new survey of 5,558 IT professionals reveals a staggering amount of enterprise-level practices that may very well lead to the next Equifax-type data breach. Published by Sonatype (in partnership with Cloudbees, Carnegie Mellon’s Software Engineering Institute, Signal Sciences, 9th Bit, and Twistlock), the 2019 DevSecOps Community Survey paints a rather unsettling picture of how a large number of enterprises are handling cybersecurity concerns, particularly when it comes to their use of open source components.

Dependencies: It’s Not Just Your Code You Need to Secure

Original article published by Cristián Rojas at Hackmetrix Blog

The EQUIFAX USA event of 2017 put a spotlight an under-considered aspect of software security: it’s not just our code that we need to secure. The facts of the case are widely known, but its cause? Not so much. Little is said about the fact that this leak would not have taken place if the developers of the EQUIFAX application had upgraded their Apache Struts web framework to a more secure version.