SlideShare a Scribd company logo
Open Source Insight:
Securing IoT, Atlanta Ransomware Attack,
Congress on Cybersecurity
By Fred Bals, Senior Content Strategist
The Black Duck blog and Open Source Insight become
part of the Synopsys Software Integrity blog in early
April. You’ll still get the latest open source security and
license compliance news, insights, and opinions you’ve
come to expect, plus the latest software security trends,
news, tips, best practices, and thought leadership every
week. Don’t delay, subscribe today! Now on to this
week’s open source security and cybersecurity news.
Cybersecurity News This Week
• What you should know about the recent Atlanta
ransomware attack
• Innovation may be outpacing security in cars
• Comment: securing IoT devices before (and after) they
ship
• Mozilla's radical open-source move helped rewrite rules
of tech
• Synopsys on source code security sensitivities
• Digging deeper into the GitHub security alerts numbers
Open Source News Stories
• Black Duck On-Demand and Synopsys: running the walk
• U.K. threatens to force IoT security by design
• Report to Congress on cybersecurity
• Cybersecurity agency warns of ‘extremely dangerous’
risks of 5G technology
• Drupal issues highly critical patch: over 1M sites
vulnerable
Open Source News Stories
What you should know about the
recent Atlanta ransomware attack
via Synopsys Software Integrity: The city of Atlanta has become
one of the latest victims of a ransomware attack. The attack is
believed to be the result of the SamSam malware that has
compromised various healthcare, government, and educational
systems over the past several years.
Innovation may be outpacing security in cars
via EE News: As the UK government’s
car cybersec guidelines recognize,
innovation may be outpacing security in
cars. Automotive OEMs therefore need
to adopt a security strategy that goes
beyond the obvious.
Comment: securing IoT devices before (and after) they
ship
via Electronics Weekly: “When it comes to IoT
devices, you need to consider a security
architecture risk analysis, to find weaknesses that
might occur as the result of business logic or
component interactions," writes Art Dahnert of
Synopsys.
Mozilla's radical open-source move helped rewrite rules
of tech
via CNET: A gamble 20 years ago unleashed the source code for the
browser that became Firefox. The approach is now core to
Facebook, Google and everyone else.
Synopsys on source code security
sensitivities
via Computer Weekly: Senior security strategist at
Synopsys Taylor Armerding further suggests that a
2016 Forrester Research study commissioned by
Synopsys set a baseline example of five hours of
work to fix a defect in the coding/development
stage. But, he reminds us, finding and fixing that
same defect in the final testing phase would take
five to seven times longer.
Digging deeper into the GitHub
security alerts numbers
via Black Duck blog: The GitHub numbers are
interesting; specifically the numbers 450,000
resolved vulnerabilities out of 4,000,000 discovered.
We know that the National Vulnerability
Database (NVD) doesn’t contain anywhere near that
many disclosures, so how are they arriving at that
number? GitHub is likely taking the number of
vulnerabilities and applying it to all the forks and
versions within GitHub using that code. That makes
their metric an interesting one, as I said, but masks the
real problem — knowing which code has been patched
in which fork. Consumers of open source projects may
themselves create a fork, and that fork could very
easily be outside of GitHub’s visibility.
via Black Duck blog: As outlined previously, the Synopsys culture is extraordinarily
well-aligned with the critical elements of our audit business: Maintaining trust through
integrity, being hyper-responsive through execution and leading the market with
superior services and tools. And all that with the same passion that drives my team
every day. To be fair, those initial impressions were based on Synopsys’s “talking the
talk.” However, a few months of “walking the walk” have only reinforced my conviction
that we have a great home. Actually, these months have felt more like running the
walk!
Black Duck On-Demand and Synopsys: running the walk
via Synopsys Software Integrity: Securing the Internet of Things
(IoT) seems like an endless reality version of “Mission Impossible”—
really impossible. Many have tried—with lists of best practices and
standards, exhortations, and warnings—but none has succeeded.
Still, the U.K. government, in a policy paper titled Secure by
Design released earlier this month, says it is also going to try, with a
13-point Code of Practice that it will force all IoT stakeholders to follow
if they don’t do it voluntarily.
U.K. threatens to force IoT security by
design
via USNI News: Cybersecurity has been gaining
attention as a national issue for the past decade.
During this time, the country has witnessed cyber
incidents affecting both public and private sector
systems and data. These incidents have included
attacks in which data was stolen, altered, or access to
it was disrupted or denied. The frequency of these
attacks, and their effects on the U.S. economy,
national security, and people’s lives have driven
cybersecurity issues to the forefront of congressional
policy conversations. This report provides an overview
of selected cybersecurity concepts and a discussion of
cybersecurity issues that are likely to be of interest
during the 115th Congress.
Report to Congress on cybersecurity
via EURACTIV: Superfast 5G mobile networks come with “extremely
dangerous” cybersecurity risks, the EU cybersecurity agency ENISA
has warned. 5G is expected to become available to European
consumers by 2025.
Cybersecurity agency warns of ‘extremely
dangerous’ risks of 5G technology
via Threatpost: Drupal released a patch for a “highly
critical” flaw in versions 6, 7 and 8 of its CMS platform
that could allow an attacker to take control of an affected
site simply by visiting it. Drupal also warned an
unprivileged and untrusted attacker could modify or
delete data hosted on affected CMS platforms.
Drupal issues highly critical
patch: over 1M sites vulnerable
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cybersecurity

More Related Content

PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
PPTX
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Black Duck by Synopsys
 
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
PDF
Software Security Assurance for DevOps
Black Duck by Synopsys
 
PPT
The Case for Continuous Open Source Management
Black Duck by Synopsys
 
PDF
Buyer and Seller Perspectives on Open Source in Tech Contracts
Black Duck by Synopsys
 
PPTX
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
Software Security Assurance for DevOps
Black Duck by Synopsys
 
The Case for Continuous Open Source Management
Black Duck by Synopsys
 
Buyer and Seller Perspectives on Open Source in Tech Contracts
Black Duck by Synopsys
 
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 

What's hot (20)

PPTX
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Black Duck by Synopsys
 
PDF
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
Black Duck by Synopsys
 
PDF
DevSecOps: The Open Source Way
Black Duck by Synopsys
 
PDF
Open Source Security for Newbies - Best Practices
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
PDF
The Intersection Between Open Source and Cybersecurity
Black Duck by Synopsys
 
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
PPTX
Winning the Cage-Match: How to Successfully Navigate Open Source Software iss...
Black Duck by Synopsys
 
PPTX
Software Security Assurance for Devops
Jerika Phelps
 
PPTX
Keynote - Lou Shipley
Jerika Phelps
 
PPTX
Making the Strategic Shift to Open Source at Fujitsu Network Communication
Black Duck by Synopsys
 
PPTX
Open Source: The Legal & Security Implications for the Connected Car
Jerika Phelps
 
PPTX
Welcome & The State of Open Source Security
Jerika Phelps
 
PPTX
Open Source: The Legal & Security Implications for the Connected Car
Black Duck by Synopsys
 
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
PDF
Leveraging Black Duck Hub to Maximize Focus - Entersekt's approach to automat...
Jerika Phelps
 
PPTX
Software Security Assurance for DevOps
Black Duck by Synopsys
 
PDF
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Black Duck by Synopsys
 
PPTX
Leveraging Black Duck Hub to Maximize Focus - Entersekt’s Approach to Empower...
Black Duck by Synopsys
 
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Black Duck by Synopsys
 
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
Black Duck by Synopsys
 
DevSecOps: The Open Source Way
Black Duck by Synopsys
 
Open Source Security for Newbies - Best Practices
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
The Intersection Between Open Source and Cybersecurity
Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
Winning the Cage-Match: How to Successfully Navigate Open Source Software iss...
Black Duck by Synopsys
 
Software Security Assurance for Devops
Jerika Phelps
 
Keynote - Lou Shipley
Jerika Phelps
 
Making the Strategic Shift to Open Source at Fujitsu Network Communication
Black Duck by Synopsys
 
Open Source: The Legal & Security Implications for the Connected Car
Jerika Phelps
 
Welcome & The State of Open Source Security
Jerika Phelps
 
Open Source: The Legal & Security Implications for the Connected Car
Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
Leveraging Black Duck Hub to Maximize Focus - Entersekt's approach to automat...
Jerika Phelps
 
Software Security Assurance for DevOps
Black Duck by Synopsys
 
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Black Duck by Synopsys
 
Leveraging Black Duck Hub to Maximize Focus - Entersekt’s Approach to Empower...
Black Duck by Synopsys
 
Ad

Similar to Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cybersecurity (20)

PPTX
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
DOCX
Final Research Project - Securing IoT Devices What are the Challe.docx
voversbyobersby
 
PPTX
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
PDF
INSECURE Magazine - 35
Felipe Prado
 
PPTX
Open Source Insight: Hospital, Medical Devices, Banking, and Automotive Cyber...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Auto Security & Hackers, Killer Robots, & Containers Gon...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Black Duck by Synopsys
 
PPTX
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Top Picks for Black Hat, GDPR & Open Source Webinar, ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
PPTX
Open Source Insight: Synopsys Moves into Open Source Security with Black Duck...
Black Duck by Synopsys
 
PPTX
A Wake-Up Call for IoT
Ahmed Banafa
 
PPTX
Codes of Ethics and the Ethics of Code
Mark Underwood
 
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Black Duck by Synopsys
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
Final Research Project - Securing IoT Devices What are the Challe.docx
voversbyobersby
 
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
INSECURE Magazine - 35
Felipe Prado
 
Open Source Insight: Hospital, Medical Devices, Banking, and Automotive Cyber...
Black Duck by Synopsys
 
Open Source Insight: Auto Security & Hackers, Killer Robots, & Containers Gon...
Black Duck by Synopsys
 
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Black Duck by Synopsys
 
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
Open Source Insight: Top Picks for Black Hat, GDPR & Open Source Webinar, ...
Black Duck by Synopsys
 
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Black Duck by Synopsys
 
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
Black Duck by Synopsys
 
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
Open Source Insight: Synopsys Moves into Open Source Security with Black Duck...
Black Duck by Synopsys
 
A Wake-Up Call for IoT
Ahmed Banafa
 
Codes of Ethics and the Ethics of Code
Mark Underwood
 
Ad

More from Black Duck by Synopsys (13)

PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
PDF
Open Source Rookies and Community
Black Duck by Synopsys
 
PDF
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
PPTX
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
PPTX
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
Open Source Rookies and Community
Black Duck by Synopsys
 
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 

Recently uploaded (20)

PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 

Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cybersecurity

  • 1. Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cybersecurity By Fred Bals, Senior Content Strategist
  • 2. The Black Duck blog and Open Source Insight become part of the Synopsys Software Integrity blog in early April. You’ll still get the latest open source security and license compliance news, insights, and opinions you’ve come to expect, plus the latest software security trends, news, tips, best practices, and thought leadership every week. Don’t delay, subscribe today! Now on to this week’s open source security and cybersecurity news. Cybersecurity News This Week
  • 3. • What you should know about the recent Atlanta ransomware attack • Innovation may be outpacing security in cars • Comment: securing IoT devices before (and after) they ship • Mozilla's radical open-source move helped rewrite rules of tech • Synopsys on source code security sensitivities • Digging deeper into the GitHub security alerts numbers Open Source News Stories
  • 4. • Black Duck On-Demand and Synopsys: running the walk • U.K. threatens to force IoT security by design • Report to Congress on cybersecurity • Cybersecurity agency warns of ‘extremely dangerous’ risks of 5G technology • Drupal issues highly critical patch: over 1M sites vulnerable Open Source News Stories
  • 5. What you should know about the recent Atlanta ransomware attack via Synopsys Software Integrity: The city of Atlanta has become one of the latest victims of a ransomware attack. The attack is believed to be the result of the SamSam malware that has compromised various healthcare, government, and educational systems over the past several years.
  • 6. Innovation may be outpacing security in cars via EE News: As the UK government’s car cybersec guidelines recognize, innovation may be outpacing security in cars. Automotive OEMs therefore need to adopt a security strategy that goes beyond the obvious.
  • 7. Comment: securing IoT devices before (and after) they ship via Electronics Weekly: “When it comes to IoT devices, you need to consider a security architecture risk analysis, to find weaknesses that might occur as the result of business logic or component interactions," writes Art Dahnert of Synopsys.
  • 8. Mozilla's radical open-source move helped rewrite rules of tech via CNET: A gamble 20 years ago unleashed the source code for the browser that became Firefox. The approach is now core to Facebook, Google and everyone else.
  • 9. Synopsys on source code security sensitivities via Computer Weekly: Senior security strategist at Synopsys Taylor Armerding further suggests that a 2016 Forrester Research study commissioned by Synopsys set a baseline example of five hours of work to fix a defect in the coding/development stage. But, he reminds us, finding and fixing that same defect in the final testing phase would take five to seven times longer.
  • 10. Digging deeper into the GitHub security alerts numbers via Black Duck blog: The GitHub numbers are interesting; specifically the numbers 450,000 resolved vulnerabilities out of 4,000,000 discovered. We know that the National Vulnerability Database (NVD) doesn’t contain anywhere near that many disclosures, so how are they arriving at that number? GitHub is likely taking the number of vulnerabilities and applying it to all the forks and versions within GitHub using that code. That makes their metric an interesting one, as I said, but masks the real problem — knowing which code has been patched in which fork. Consumers of open source projects may themselves create a fork, and that fork could very easily be outside of GitHub’s visibility.
  • 11. via Black Duck blog: As outlined previously, the Synopsys culture is extraordinarily well-aligned with the critical elements of our audit business: Maintaining trust through integrity, being hyper-responsive through execution and leading the market with superior services and tools. And all that with the same passion that drives my team every day. To be fair, those initial impressions were based on Synopsys’s “talking the talk.” However, a few months of “walking the walk” have only reinforced my conviction that we have a great home. Actually, these months have felt more like running the walk! Black Duck On-Demand and Synopsys: running the walk
  • 12. via Synopsys Software Integrity: Securing the Internet of Things (IoT) seems like an endless reality version of “Mission Impossible”— really impossible. Many have tried—with lists of best practices and standards, exhortations, and warnings—but none has succeeded. Still, the U.K. government, in a policy paper titled Secure by Design released earlier this month, says it is also going to try, with a 13-point Code of Practice that it will force all IoT stakeholders to follow if they don’t do it voluntarily. U.K. threatens to force IoT security by design
  • 13. via USNI News: Cybersecurity has been gaining attention as a national issue for the past decade. During this time, the country has witnessed cyber incidents affecting both public and private sector systems and data. These incidents have included attacks in which data was stolen, altered, or access to it was disrupted or denied. The frequency of these attacks, and their effects on the U.S. economy, national security, and people’s lives have driven cybersecurity issues to the forefront of congressional policy conversations. This report provides an overview of selected cybersecurity concepts and a discussion of cybersecurity issues that are likely to be of interest during the 115th Congress. Report to Congress on cybersecurity
  • 14. via EURACTIV: Superfast 5G mobile networks come with “extremely dangerous” cybersecurity risks, the EU cybersecurity agency ENISA has warned. 5G is expected to become available to European consumers by 2025. Cybersecurity agency warns of ‘extremely dangerous’ risks of 5G technology
  • 15. via Threatpost: Drupal released a patch for a “highly critical” flaw in versions 6, 7 and 8 of its CMS platform that could allow an attacker to take control of an affected site simply by visiting it. Drupal also warned an unprivileged and untrusted attacker could modify or delete data hosted on affected CMS platforms. Drupal issues highly critical patch: over 1M sites vulnerable