SlideShare a Scribd company logo
Open Source Insight:
IoT Security, Tech Due Diligence, and Software Security Training
Fred Bals | Senior Content Writer/Editor
Cybersecurity News This Week
A grab-bag of open source security and cybersecurity news is in this
week’s edition of Open Source Insight. Is “many eyeballs” not
enough? Some security researchers think Linus’ Law doesn’t work
anymore. Black Duck by Synopsys kicks off a new video series with
MITRE IoT expert, Bob Martin. Learn how open source tech due
diligence helped one company close a deal securely. Should “Privacy
Day” be renamed to “Lack of Privacy” day? Plus, an eye-catching
infographic on how too little software security training is putting many
companies at risk.
• Is the BSD OS dying? Some security
researchers think so
• Duck Talks: 20 Billion Reasons for IoT
Security
• What does DevOps do in 2018?
• When Good Containers Go Bad
• When Software is the Company, Tech Due
Diligence is Critical
Open Source News
More Open Source News
• Connected Vehicles: Could Open Source Software
Pose Cyber Security Risks?
• Privacy still an uphill climb on Data Privacy Day
• GDPR: Deadline looms but businesses still aren't
ready
• The 6 Biggest Challenges Facing DevOps
• Infographic: A lack of software security training puts
companies at risk
via CSO: Too few eyeballs on code is a security
issue as vulnerabilities go unreported and
unpatched. Can FreeBSD, OpenBSD, and NetBSD
survive?
Is the BSD OS dying? Some security
researchers think so
Duck Talks: 20 Billion Reasons for
IoT Security
via Black Duck blog (video): Bob Martin from MITRE is a
leading expert on Internet of Things security. His presentation “20
Billion Reasons for IoT Security” covered a range of topics
around IoT. He sat down with us at FLIGHT to discuss how we
should be thinking about IoT, what security concerns might
surface as these industries evolve, and how to manage the risks
appropriately.
via InfoSecurity: Open source will continue to
drive healthy competition. The days when
companies were afraid of using open source
software are pretty much long gone now. Almost
every recent successful online business has
been built on top of freely available software.
What does DevOps do in 2018?
When Good Containers Go Bad
via Sysbus (Germany): Data center operators face challenges in
terms of infrastructure complexity and application speed, while at
the same time addressing compliance with global governance
regulations, such as the General Data Protection Regulation
(GDPR).
via Black Duck blog: The need to understand open
source risk in a recent acquisition was the driver for
the leading provider of patient medical financing
options, AccessOne, to reach out to Black Duck by
Synopsys for an open source code audit.
When Software is the Company, Tech Due
Diligence is Critical
Connected Vehicles: Could Open Source
Software Pose Cyber Security Risks?
via Software Testing News: Vehicle manufacturers need to adopt
a cyber security approach to that addresses not only obvious
exposures in their car’s software but also the hidden vulnerabilities
that could be introduced by open source components in that
software.
via Synopsys Software Integrity blog: You could make
a pretty solid case that a decade later, this year’s
observance, on Sunday, ought to be called Lack of
Privacy Day. That’s even with the looming
implementation in May of the General Data Protection
Regulation (GDPR) by the European Union — a move
toward privacy protections explained in detail by
Synopsys security consultant Stephen Gardner in a blog
post earlier this month.
Privacy still an uphill climb on
Data Privacy Day
GDPR: Deadline looms but businesses
still aren't ready
via ZDNet: The UK government is warning organisations that they
must prepare for new data protection laws now — or face the
consequences when they come into force.
via InformationWeek: The DevOps field now
embraces millions of software developers and
entrepreneurs who have adjusted their teams and
core philosophies to fall in line with the DevOps
vision. However, these guiding principles are still
evolving, and if you want to remain relevant and
agile in 2018, you’ll need to evolve with them.
The 6 Biggest Challenges Facing DevOps
Infographic: A lack of software security
training puts companies at risk
via Synopsys Software Integrity blog: An old proverb states that if
you give a man a fish, you feed him for a day; but, if you teach a man to
fish, you feed him for life. Software security training aligns very well with
this proverb. The majority of developers don’t come equipped with
security skills. In fact 95% of software security bugs are caused by just
19 programming flaws. And yet, only 2.8% of undergraduate computer
science programs require a security course.
Subscribe
Stay up to date on open source security and cybersecurity –
subscribe to our blog today.
Open Source Insight:IoT Security, Tech Due Diligence, and Software Security Training

More Related Content

What's hot (20)

PPTX
Smart Tech = Smart Organizations : Building Smarter Organizations
Rick Huijbregts
 
PPT
Tomorrow is so Yesterday
Lisa Harvey
 
PPTX
Living In a World of Data Exploitation - CPDP 2017
Frederike Kaltheuner
 
PPTX
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
PDF
Io t whitepaper_5_15_17
Aravindharamanan S
 
PDF
Blockchain 101 for Financial Services
Appian
 
PDF
The Secure Path to Value in the Cloud by Denny Heaberlin
Cloud Expo
 
PPTX
Software-Defined Security: The New School of Security Designed for DevOps
VMware Tanzu
 
PDF
Close the Security Gaps of a Remote Workforce
jlieberman07
 
PPTX
Innovate for Cyber Resilience
accenture
 
PDF
Why a new cybersecurity paradigm for IoTs
Réda Berrehili
 
PDF
Smart Cities Day 1 Secure Cities
4 All of Us
 
PDF
How to earn 15% interest (and understand stablecoins)
Sean O'Connor
 
PPTX
FS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data Assets
Puneet Kukreja
 
PDF
The Growing U.S. IT Productivity Gap
Citrix
 
PPTX
2015 KSU So You Want To Be in Cyber Security
Phil Agcaoili
 
PDF
Cisco Internet of Things and WC june 2014
Vasily Ryzhonkov
 
PDF
Igor Mate Tetra Pak Fostering Digital Businesses By Personal Data Protection ...
CIO Edge
 
PDF
June 2016 Worldwide Netskope Cloud Report
Netskope
 
PPTX
Internet of things ecosystem: The quest for value
Deloitte United States
 
Smart Tech = Smart Organizations : Building Smarter Organizations
Rick Huijbregts
 
Tomorrow is so Yesterday
Lisa Harvey
 
Living In a World of Data Exploitation - CPDP 2017
Frederike Kaltheuner
 
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
Io t whitepaper_5_15_17
Aravindharamanan S
 
Blockchain 101 for Financial Services
Appian
 
The Secure Path to Value in the Cloud by Denny Heaberlin
Cloud Expo
 
Software-Defined Security: The New School of Security Designed for DevOps
VMware Tanzu
 
Close the Security Gaps of a Remote Workforce
jlieberman07
 
Innovate for Cyber Resilience
accenture
 
Why a new cybersecurity paradigm for IoTs
Réda Berrehili
 
Smart Cities Day 1 Secure Cities
4 All of Us
 
How to earn 15% interest (and understand stablecoins)
Sean O'Connor
 
FS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data Assets
Puneet Kukreja
 
The Growing U.S. IT Productivity Gap
Citrix
 
2015 KSU So You Want To Be in Cyber Security
Phil Agcaoili
 
Cisco Internet of Things and WC june 2014
Vasily Ryzhonkov
 
Igor Mate Tetra Pak Fostering Digital Businesses By Personal Data Protection ...
CIO Edge
 
June 2016 Worldwide Netskope Cloud Report
Netskope
 
Internet of things ecosystem: The quest for value
Deloitte United States
 

Similar to Open Source Insight: IoT Security, Tech Due Diligence, and Software Security Training (20)

PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
PPTX
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
PPTX
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
PDF
Webinar – Streamling Your Tech Due Diligence Process for Software Assets
Synopsys Software Integrity Group
 
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
PDF
Infosecurity Europe - Infographic
Synopsys Software Integrity Group
 
PPTX
Solnet dev secops meetup
pbink
 
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
PPTX
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
PPTX
Open Source Insight: Synopsys Moves into Open Source Security with Black Duck...
Black Duck by Synopsys
 
PDF
Webinar–That is Not How This Works
Synopsys Software Integrity Group
 
PDF
Webinar–2019 Open Source Risk Analysis Report
Synopsys Software Integrity Group
 
PDF
Why Data Security Should Be a Priority in Your Software Development Strategy?
Mars Devs
 
PPTX
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
Webinar – Streamling Your Tech Due Diligence Process for Software Assets
Synopsys Software Integrity Group
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
Infosecurity Europe - Infographic
Synopsys Software Integrity Group
 
Solnet dev secops meetup
pbink
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
Open Source Insight: Synopsys Moves into Open Source Security with Black Duck...
Black Duck by Synopsys
 
Webinar–That is Not How This Works
Synopsys Software Integrity Group
 
Webinar–2019 Open Source Risk Analysis Report
Synopsys Software Integrity Group
 
Why Data Security Should Be a Priority in Your Software Development Strategy?
Mars Devs
 
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
Black Duck by Synopsys
 
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 
Ad

More from Black Duck by Synopsys (18)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
PDF
Open Source Rookies and Community
Black Duck by Synopsys
 
PDF
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
PPTX
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Black Duck by Synopsys
 
PDF
Buyer and Seller Perspectives on Open Source in Tech Contracts
Black Duck by Synopsys
 
PDF
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
Black Duck by Synopsys
 
PPTX
Making the Strategic Shift to Open Source at Fujitsu Network Communication
Black Duck by Synopsys
 
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
Open Source Rookies and Community
Black Duck by Synopsys
 
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Black Duck by Synopsys
 
Buyer and Seller Perspectives on Open Source in Tech Contracts
Black Duck by Synopsys
 
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
Black Duck by Synopsys
 
Making the Strategic Shift to Open Source at Fujitsu Network Communication
Black Duck by Synopsys
 
Ad

Recently uploaded (20)

PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
LOOPS in C Programming Language - Technology
RishabhDwivedi43
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
DOCX
Python coding for beginners !! Start now!#
Rajni Bhardwaj Grover
 
PPTX
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
PDF
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
PDF
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
PDF
“NPU IP Hardware Shaped Through Software and Use-case Analysis,” a Presentati...
Edge AI and Vision Alliance
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
PPTX
AI Penetration Testing Essentials: A Cybersecurity Guide for 2025
defencerabbit Team
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PDF
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PDF
Staying Human in a Machine- Accelerated World
Catalin Jora
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
LOOPS in C Programming Language - Technology
RishabhDwivedi43
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
Python coding for beginners !! Start now!#
Rajni Bhardwaj Grover
 
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
Using FME to Develop Self-Service CAD Applications for a Major UK Police Force
Safe Software
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
“NPU IP Hardware Shaped Through Software and Use-case Analysis,” a Presentati...
Edge AI and Vision Alliance
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
AI Penetration Testing Essentials: A Cybersecurity Guide for 2025
defencerabbit Team
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
Staying Human in a Machine- Accelerated World
Catalin Jora
 

Open Source Insight: IoT Security, Tech Due Diligence, and Software Security Training

  • 1. Open Source Insight: IoT Security, Tech Due Diligence, and Software Security Training Fred Bals | Senior Content Writer/Editor
  • 2. Cybersecurity News This Week A grab-bag of open source security and cybersecurity news is in this week’s edition of Open Source Insight. Is “many eyeballs” not enough? Some security researchers think Linus’ Law doesn’t work anymore. Black Duck by Synopsys kicks off a new video series with MITRE IoT expert, Bob Martin. Learn how open source tech due diligence helped one company close a deal securely. Should “Privacy Day” be renamed to “Lack of Privacy” day? Plus, an eye-catching infographic on how too little software security training is putting many companies at risk.
  • 3. • Is the BSD OS dying? Some security researchers think so • Duck Talks: 20 Billion Reasons for IoT Security • What does DevOps do in 2018? • When Good Containers Go Bad • When Software is the Company, Tech Due Diligence is Critical Open Source News
  • 4. More Open Source News • Connected Vehicles: Could Open Source Software Pose Cyber Security Risks? • Privacy still an uphill climb on Data Privacy Day • GDPR: Deadline looms but businesses still aren't ready • The 6 Biggest Challenges Facing DevOps • Infographic: A lack of software security training puts companies at risk
  • 5. via CSO: Too few eyeballs on code is a security issue as vulnerabilities go unreported and unpatched. Can FreeBSD, OpenBSD, and NetBSD survive? Is the BSD OS dying? Some security researchers think so
  • 6. Duck Talks: 20 Billion Reasons for IoT Security via Black Duck blog (video): Bob Martin from MITRE is a leading expert on Internet of Things security. His presentation “20 Billion Reasons for IoT Security” covered a range of topics around IoT. He sat down with us at FLIGHT to discuss how we should be thinking about IoT, what security concerns might surface as these industries evolve, and how to manage the risks appropriately.
  • 7. via InfoSecurity: Open source will continue to drive healthy competition. The days when companies were afraid of using open source software are pretty much long gone now. Almost every recent successful online business has been built on top of freely available software. What does DevOps do in 2018?
  • 8. When Good Containers Go Bad via Sysbus (Germany): Data center operators face challenges in terms of infrastructure complexity and application speed, while at the same time addressing compliance with global governance regulations, such as the General Data Protection Regulation (GDPR).
  • 9. via Black Duck blog: The need to understand open source risk in a recent acquisition was the driver for the leading provider of patient medical financing options, AccessOne, to reach out to Black Duck by Synopsys for an open source code audit. When Software is the Company, Tech Due Diligence is Critical
  • 10. Connected Vehicles: Could Open Source Software Pose Cyber Security Risks? via Software Testing News: Vehicle manufacturers need to adopt a cyber security approach to that addresses not only obvious exposures in their car’s software but also the hidden vulnerabilities that could be introduced by open source components in that software.
  • 11. via Synopsys Software Integrity blog: You could make a pretty solid case that a decade later, this year’s observance, on Sunday, ought to be called Lack of Privacy Day. That’s even with the looming implementation in May of the General Data Protection Regulation (GDPR) by the European Union — a move toward privacy protections explained in detail by Synopsys security consultant Stephen Gardner in a blog post earlier this month. Privacy still an uphill climb on Data Privacy Day
  • 12. GDPR: Deadline looms but businesses still aren't ready via ZDNet: The UK government is warning organisations that they must prepare for new data protection laws now — or face the consequences when they come into force.
  • 13. via InformationWeek: The DevOps field now embraces millions of software developers and entrepreneurs who have adjusted their teams and core philosophies to fall in line with the DevOps vision. However, these guiding principles are still evolving, and if you want to remain relevant and agile in 2018, you’ll need to evolve with them. The 6 Biggest Challenges Facing DevOps
  • 14. Infographic: A lack of software security training puts companies at risk via Synopsys Software Integrity blog: An old proverb states that if you give a man a fish, you feed him for a day; but, if you teach a man to fish, you feed him for life. Software security training aligns very well with this proverb. The majority of developers don’t come equipped with security skills. In fact 95% of software security bugs are caused by just 19 programming flaws. And yet, only 2.8% of undergraduate computer science programs require a security course.
  • 15. Subscribe Stay up to date on open source security and cybersecurity – subscribe to our blog today.