SlideShare ist ein Scribd-Unternehmen logo
1 von 16
Open Source Insight:
Paraskevidekatriaphobia, Web APIs,
Jeep Hacking, More Equifax Woes
By Fred Bals | Senior Content Writer/Editor
Cybersecurity News This Week
On this Friday the 13th, the paraskevidekatriaphobia edition of Open
Source Insight delves into scary software exploits like jeep hacking
and data breaches. October is Cybersecurity Awareness Month, but
how aware and cybersecure are the businesses holding our personal
data? Black Duck joins forces with Google to clean up software supply
chains. If it’s not one thing it’s two things for Equifax. Ten steps you
need to take now to comply with GDPR. And Black Duck’s new Hub
plugin to Visual Studio IDE.
• Jeep Hacking & the Security of Things:
Flight 2017
• It’s Cybersecurity Awareness Month. Do You
Feel More Cybersecure and Aware Yet?
• Google and Friends Open-Source Grafeas
API to Clean up Software Supply Chains
• Black Duck & Google Grafeas: Improving
Container Visibility & Security
• The Silver Lining on the Equifax Breach
Open Source News
More Open Source News
• Web APIs Are the New Open Source Software
• Equifax Takes Down Webpage After Report Of New
Cybersecurity 'Situation'
• Cyber Security Is A Business Risk, Not Just An IT
Problem
• 10 Steps Enterprises Need to Take to Comply with
GDPR
• Be Agile & Decrease Costs with Black Duck’s Visual
Studio IDE Plugin
via Black Duck blog (Kiara White): In less than a
month, FLIGHT 2017, Black Duck's user conference, will return to
the Seaport Hotel and World Trade Center in Boston,
Massachusetts. We're delighted to announce that notorious Jeep
hackers Chris Valasek and Dr. Charlie Miller will take the stage as
keynote speakers. They'll address the future of the security of
things, and the challenges and opportunities we'll face as machine
learning, autonomous vehicles, big data and the Internet of Things
converge to build products and services.
Jeep Hacking & the Security of Things:
Flight 2017
It’s Cybersecurity Awareness Month. Do You
Feel More Cybersecure and Aware Yet?
via Future Tense: October is Cybersecurity Awareness Month.
Maybe the best one can do to raise awareness is to tell fellow
internet users to read the news.
via Silicon Angle: The internet giant’s long list
of friends includes JFrog Ltd., Red Hat Inc., IBM
Corp., Black Duck Software Inc., Twistlock Ltd,
Aqua Security Software Ltd. and CoreOS Inc.
They’ve all joined forces to create a new
application programming interface
called Grafeas, which is an open source initiative
to “define a uniform way for auditing and
governing the modern software supply chain.”
Google and Friends Open-Source Grafeas
API to Clean up Software Supply Chains
Black Duck & Google Grafeas: Improving
Container Visibility & Security
via Black Duck blog (Sheryl Sage and Neal Goldman): Black Duck
has been working with Google on the development and testing of the
Grafeas API over the last year, and we are continuing to work with
Google to deliver on the vision of improving visibility into open source
vulnerabilities before they hit production environments. Because many
of our customers want to see the results of open source scans in the
consoles of their primary development and deployment tools, you’ll
continue to see improvements in the Black Duck’s integrations with
Google Cloud Platform, including the Grafeas API and other new
Google platform features.
via CSO: If we seize this moment to get people
more engaged in understanding and acting upon
information security and protection, it may turn
out that the Equifax breach was a good thing
after all.
The Silver Lining on the Equifax Breach
Web APIs Are the New Open Source Software
via Black Duck blog (David Znidarsic |
Founder & President of Stairstep
Consulting): If you are relaxing because you
have your open source usage under control,
beware. There is another increasingly
common type of ungoverned third-party code
that your engineers are using in your
products: Web APIs.
via NPR: On Thursday, Equifax explained
that it had taken the page offline after Ars
Technica, a website covering technology and
other topics, pointed out a potential issue:
fraudulent Adobe Flash updates.
Equifax Takes Down Webpage After Report Of New
Cybersecurity 'Situation'
Cyber Security Is A Business Risk,
Not Just An IT Problem
via Forbes: Gone are the days when companies could pass the
headaches of cyber security to the IT department, as it has become
more of a business issue too. This is especially important as
businesses are more digitized, meaning they are exposed to an
increasing number of threats if they do not manage the risk of security
properly.
via Information week: If your organization
doesn't have adequate data protection
measures in place, including assigning a data
protection officer, you could face steep fines
next May.
10 Steps Enterprises Need to Take to
Comply with GDPR
Be Agile & Decrease Costs with Black Duck’s
Visual Studio IDE Plugin
via Black Duck blog (Evan Klein): Black Duck’s new Hub plugin to
Visual Studio IDE can scan your code as your team is developing it,
immediately alerting you to any components with potential security
risks. Think of it as a spell checker for open source components.
Black Duck will tell you if a component is vulnerable or violates any
open source use policies that you’ve set. More detailed information is
only a click away in Black Duck Hub, where you can quickly find safer
versions and select the one that works best for your needs. The
plugin is a simple and unobtrusive tool, giving you the ability to make
corrections as you develop without creating a new process that
disrupts your work.
Subscribe
Stay up to date on open source security and cybersecurity –
subscribe to our blog today.
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More Equifax Woes

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Keynote - Lou Shipley
Keynote - Lou ShipleyKeynote - Lou Shipley
Keynote - Lou Shipley
 
Policy in OpenStack - Martin Casado, CTO, VMware - OpenStackSV 2014
Policy in OpenStack - Martin Casado, CTO, VMware - OpenStackSV 2014Policy in OpenStack - Martin Casado, CTO, VMware - OpenStackSV 2014
Policy in OpenStack - Martin Casado, CTO, VMware - OpenStackSV 2014
 
Tenzin thiley bhutia
Tenzin thiley bhutiaTenzin thiley bhutia
Tenzin thiley bhutia
 
Over-Engineering: Causes, Symptoms, and Treatment
Over-Engineering: Causes, Symptoms, and TreatmentOver-Engineering: Causes, Symptoms, and Treatment
Over-Engineering: Causes, Symptoms, and Treatment
 
The Software Defined Economy - Jonathan Bryce, Exec. Dir., OpenStack Foundati...
The Software Defined Economy - Jonathan Bryce, Exec. Dir., OpenStack Foundati...The Software Defined Economy - Jonathan Bryce, Exec. Dir., OpenStack Foundati...
The Software Defined Economy - Jonathan Bryce, Exec. Dir., OpenStack Foundati...
 
O2 Presentation Sdp Event
O2 Presentation Sdp EventO2 Presentation Sdp Event
O2 Presentation Sdp Event
 
Technology Trends & The Impact for Software Industry
Technology Trends & The Impact for Software IndustryTechnology Trends & The Impact for Software Industry
Technology Trends & The Impact for Software Industry
 
Production machine learning: Managing models, workflows and risk at scale
Production machine learning: Managing models, workflows and risk at scaleProduction machine learning: Managing models, workflows and risk at scale
Production machine learning: Managing models, workflows and risk at scale
 
Connect your industry to cloud using IoT and Salesforce
Connect your industry to cloud using IoT and SalesforceConnect your industry to cloud using IoT and Salesforce
Connect your industry to cloud using IoT and Salesforce
 
Securing a great Developer Experience - v1.3
Securing a great Developer Experience - v1.3Securing a great Developer Experience - v1.3
Securing a great Developer Experience - v1.3
 
From Zero to SAFe
From Zero to SAFeFrom Zero to SAFe
From Zero to SAFe
 
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
 
10 top notch big data trends to watch out for in 2017
10 top notch big data trends to watch out for in 201710 top notch big data trends to watch out for in 2017
10 top notch big data trends to watch out for in 2017
 
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic CloudTirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
 
Creating Datadipity
Creating DatadipityCreating Datadipity
Creating Datadipity
 
Augmenting and Automating DevOps with Artificial Intelligence
Augmenting and Automating DevOps with Artificial IntelligenceAugmenting and Automating DevOps with Artificial Intelligence
Augmenting and Automating DevOps with Artificial Intelligence
 
2021 Open Source Governance: Top Ten Trends and Predictions
2021 Open Source Governance: Top Ten Trends and Predictions2021 Open Source Governance: Top Ten Trends and Predictions
2021 Open Source Governance: Top Ten Trends and Predictions
 
From Reversing to Exploitation: Android Application Security in Essence
From Reversing to Exploitation: Android Application Security in EssenceFrom Reversing to Exploitation: Android Application Security in Essence
From Reversing to Exploitation: Android Application Security in Essence
 
BeyondCorp Myths: Busted
BeyondCorp Myths: BustedBeyondCorp Myths: Busted
BeyondCorp Myths: Busted
 
The Evolution of a Connected Business
The Evolution of a Connected Business The Evolution of a Connected Business
The Evolution of a Connected Business
 

Ähnlich wie Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More Equifax Woes

Ähnlich wie Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More Equifax Woes (20)

Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
 
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
 
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Open Source Insight:2017 Top 10 IT Security Stories, Breaches, and Predictio...Open Source Insight:2017 Top 10 IT Security Stories, Breaches, and Predictio...
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
 
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Open Source Insight:Container Tech, Data Centre Security & 2018's Biggest Se...Open Source Insight:Container Tech, Data Centre Security & 2018's Biggest Se...
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
 
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Open Source Insight: Samba Vulnerability, Connected Car Risks,  and Are You R...Open Source Insight: Samba Vulnerability, Connected Car Risks,  and Are You R...
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
 
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
 
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
 
Open Source Insight: Hub Detect & DevOps, OSS for Cars & 1.8 M Voter Info Leaked
Open Source Insight: Hub Detect & DevOps, OSS for Cars & 1.8 M Voter Info LeakedOpen Source Insight: Hub Detect & DevOps, OSS for Cars & 1.8 M Voter Info Leaked
Open Source Insight: Hub Detect & DevOps, OSS for Cars & 1.8 M Voter Info Leaked
 
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
 
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Open Source Insight: Balancing Agility and Open Source Security for DevOpsOpen Source Insight: Balancing Agility and Open Source Security for DevOps
Open Source Insight: Balancing Agility and Open Source Security for DevOps
 
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
Open Source Insight:  GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...Open Source Insight:  GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
 
Open Source Insight: NVD's New Look, Struts Vuln Ransomware & Google Open So...
Open Source Insight:  NVD's New Look, Struts Vuln Ransomware & Google Open So...Open Source Insight:  NVD's New Look, Struts Vuln Ransomware & Google Open So...
Open Source Insight: NVD's New Look, Struts Vuln Ransomware & Google Open So...
 
The Trinity in Exponential Technologies: Open Source, Blockchain and Microsof...
The Trinity in Exponential Technologies: Open Source, Blockchain and Microsof...The Trinity in Exponential Technologies: Open Source, Blockchain and Microsof...
The Trinity in Exponential Technologies: Open Source, Blockchain and Microsof...
 
Juarez Barbosa Junior - Microsoft - OSL19
Juarez Barbosa Junior - Microsoft - OSL19Juarez Barbosa Junior - Microsoft - OSL19
Juarez Barbosa Junior - Microsoft - OSL19
 
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
Open Source Insight:  Amazon Servers Exposed  Open Source & the Public Sector...Open Source Insight:  Amazon Servers Exposed  Open Source & the Public Sector...
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
 

Mehr von Black Duck by Synopsys

Mehr von Black Duck by Synopsys (20)

Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018Open-Source- Sicherheits- und Risikoanalyse 2018
Open-Source- Sicherheits- und Risikoanalyse 2018
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical GuideFLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your DealFLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
 
FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub FLIGHT Amsterdam Presentation - From Protex to Hub
FLIGHT Amsterdam Presentation - From Protex to Hub
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...Open Source Insight:GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
 
Open Source Rookies and Community
Open Source Rookies and CommunityOpen Source Rookies and Community
Open Source Rookies and Community
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
 
20 Billion Reasons for IoT Security
20 Billion Reasons for IoT Security20 Billion Reasons for IoT Security
20 Billion Reasons for IoT Security
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight:Banking and Open Source, 2018 CISO Report, GDPR LoomingOpen Source Insight:Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
 
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
 
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
 
Buyer and Seller Perspectives on Open Source in Tech Contracts
Buyer and Seller Perspectives on Open Source in Tech ContractsBuyer and Seller Perspectives on Open Source in Tech Contracts
Buyer and Seller Perspectives on Open Source in Tech Contracts
 

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Kürzlich hochgeladen (20)

HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 

Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More Equifax Woes

  • 1. Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More Equifax Woes By Fred Bals | Senior Content Writer/Editor
  • 2. Cybersecurity News This Week On this Friday the 13th, the paraskevidekatriaphobia edition of Open Source Insight delves into scary software exploits like jeep hacking and data breaches. October is Cybersecurity Awareness Month, but how aware and cybersecure are the businesses holding our personal data? Black Duck joins forces with Google to clean up software supply chains. If it’s not one thing it’s two things for Equifax. Ten steps you need to take now to comply with GDPR. And Black Duck’s new Hub plugin to Visual Studio IDE.
  • 3. • Jeep Hacking & the Security of Things: Flight 2017 • It’s Cybersecurity Awareness Month. Do You Feel More Cybersecure and Aware Yet? • Google and Friends Open-Source Grafeas API to Clean up Software Supply Chains • Black Duck & Google Grafeas: Improving Container Visibility & Security • The Silver Lining on the Equifax Breach Open Source News
  • 4. More Open Source News • Web APIs Are the New Open Source Software • Equifax Takes Down Webpage After Report Of New Cybersecurity 'Situation' • Cyber Security Is A Business Risk, Not Just An IT Problem • 10 Steps Enterprises Need to Take to Comply with GDPR • Be Agile & Decrease Costs with Black Duck’s Visual Studio IDE Plugin
  • 5. via Black Duck blog (Kiara White): In less than a month, FLIGHT 2017, Black Duck's user conference, will return to the Seaport Hotel and World Trade Center in Boston, Massachusetts. We're delighted to announce that notorious Jeep hackers Chris Valasek and Dr. Charlie Miller will take the stage as keynote speakers. They'll address the future of the security of things, and the challenges and opportunities we'll face as machine learning, autonomous vehicles, big data and the Internet of Things converge to build products and services. Jeep Hacking & the Security of Things: Flight 2017
  • 6. It’s Cybersecurity Awareness Month. Do You Feel More Cybersecure and Aware Yet? via Future Tense: October is Cybersecurity Awareness Month. Maybe the best one can do to raise awareness is to tell fellow internet users to read the news.
  • 7. via Silicon Angle: The internet giant’s long list of friends includes JFrog Ltd., Red Hat Inc., IBM Corp., Black Duck Software Inc., Twistlock Ltd, Aqua Security Software Ltd. and CoreOS Inc. They’ve all joined forces to create a new application programming interface called Grafeas, which is an open source initiative to “define a uniform way for auditing and governing the modern software supply chain.” Google and Friends Open-Source Grafeas API to Clean up Software Supply Chains
  • 8. Black Duck & Google Grafeas: Improving Container Visibility & Security via Black Duck blog (Sheryl Sage and Neal Goldman): Black Duck has been working with Google on the development and testing of the Grafeas API over the last year, and we are continuing to work with Google to deliver on the vision of improving visibility into open source vulnerabilities before they hit production environments. Because many of our customers want to see the results of open source scans in the consoles of their primary development and deployment tools, you’ll continue to see improvements in the Black Duck’s integrations with Google Cloud Platform, including the Grafeas API and other new Google platform features.
  • 9. via CSO: If we seize this moment to get people more engaged in understanding and acting upon information security and protection, it may turn out that the Equifax breach was a good thing after all. The Silver Lining on the Equifax Breach
  • 10. Web APIs Are the New Open Source Software via Black Duck blog (David Znidarsic | Founder & President of Stairstep Consulting): If you are relaxing because you have your open source usage under control, beware. There is another increasingly common type of ungoverned third-party code that your engineers are using in your products: Web APIs.
  • 11. via NPR: On Thursday, Equifax explained that it had taken the page offline after Ars Technica, a website covering technology and other topics, pointed out a potential issue: fraudulent Adobe Flash updates. Equifax Takes Down Webpage After Report Of New Cybersecurity 'Situation'
  • 12. Cyber Security Is A Business Risk, Not Just An IT Problem via Forbes: Gone are the days when companies could pass the headaches of cyber security to the IT department, as it has become more of a business issue too. This is especially important as businesses are more digitized, meaning they are exposed to an increasing number of threats if they do not manage the risk of security properly.
  • 13. via Information week: If your organization doesn't have adequate data protection measures in place, including assigning a data protection officer, you could face steep fines next May. 10 Steps Enterprises Need to Take to Comply with GDPR
  • 14. Be Agile & Decrease Costs with Black Duck’s Visual Studio IDE Plugin via Black Duck blog (Evan Klein): Black Duck’s new Hub plugin to Visual Studio IDE can scan your code as your team is developing it, immediately alerting you to any components with potential security risks. Think of it as a spell checker for open source components. Black Duck will tell you if a component is vulnerable or violates any open source use policies that you’ve set. More detailed information is only a click away in Black Duck Hub, where you can quickly find safer versions and select the one that works best for your needs. The plugin is a simple and unobtrusive tool, giving you the ability to make corrections as you develop without creating a new process that disrupts your work.
  • 15. Subscribe Stay up to date on open source security and cybersecurity – subscribe to our blog today.