SlideShare a Scribd company logo
Open Source Insight:
GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equifax
By Fred Bals | Senior Content Writer/Editor
Cybersecurity News This Week
COSRI research director Chris Fearon makes the case that Equifax
was either unaware of or slow to respond to reports of known critical
vulnerabilities in their system, and as a result had not upgraded to
safer versions. That opinion was later proven out by Congressional
hearings into the breach, as Fred Bals relates in his blog on whether
SAST and DAST fell down on the job for Equifax. Black Duck VP and
General Counsel, Matt Jacobs partners with Irwin Mitchell’s Dan
Headley to review what GDPR will mean for open source code. Is
open source more dangerous than Windows? And Larry Ellison claims
Oracle could have saved Equifax from much heartache in this week’s
open source security and cybersecurity news wrap.
• How Do We Reconcile the Open Source
Security Risk With GDPR Best Practice?
• Examining Apache SCE Vulns
• The Next Step in Modernization
• The Attack of the Car Wash System and
Other Menacing Stories of the Internet of
Things
• Step Aside, Windows! Open Source and
Linux Are IT’s New Security Headache
Open Source News
More Open Source News
• Did SAST and DAST Fail Equifax?
• Ellison Claims Oracle Software Could Have Prevented Equifax
Hack
• BigchainDB Brings Scalable Database Technology to
Blockchains
• Russian Intelligence Reportedly Breached the NSA in 2015,
Stealing Cybersecurity Strategy
• FICO-Like Cybersecurity Scores Are Imminent: What Do They
Mean For Your Business?
• Exception Based Review Process – Less Is More!
via SC Media: GDPR is a top-to-bottom reform of
European data privacy law and deals with a much
wider range of topics than information
security. Nevertheless, security is a key element
of GDPR's overall policy objective of promoting
transparency, accountability and trust in
organisations which deal with people's data, and
its security provisions are a critical part of
achieving that objective...
How Do We Reconcile the Open Source Security
Risk With GDPR Best Practice?
Examining Apache SCE Vulns
via Black Duck blog (Christopher Fearon): The timeline of
related events makes it clear that fixed versions of Struts were
available at or before the security advisories were published, and
that known exploits were not available in the wild beforehand. The
timeline also bears witness to Apache's assertions of consistent
good practise and tells us that the attack was likely to be a
product of poor security practises on the part of Equifax.
via IBM Systems Magazine: Modernization has
evolved from a buzzword to an imperative for
any business that wishes to stay competitive.
New computer hardware and enhanced internet
interconnectivity don’t simply offer greater power
and faster speeds, they allow for new
possibilities. It’s in this environment — which
includes the Internet of Things (IoT) — where
open-source databases (OSDBs) are
increasingly relied upon.
The Next Step in Modernization
The Attack of the Car Wash System and Other
Menacing Stories of the Internet of Things
via Industry of Things (Germany):
Safe software is a short-lived concept.
What is considered safe today can
change overnight when new
vulnerabilities are discovered and
disclosed. The older the code, the
higher the probability that
vulnerabilities will be revealed.
via ComputerWorld: The Equifax breach is the
latest example of attackers targeting open-
source software in the enterprise.
Step Aside, Windows! Open Source and Linux
Are IT’s New Security Headache
Did SAST and DAST Fail Equifax?
via Black Duck blog (Fred Bals): [Equifax] hasn’t elaborated so
far on what was used to “scan” the Equifax systems, but given its
failure to identify a known open source vulnerability, one could
assume that it wasn’t a dedicated open source vulnerability
management solution (or if it was, Equifax should seriously
consider asking for its money back). It’s more likely that Equifax
was using some combination of traditional SAST and DAST tools
to protect itself.
via Market Watch: The massive data breach
at Equifax Inc. could have been prevented
with Oracle Corp.’s automated databases,
Larry Ellison claimed Tuesday, using the
credit-reporting company’s woes as a selling
point for Oracle’s new product.
Ellison Claims Oracle Software Could Have
Prevented Equifax Hack
BigchainDB Brings Scalable Database
Technology to Blockchains
via Black Duck blog (Masha McConaghy | Founder & CMO of
BigchainDB): For nine years, the Black Duck Open Source Rookies
of the Year awards have recognized some of the most innovative and
influential open source projects launched during the previous year.
We sat down with Founder and CMO Masha McConaghy to hear the
exciting story of one of this year's rookies: BigchainDB.
via Techcrunch: The NSA suffered a serious
breach in 2015, exposing the agency’s
cyberwarfare strategy, including its own
defenses and methods of attacking foreign
networks, reports The Wall Street
Journal today. Russian intelligence is said to be
behind the attack, and software from Russia-
based Kaspersky labs is suggested to have
been their vector.
Russian Intelligence Reportedly Breached
the NSA in 2015, Stealing Cybersecurity
Strategy
FICO-Like Cybersecurity Scores Are Imminent: What
Do They Mean For Your Business?
via Forbes: what if we started using a unified rating system for
evaluating cybersecurity like we do in all other aspects of business?
That system is already underway.
via Black Duck blog (Hal Hearst): In my
previous post I wrote about how the changing
situation around open source management has
pushed the need for an exception based review
process for open source. In my opinion, it's the
only process that really works. And by “works,” I
mean scales across a large enterprise in which
the use of open source is common. Exception
based is a key element in the “fast & simple”
approach.
Exception Based Review Process –
Less Is More!
Subscribe
Stay up to date on open source security and cybersecurity –
subscribe to our blog today.
Open Source Insight:  GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equifax

More Related Content

What's hot (19)

PDF
Modern Adversaries (Amplify Partners)
Andrew Manoske
 
PDF
Top 12 Cybersecurity Predictions for 2017
IBM Security
 
PPTX
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
Black Duck by Synopsys
 
PDF
Graph Intelligence: The Essentials for Cybersecurity
Neo4j
 
PDF
20160713 2016 the honeynet projct annual workshop focus and global trends
Yi-Lang Tsai
 
PDF
Scared About Supply Chain Cybersecurity? 5 Reasons You Aren't Scared Enough
Xeneta
 
PDF
Qrator Labs annual report 2017
Qrator Labs
 
PDF
5 Security Trends to Watch in 2020
Dharmendra Rama
 
PPTX
Global Threats| Cybersecurity|
paul young cpa, cga
 
PDF
Cisco 2013 Annual Security Report
Kim Jensen
 
PPTX
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Black Duck by Synopsys
 
PPTX
Dev Secops Software Supply Chain
Cameron Townshend
 
PPTX
Security Software Supply Chains - Sonatype - DevSecCon Singapore March 2019
Cameron Townshend
 
PDF
2017 Data Breach Investigations Report
- Mark - Fullbright
 
PDF
Cyber security trends 2018
Ruchi Vishwakarma
 
PDF
Are you ready for the next attack? Reviewing the SP Security Checklist
APNIC
 
PDF
1530 track1 ulinski
Rising Media, Inc.
 
PDF
[CB20] It is a World Wide Web, but All Politics is Local: Planning to Survive...
CODE BLUE
 
PPTX
The Top Five Cybersecurity Threats for 2018
CheapSSLsecurity
 
Modern Adversaries (Amplify Partners)
Andrew Manoske
 
Top 12 Cybersecurity Predictions for 2017
IBM Security
 
Open Source Insight: Apache Struts Exploits, Cloudera IPO Risks & the Next Cy...
Black Duck by Synopsys
 
Graph Intelligence: The Essentials for Cybersecurity
Neo4j
 
20160713 2016 the honeynet projct annual workshop focus and global trends
Yi-Lang Tsai
 
Scared About Supply Chain Cybersecurity? 5 Reasons You Aren't Scared Enough
Xeneta
 
Qrator Labs annual report 2017
Qrator Labs
 
5 Security Trends to Watch in 2020
Dharmendra Rama
 
Global Threats| Cybersecurity|
paul young cpa, cga
 
Cisco 2013 Annual Security Report
Kim Jensen
 
Open Source Insight: OWASP Top 10, Red Hat OpenShift News, & Gmail Phishing Scam
Black Duck by Synopsys
 
Dev Secops Software Supply Chain
Cameron Townshend
 
Security Software Supply Chains - Sonatype - DevSecCon Singapore March 2019
Cameron Townshend
 
2017 Data Breach Investigations Report
- Mark - Fullbright
 
Cyber security trends 2018
Ruchi Vishwakarma
 
Are you ready for the next attack? Reviewing the SP Security Checklist
APNIC
 
1530 track1 ulinski
Rising Media, Inc.
 
[CB20] It is a World Wide Web, but All Politics is Local: Planning to Survive...
CODE BLUE
 
The Top Five Cybersecurity Threats for 2018
CheapSSLsecurity
 

Similar to Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equifax (20)

PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
PPTX
Threat Check for Struts Released, Equifax Breach Dominates News
Black Duck by Synopsys
 
PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
PPTX
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Black Duck by Synopsys
 
PDF
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Black Duck by Synopsys
 
PDF
Cisco 2014 Midyear Security Report
Cisco Security
 
PPTX
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Artifex Ruling, NY Cybersecurity Regs, PATCH Act, & Wan...
Black Duck by Synopsys
 
PPTX
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Black Duck by Synopsys
 
PPTX
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Black Duck by Synopsys
 
PPTX
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Black Duck by Synopsys
 
PDF
Secureview 2q 2011
Felipe Prado
 
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
PPTX
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
PPTX
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Black Duck by Synopsys
 
Threat Check for Struts Released, Equifax Breach Dominates News
Black Duck by Synopsys
 
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Black Duck by Synopsys
 
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Black Duck by Synopsys
 
Open Source Insight: Struts in VMware, Law Firm Cybersecurity, Hospital Data ...
Black Duck by Synopsys
 
Cisco 2014 Midyear Security Report
Cisco Security
 
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Black Duck by Synopsys
 
Open Source Insight: Artifex Ruling, NY Cybersecurity Regs, PATCH Act, & Wan...
Black Duck by Synopsys
 
Open Source Insight: AI for Open Source Management, IoT Time Bombs, Ready for...
Black Duck by Synopsys
 
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Black Duck by Synopsys
 
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
Black Duck by Synopsys
 
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Black Duck by Synopsys
 
Open Source Insight: 2017 Top 10 IT Security Stories, Breaches, and Predictio...
Black Duck by Synopsys
 
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
Black Duck by Synopsys
 
Secureview 2q 2011
Felipe Prado
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Black Duck by Synopsys
 
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Black Duck by Synopsys
 
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Black Duck by Synopsys
 
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Black Duck by Synopsys
 
Ad

More from Black Duck by Synopsys (20)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
PDF
Open Source Rookies and Community
Black Duck by Synopsys
 
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
PDF
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
PPTX
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
PPTX
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
PPTX
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
Black Duck by Synopsys
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Black Duck by Synopsys
 
Open-Source- Sicherheits- und Risikoanalyse 2018
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
Black Duck by Synopsys
 
FLIGHT Amsterdam Presentation - From Protex to Hub
Black Duck by Synopsys
 
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Black Duck by Synopsys
 
Open Source Rookies and Community
Black Duck by Synopsys
 
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Black Duck by Synopsys
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Black Duck by Synopsys
 
20 Billion Reasons for IoT Security
Black Duck by Synopsys
 
Open Source Insight: IoT Security, Tech Due Diligence, and Software Security ...
Black Duck by Synopsys
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Black Duck by Synopsys
 
Open Source Insight: Balancing Agility and Open Source Security for DevOps
Black Duck by Synopsys
 
Ad

Recently uploaded (20)

PDF
Arcee AI - building and working with small language models (06/25)
Julien SIMON
 
PDF
CloudStack GPU Integration - Rohit Yadav
ShapeBlue
 
PDF
Productivity Management Software | Workstatus
Lovely Baghel
 
PDF
How Current Advanced Cyber Threats Transform Business Operation
Eryk Budi Pratama
 
PPTX
UI5Con 2025 - Get to Know Your UI5 Tooling
Wouter Lemaire
 
PDF
Trading Volume Explained by CIFDAQ- Secret Of Market Trends
CIFDAQ
 
PDF
Bitcoin+ Escalando sin concesiones - Parte 1
Fernando Paredes García
 
PDF
Julia Furst Morgado The Lazy Guide to Kubernetes with EKS Auto Mode + Karpenter
AWS Chicago
 
PPTX
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
PDF
Meetup Kickoff & Welcome - Rohit Yadav, CSIUG Chairman
ShapeBlue
 
PDF
Novus Safe Lite- What is Novus Safe Lite.pdf
Novus Hi-Tech
 
PDF
Ampere Offers Energy-Efficient Future For AI And Cloud
ShapeBlue
 
PDF
Lecture A - AI Workflows for Banking.pdf
Dr. LAM Yat-fai (林日辉)
 
PDF
Apache CloudStack 201: Let's Design & Build an IaaS Cloud
ShapeBlue
 
PPTX
TYPES OF COMMUNICATION Presentation of ICT
JulieBinwag
 
PDF
How a Code Plagiarism Checker Protects Originality in Programming
Code Quiry
 
PPTX
Extensions Framework (XaaS) - Enabling Orchestrate Anything
ShapeBlue
 
PDF
GITLAB-CICD_For_Professionals_KodeKloud.pdf
deepaktyagi0048
 
PDF
OpenInfra ID 2025 - Are Containers Dying? Rethinking Isolation with MicroVMs.pdf
Muhammad Yuga Nugraha
 
PPTX
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 
Arcee AI - building and working with small language models (06/25)
Julien SIMON
 
CloudStack GPU Integration - Rohit Yadav
ShapeBlue
 
Productivity Management Software | Workstatus
Lovely Baghel
 
How Current Advanced Cyber Threats Transform Business Operation
Eryk Budi Pratama
 
UI5Con 2025 - Get to Know Your UI5 Tooling
Wouter Lemaire
 
Trading Volume Explained by CIFDAQ- Secret Of Market Trends
CIFDAQ
 
Bitcoin+ Escalando sin concesiones - Parte 1
Fernando Paredes García
 
Julia Furst Morgado The Lazy Guide to Kubernetes with EKS Auto Mode + Karpenter
AWS Chicago
 
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
Meetup Kickoff & Welcome - Rohit Yadav, CSIUG Chairman
ShapeBlue
 
Novus Safe Lite- What is Novus Safe Lite.pdf
Novus Hi-Tech
 
Ampere Offers Energy-Efficient Future For AI And Cloud
ShapeBlue
 
Lecture A - AI Workflows for Banking.pdf
Dr. LAM Yat-fai (林日辉)
 
Apache CloudStack 201: Let's Design & Build an IaaS Cloud
ShapeBlue
 
TYPES OF COMMUNICATION Presentation of ICT
JulieBinwag
 
How a Code Plagiarism Checker Protects Originality in Programming
Code Quiry
 
Extensions Framework (XaaS) - Enabling Orchestrate Anything
ShapeBlue
 
GITLAB-CICD_For_Professionals_KodeKloud.pdf
deepaktyagi0048
 
OpenInfra ID 2025 - Are Containers Dying? Rethinking Isolation with MicroVMs.pdf
Muhammad Yuga Nugraha
 
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 

Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equifax

  • 1. Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equifax By Fred Bals | Senior Content Writer/Editor
  • 2. Cybersecurity News This Week COSRI research director Chris Fearon makes the case that Equifax was either unaware of or slow to respond to reports of known critical vulnerabilities in their system, and as a result had not upgraded to safer versions. That opinion was later proven out by Congressional hearings into the breach, as Fred Bals relates in his blog on whether SAST and DAST fell down on the job for Equifax. Black Duck VP and General Counsel, Matt Jacobs partners with Irwin Mitchell’s Dan Headley to review what GDPR will mean for open source code. Is open source more dangerous than Windows? And Larry Ellison claims Oracle could have saved Equifax from much heartache in this week’s open source security and cybersecurity news wrap.
  • 3. • How Do We Reconcile the Open Source Security Risk With GDPR Best Practice? • Examining Apache SCE Vulns • The Next Step in Modernization • The Attack of the Car Wash System and Other Menacing Stories of the Internet of Things • Step Aside, Windows! Open Source and Linux Are IT’s New Security Headache Open Source News
  • 4. More Open Source News • Did SAST and DAST Fail Equifax? • Ellison Claims Oracle Software Could Have Prevented Equifax Hack • BigchainDB Brings Scalable Database Technology to Blockchains • Russian Intelligence Reportedly Breached the NSA in 2015, Stealing Cybersecurity Strategy • FICO-Like Cybersecurity Scores Are Imminent: What Do They Mean For Your Business? • Exception Based Review Process – Less Is More!
  • 5. via SC Media: GDPR is a top-to-bottom reform of European data privacy law and deals with a much wider range of topics than information security. Nevertheless, security is a key element of GDPR's overall policy objective of promoting transparency, accountability and trust in organisations which deal with people's data, and its security provisions are a critical part of achieving that objective... How Do We Reconcile the Open Source Security Risk With GDPR Best Practice?
  • 6. Examining Apache SCE Vulns via Black Duck blog (Christopher Fearon): The timeline of related events makes it clear that fixed versions of Struts were available at or before the security advisories were published, and that known exploits were not available in the wild beforehand. The timeline also bears witness to Apache's assertions of consistent good practise and tells us that the attack was likely to be a product of poor security practises on the part of Equifax.
  • 7. via IBM Systems Magazine: Modernization has evolved from a buzzword to an imperative for any business that wishes to stay competitive. New computer hardware and enhanced internet interconnectivity don’t simply offer greater power and faster speeds, they allow for new possibilities. It’s in this environment — which includes the Internet of Things (IoT) — where open-source databases (OSDBs) are increasingly relied upon. The Next Step in Modernization
  • 8. The Attack of the Car Wash System and Other Menacing Stories of the Internet of Things via Industry of Things (Germany): Safe software is a short-lived concept. What is considered safe today can change overnight when new vulnerabilities are discovered and disclosed. The older the code, the higher the probability that vulnerabilities will be revealed.
  • 9. via ComputerWorld: The Equifax breach is the latest example of attackers targeting open- source software in the enterprise. Step Aside, Windows! Open Source and Linux Are IT’s New Security Headache
  • 10. Did SAST and DAST Fail Equifax? via Black Duck blog (Fred Bals): [Equifax] hasn’t elaborated so far on what was used to “scan” the Equifax systems, but given its failure to identify a known open source vulnerability, one could assume that it wasn’t a dedicated open source vulnerability management solution (or if it was, Equifax should seriously consider asking for its money back). It’s more likely that Equifax was using some combination of traditional SAST and DAST tools to protect itself.
  • 11. via Market Watch: The massive data breach at Equifax Inc. could have been prevented with Oracle Corp.’s automated databases, Larry Ellison claimed Tuesday, using the credit-reporting company’s woes as a selling point for Oracle’s new product. Ellison Claims Oracle Software Could Have Prevented Equifax Hack
  • 12. BigchainDB Brings Scalable Database Technology to Blockchains via Black Duck blog (Masha McConaghy | Founder & CMO of BigchainDB): For nine years, the Black Duck Open Source Rookies of the Year awards have recognized some of the most innovative and influential open source projects launched during the previous year. We sat down with Founder and CMO Masha McConaghy to hear the exciting story of one of this year's rookies: BigchainDB.
  • 13. via Techcrunch: The NSA suffered a serious breach in 2015, exposing the agency’s cyberwarfare strategy, including its own defenses and methods of attacking foreign networks, reports The Wall Street Journal today. Russian intelligence is said to be behind the attack, and software from Russia- based Kaspersky labs is suggested to have been their vector. Russian Intelligence Reportedly Breached the NSA in 2015, Stealing Cybersecurity Strategy
  • 14. FICO-Like Cybersecurity Scores Are Imminent: What Do They Mean For Your Business? via Forbes: what if we started using a unified rating system for evaluating cybersecurity like we do in all other aspects of business? That system is already underway.
  • 15. via Black Duck blog (Hal Hearst): In my previous post I wrote about how the changing situation around open source management has pushed the need for an exception based review process for open source. In my opinion, it's the only process that really works. And by “works,” I mean scales across a large enterprise in which the use of open source is common. Exception based is a key element in the “fast & simple” approach. Exception Based Review Process – Less Is More!
  • 16. Subscribe Stay up to date on open source security and cybersecurity – subscribe to our blog today.