Securing Open Source - Security Boulevard https://securityboulevard.com/category/editorial-calendar/securing-open-source/ The Home of the Security Bloggers Network Fri, 20 Oct 2023 15:10:39 +0000 en-US hourly 1 https://wordpress.org/?v=6.3.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Securing Open Source - Security Boulevard https://securityboulevard.com/category/editorial-calendar/securing-open-source/ 32 32 133346385 KeePass Malicious Ads: Google Goof Permits Punycode Attacks Again https://securityboulevard.com/2023/10/keepass-malicious-ads-punycode-richixbw/ Fri, 20 Oct 2023 15:10:39 +0000 https://securityboulevard.com/?p=1993030 ķ≠k

Mote below k: Not only malvertising, but also “verified by Google.”

The post KeePass Malicious Ads: Google Goof Permits Punycode Attacks Again appeared first on Security Boulevard.

]]>
1993030
iPhone/iPad Warning: Update Now to Avoid Zero-Day Pain https://securityboulevard.com/2023/10/ios-7-0-3-update-richixbw/ Fri, 06 Oct 2023 15:26:53 +0000 https://securityboulevard.com/?p=1991731 Three iPhone 15s sit on a wicker table, with the words “PATCH NOW!” macro’ed on top

Apple’s embarrassing regression: iOS 17.0.3 fixes yet more nasty zero-days (and the overheating bug).

The post iPhone/iPad Warning: Update Now to Avoid Zero-Day Pain appeared first on Security Boulevard.

]]>
1991731
Patch EVERYTHING: Widely Used ‘WebP’ Code has Critical Bug https://securityboulevard.com/2023/09/patch-everything-widely-used-webp-code-has-critical-bug/ Wed, 13 Sep 2023 17:10:18 +0000 https://securityboulevard.com/?p=1989037 The Google WebP logo

WebP FAIL. Critical vuln in libwebp: Go get updates to Chrome, Firefox, Edge, Slack and more.

The post Patch EVERYTHING: Widely Used ‘WebP’ Code has Critical Bug appeared first on Security Boulevard.

]]>
1989037
Google Kills 3rd-Party Cookies — but Monopolizes AdTech https://securityboulevard.com/2023/09/google-privacy-sandbox-richixbw/ Fri, 08 Sep 2023 17:39:16 +0000 https://securityboulevard.com/?p=1988593 Google Android malware

Firefox looking good right now: “Privacy Sandbox” criticized as a proprietary, hypocritical, anti-competitive, self-serving contradiction.

The post Google Kills 3rd-Party Cookies — but Monopolizes AdTech appeared first on Security Boulevard.

]]>
1988593
BadBazaar: Chinese Spyware Shams Signal, Telegram Apps https://securityboulevard.com/2023/08/badbazaar-signal-telegram-gref-richixbw/ Thu, 31 Aug 2023 17:13:45 +0000 https://securityboulevard.com/?p=1987879 A phone home screen shows Signal and Telegram app icons

After sneaking into Google and Samsung app stores, “GREF” APT targets Uyghurs and other PRC minorities.

The post BadBazaar: Chinese Spyware Shams Signal, Telegram Apps appeared first on Security Boulevard.

]]>
1987879
Teenage Hackers Must be Stopped: US DHS’s CSRB Report https://securityboulevard.com/2023/08/lapsus-dhs-csrb-sms-richixbw/ Fri, 11 Aug 2023 15:16:16 +0000 https://securityboulevard.com/?p=1984691 DHS secretary Alejandro Mayorkas

2FA SMS FAIL: Lapsus$ social engineers exploited weak two-factor authentication. Something must be done! (Well, this is something.)

The post Teenage Hackers Must be Stopped: US DHS’s CSRB Report appeared first on Security Boulevard.

]]>
1984691
Has the Altruism Model of Open Source Security Peaked? https://securityboulevard.com/2023/05/has-the-altruism-model-of-open-source-security-peaked/ Thu, 04 May 2023 13:00:36 +0000 https://securityboulevard.com/?p=1973622 OpenText OCSF WhiteSource Log4j window Proofpoint Open Source Security

With an executive order, the Biden administration attempted to address concerns around open source software’s security. In Section 4 of Executive Order 14028, Improving the Nation’s Cybersecurity, open source and the software supply chain was specifically mentioned, with a requirement for “ensuring and attesting, to the extent practicable, to the integrity and provenance of open..

The post Has the Altruism Model of Open Source Security Peaked? appeared first on Security Boulevard.

]]>
1973622
FINALLY! Google Makes 2FA App Useable — BUT There’s a Catch https://securityboulevard.com/2023/04/google-2fa-app-sync-richixbw/ Tue, 25 Apr 2023 17:39:06 +0000 https://securityboulevard.com/?p=1973044

2FA OTP ASAP? Google Authenticator app now syncs your secrets: No stress if you break your phone.

The post FINALLY! Google Makes 2FA App Useable — BUT There’s a Catch appeared first on Security Boulevard.

]]>
1973044
Governments Try to Ban Encryption (Yet Again) https://securityboulevard.com/2023/04/ban-encryption-yet-again-richixbw/ Mon, 24 Apr 2023 17:38:07 +0000 https://securityboulevard.com/?p=1972852

Déjà vu: Yet again, they’re tugging on the “think of the children” strings. But you can’t make math illegal.

The post Governments Try to Ban Encryption (Yet Again) appeared first on Security Boulevard.

]]>
1972852
Drop Everything: Update Chrome NOW — 0-Day Exploit in Wild https://securityboulevard.com/2023/04/update-chrome-0-day-in-wild-richixbw/ Mon, 17 Apr 2023 16:00:45 +0000 https://securityboulevard.com/?p=1972145

It’s Help|About Time: Chrome’s “V8” JavaScript engine has high-severity vuln. Scrotes already exploiting it.

The post Drop Everything: Update Chrome NOW — 0-Day Exploit in Wild appeared first on Security Boulevard.

]]>
1972145