Strengthening open source security requires coordinated action across the software supply chain. The Eclipse Foundation and OWASP® Foundation have signed a Memorandum of Understanding focused on improving alignment and adoption across existing security initiatives and helping organisations embed sustainable security and regulatory readiness practices across the software lifecycle. The goal is not to create competing frameworks, but to align and amplify the work already underway. Explore the collaboration: https://hubs.la/Q04s6Bkc0 #CyberResilienceAct #OpenSourceSecurity #SoftwareSupplyChain #AppSec
Eclipse Foundation’s Post
More Relevant Posts
-
North Korean Supply-Chain Campaigns Turn Trusted npm Packages Into a Silent Gateway for Cyberattacks + Video Introduction: When a Routine Software Update Becomes a Security Incident Modern software is built on trust. Developers install open-source packages, update dependencies, and rely on automated tools to keep applications secure and efficient. Most of the time, these actions happen quietly in the background. But when a trusted package maintainer is compromised, a routine update can become an entry point into thousands of organizations at once....
To view or add a comment, sign in
-
'Secure by Design' is not a feature. It is a fundamental software engineering principle. Embedding security throughout the software development lifecycle, right from the first phase helps reduce vulnerabilities, improve resilience, business-aligned and strengthen trust in software products. The newly released CIS Secure by Design v1.1 'A Guide to Assessing Software Security Practices' provides practical guidance to help organizations build and assess secure software. A useful resource for software developers, architects, and security professionals committed to Secure by Design. #SecureByDesign #ApplicationSecurity #DevSecOps #CyberSecurity #SoftwareSecurity #CIS #SecureDevelopment
🇪🇺EU GRC Strategist & Evangelist | Translating NIS2, DORA & GDPR into practical control frameworks | CISM, CIPP/E, CDPSE, ISO 27001 LA | Creator of ISMS & Privacy Toolkits | Author of GRC & DORA Pro Handbooks
New release: Secure by Design, Version 1.1. A Guide to Assessing Software Security Practices
To view or add a comment, sign in
-
𝟭,𝟯𝟬𝟬+ 𝗰𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲𝗱 𝗻𝗽𝗺 𝗽𝗮𝗰𝗸𝗮𝗴𝗲𝘀. 𝟮 𝗯𝗶𝗹𝗹𝗶𝗼𝗻 𝗺𝗼𝗻𝘁𝗵𝗹𝘆 𝗱𝗼𝘄𝗻𝗹𝗼𝗮𝗱𝘀. The latest 𝗦𝗵𝗮𝗶-𝗛𝘂𝗹𝘂𝗱 (𝗖𝗵𝗮𝗶𝗻𝗗𝗿𝗼𝗽) 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻 is one of the largest software supply chain attacks we've seen this year. But the biggest takeaway isn't the scale. 𝗜𝘁'𝘀 𝘁𝗵𝗮𝘁 𝘁𝗵𝗲 𝗮𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀 𝗱𝗶𝗱𝗻'𝘁 𝗲𝘅𝗽𝗹𝗼𝗶𝘁 𝗻𝗽𝗺. 𝗧𝗵𝗲𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘁𝗿𝘂𝘀𝘁. As software supply chains become increasingly automated, verifying where software came from is no longer enough. Engineering teams also need confidence in the software they choose to build with. We've shared our perspective on what this incident means for software provenance, software trust, and the future of software supply chain security. Read more: https://lnkd.in/ddWDsw5k 𝗪𝗵𝗮𝘁 𝗱𝗼 𝘆𝗼𝘂 𝘁𝗵𝗶𝗻𝗸 𝗶𝘀 𝘁𝗵𝗲 𝗯𝗶𝗴𝗴𝗲𝘀𝘁 𝗹𝗲𝘀𝘀𝗼𝗻 𝗳𝗿𝗼𝗺 𝘁𝗵𝗲 𝗦𝗵𝗮𝗶-𝗛𝘂𝗹𝘂𝗱 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻?
To view or add a comment, sign in
-
-
JetBrains issued a critical vulnerability alert for CVE-2026-63077 in TeamCity On-Premises. This vulnerability allows an unauthenticated attacker with HTTP or HTTPS access to the server to execute operating system commands using the agent polling protocol. The recommendation is to upgrade to TeamCity 2025.11.7 or 2026.1.3, or apply the patch plugin if an immediate upgrade is not possible. The risk extends beyond the server: TeamCity typically handles credentials, artifacts, and deployment processes. Therefore, in addition to patching, it is advisable to review exposure, logs, configuration changes, and the potential impact on the software supply chain. #Ciberseguridad #TeamCity #JetBrains #CVE #DevSecOps #CICD #SupplyChainSecurity #Vulnerabilidades Fuente: https://lnkd.in/dpZDhW-Y
To view or add a comment, sign in
-
-
For those interested, CISA just released a new 31-page publication; "Open Source Software: Security Principles and Practices" It introduces a new framework for trust assessment, covers secure use of open source software, vulnerability management, SBOM use, and handling of open source artificial intelligence systems. https://lnkd.in/gWY8sb7J
To view or add a comment, sign in
-
JetBrains has fixed a critical security flaw in its TeamCity software — a tool companies use to build and test their code before it goes live. The flaw let attackers with no login break in and run their own commands on the server, meaning they could tamper with software before it reaches customers. This is fixed in versions 2025.11.7 and 2026.1.3. If your workplace uses TeamCity to build software, forward this to your IT team today and ask them to confirm the update has been applied — an unpatched build server can let attackers slip malicious code into products used by thousands of people. ☠️ #CyberNewsLive https://lnkd.in/eMvqvqQd
To view or add a comment, sign in
-
Enforcing zero-trust network policies, dependency scans, and credential sanitization at every step of the Secure Software Development Life Cycle. Security is baked directly into our pipelines.
To view or add a comment, sign in
-
Free code. Real responsibility. Open-source security cannot depend on exhausted maintainers. The curl project paused vulnerability report handling during July 2026 after months of sustained pressure. Submissions reopened on 3 August, but the decision should prompt a wider discussion about software supply chain responsibility. curl was transparent. Organisations consuming open-source software still need their own controls when an upstream project slows, changes its disclosure process or cannot respond immediately. I would expect five basics: - A current dependency inventory showing where curl and other critical libraries are deployed. - Continuous monitoring of upstream security advisories and affected versions. - Risk-based vulnerability management that considers exposure, exploitability and business impact. - Compensating controls for network access, credentials and high-risk workflows. - A tested escalation path covering engineering, security operations and suppliers. The operational point is simple: a free dependency can still carry a material business risk. Downloading the code does not transfer accountability for understanding, monitoring or containing that risk. I help organisations turn software supply chain exposure into a practical control model, combining dependency visibility, vulnerability prioritisation, detection coverage and incident response. If a critical service depends on open source but ownership becomes unclear when something goes wrong, message me. That is the gap worth fixing before the next security advisory. #OpenSourceSecurity #SoftwareSupplyChain #VulnerabilityManagement
To view or add a comment, sign in
-
-
CISA has published "Open Source Software: Security Principles and Practices". Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. https://lnkd.in/gKmzsZ8N
To view or add a comment, sign in
-
🔐 Spring Security, explained in one flow (not a wall of text) Most people learn Spring Security by memorizing filter names. I found it clicks faster once you separate two questions: → Authentication = WHO are you? → Authorization = WHAT are you allowed to do? Everything else — the Filter Chain, JWT, BCrypt, SecurityContext — exists to answer those two questions before a request ever reaches your Controller. Here's the request lifecycle I'm implementing for my Job Application Tracker API: 1️⃣ Client sends a request 2️⃣ Security Filter Chain intercepts it 3️⃣ JWT is extracted & validated 4️⃣ Authentication confirms WHO the user is 5️⃣ Authorization checks WHAT they're allowed to do 6️⃣ ✅ Allowed → Controller → Service → Repository → DB ❌ Denied → 403, before it ever touches business logic Passwords are hashed with BCrypt (never stored plain), and the authenticated user lives in the SecurityContext for the rest of the request. Currently building this out with Spring Boot + Spring Security + JWT. Sharing the journey as I go 🚀 #SpringBoot #SpringSecurity #JWT #JavaDevelopers #BackendDevelopment #SoftwareEngineering
To view or add a comment, sign in
-
Explore related topics
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development