Open Source
Exclusive
Report: Russia-based Yandex employee oversees open-source software approved for DOD use
The package is listed inside Platform One’s Iron Bank, a vetted Defense Department software repository, people familiar say.
DARPA unveils winners of AI challenge to boost critical infrastructure cybersecurity
The AI Cyber Challenge aims to accelerate the distribution of open-source AI models to help patch the code that powers major infrastructure like water treatment plans and power grids. Four of the open-source models have already been made available for use.
Foreign adversaries are trying to weaponize open-source software, report finds
Hacking units affiliated with nation-state adversaries are subtly contributing to open-source software tools and working to insert backdoors into publicly available code used by millions worldwide, new research says.
National AI Action plan should expand open-source offerings, respondents say
During the open comment period, a multitude of entities — from private sector to academic research bodies — touted the benefits of a robust open-source AI ecosystem.
Strengthening open source: A roadmap to enhanced cybersecurity
COMMENTARY | Open-source software is a cornerstone of American innovation, underpinning critical infrastructure and driving economic growth.
Half of critical open source projects contain memory-unsafe code, U.S. cyber agency says
The findings come after recent hijacking attempts into major open-source tools.
New mailing list aims to share hacking attempts on open-source projects
The Siren email list allows members to share active exploitations of open-source projects, fueled by recent attempts to sabotage free-to-use software tooling
Feds beware: New studies demonstrate key AI shortcomings
Recent studies have started to show that there are serious downsides when it comes to such programs’ ability to produce secure code.
Hackers tried to breach, disable widely used open-source Java tools, groups warn
The alert comes just after a possible nation state entity attempted to hijack an open-source Linux tool last month.
Linux backdoor was a long con, possibly with nation-state support, experts say
If the XZ Utils vulnerability hadn’t been caught in time, hackers would have had a “skeleton key to the world,” one analyst told Nextgov/FCW.
NTIA explores the benefits and risks of open-weight AI models
A new request for information issued by the National Telecommunications and Information Administration will inform regulatory policy on open-weight models.
Taking open source risks seriously
COMMENTARY | Software bills of materials don't address what tech leaders should actually do to make sure open source components are safe to use.
Featured eBooks