source

Backed by Google, a group of respected computer security pros launched oCERT, an effort to be the go-to place for security incident response for open-source projects....SOLVE MORE ISSUES on the first call. Try WebEx FREE ZAP REMOTE SUPPORT ISSUES! Crush Support Log Jams! BLAST THROUGH FIREWALLS! Try WebEx REMOTE SUPPORT read more »
addto Add this link to... report Bury 
How dunnit plot gets scriptedThe source of the mystery infection of more than 10,000 websites back in January has been uncovered.… read more »
addto Add this link to... report Bury 
http://www.theregister.co.uk/2008/04/16/mystery_web_compromise_unpicked/By John LeydenThe Register16th April 2008The source of the mystery infection of more than 10,000 websites back in January has been uncovered.Thousands of legitimate websites were compromised at the start of the year to serve up malware, as we reported [1] at the time.It seemed [2] that the exploitation of SQL Injection vulnerabilities was involved in the automated attacks. The precise mechanism was unclear until earlier this week when read more »
addto Add this link to... report Bury 
Google has removed an open source project that enables the proprietary CoreAVC high-definition video decoder to run in Linux following a complaint from the codec's developer -- but the project could soon return. read more »
addto Add this link to... report Bury 
oCERT to make the world safe for GPLGoogle is spearheading a volunteer workforce it hopes will become the centralized authority for responding to security issues in open source software.… read more »
addto Add this link to... report Bury 
Audit gives thumbs upThe quality of open source code has improved over the last two years, according to an audit sponsored by the US Department of Homeland Security.… read more »
addto Add this link to... report Bury 
http://www.gcn.com/online/vol1_no1/46342-1.htmlBy Wilson P. Dizard IIIGCN.com05/23/08 A two-year study of more than 55 million lines of code showed that open-source systems include a variety of errors that closely track those found in software written for proprietary systems.The incidence of those errors in open-source code is declining, according to a study that the Homeland Security Department funded. The department hired Coverity to analyze more than 55 million lines of code in two years as part of the read more »
addto Add this link to... report Bury 
Once upon a time, using open-source servers and applications for business was frowned upon in many circles. Today, you?d be hard pressed to find any sizeable infrastructure that doesn?t leverage open-source code in some form or another, be it a few MySQL databases, Apache on the Web servers, or a pile of Perl, PHP, Ruby, or Python applications holding things together. read more »
addto Add this link to... report Bury 
GPL security project goes under commercial managementOSSEC, the open source host-based intrusion detection project, has been snapped up by Third Brigade, a commercial firm in the same information security sub-market. Terms of the deal, announced on Tuesday, were undisclosed.… read more »
addto Add this link to... report Bury 
Internet consumer advocacy group Stopbadware.org released data on "badware" Web sites on Tuesday, saying that Google was one of the top five networks responsible for hosting these dangerous Web sites. read more »
addto Add this link to... report Bury 
From: InfoSec News <alerts_at_private>Date: Tue, 15 Jul 2008 05:09:28 -0500 (CDT)http://attrition.org/news/content/08-07-15.001.htmlRICHMOND, VA, July 14, 2008 - The Open Security Foundation (OSF) is pleased to announce that the DataLossDB (also known as the Data Loss Database - Open Source (DLDOS) currently run by Attrition.org) will be formally maintained as an ongoing project under the OSF umbrella organization as of July 15, 2008.Attrition.org's Data Loss project, which was originally conceptuali read more »
addto Add this link to... report Bury