open source

Open Source Does Not Equal Secure

Way back in 1999, I wrote about open-source software: First, simply publishing the code does not automatically mean that people…

3 days ago

Who’s your fridge talking to at night?

By Gary Fisk, Sales Engineer, Corelight I love origin stories – the tales of grand plans, unforeseen circumstances, and necessity…

2 weeks ago

Why Linux Should Factor Into Your Security Strategy

Linux is a pervasive operating system—and for good reason. It’s lightweight, flexible, multi-architecture supportive and open source, all leading to…

3 weeks ago

Shine Theory / DevOps / Community

A podcast called The Allusionist (hosted by Helen Zaltzman) crossed my path that provided me with a light-bulb moment. The…

1 month ago

Who Owns Open Source Security?

According to a recent report by the Internet Security Forum, open source software (OSS) is quickly becoming a pillar within…

2 months ago

New Study Finds 75% of Codebases Have Vulnerabilities

A new report and study, the 2020 Open Source Security and Risk Analysis report examined audit data from 1,250+ commercial…

3 months ago

Linux Foundation Addresses Open Source Security

The Linux Foundation announced this week it has launched yet another consortium, this time in the hopes of bringing some…

4 months ago

Zeek in it’s sweet spot: Detecting F5’s Big-IP CVE10 (CVE-2020-5902)

By Ben Reardon, Corelight Security Researcher Having a CVE 10 unauthenticated Remote Code Execution vulnerability on a central load balancing…

4 months ago

How to Better Navigate the World of DevSecOps with Sonatype and Saltworks Security

Recently we partnered with Orasi Software and Saltworks Security to discuss how organizations are using open source software. Saltworks’ Founder…

4 months ago

Ripple20 Zeek package open sourced

By Ben Reardon, Corelight Security Researcher Recently, security research group JSOF released 19 vulnerabilities related to the “Treck” TCP/IP stack.…

5 months ago