White House to study open source software in critical infrastructure
Full article702 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Biden administration is looking to understand just how widespread open-source software is in critical infrastructure.
LAS VEGAS — A year after asking the hacker community how they can better help protect the open source software that is the foundation of the digital economy, the White House is looking to better secure the ecosystem through a new office dedicated to studying such components in critical infrastructure.
The Office of the National Cyber Director released new details Friday on several projects aimed at securing open source software. The report comes a year after the office asked attendees at DEF CON in 2023 to contribute to a request for information around how to better focus on securing open source software.
The new office runs out of the Department of Homeland Security and will examine the prevalence of open source software present in critical infrastructure and how to secure it, said Nasreen Djouini, senior policy advisor at the Office of the National Cyber Director. The program will have the support of the Department of Energy’s national labs, including at Los Alamos and Lawrence Livermore.
Cyberattacks on open source software by both criminal hackers and nation-backed threats are an increasing concern, as the transparent development process has become a target for malicious activity. What’s more, open source software is largely voluntary, so resources for digital security can be minimal and dependent on the individual contributor or project.
Friday’s report also included a summation of comments submitted to ONCD about how to best secure open source software.
The comments included requests for better resource assistance to developers and maintainers of the software supply chain. Other comments advocated for switching to memory-safe languages like Rust. That’s a transition the Defense Advanced Research Projects Agency is trying to do autonomously.
The Biden administration has made securing open-source software a priority after the Log4J vulnerability exposed the security risks of the open-source ecosystem in 2021.
Experts note that years later vulnerable versions of the Log4J software version are still commonly found in the wild.
More Scoops
The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.
Open-source software’s archenemy TeamPCP goes back further than anyone thought
National cyber director lays out White House plans to secure AI without writing new rules
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/open-source-critical-infrastructure-def-con/