Researchers at an Israeli security firm on Tuesday revealed how hackers could turn a generative AI’s “hallucinations” into a nightmare for an organization’s software supply chain. . In a blog post on the Vulcan Cyber website, researchers Bar Lanyado, Ortel Keizman, and Yair Divinsky illustrated how one could exploit false information generated by ChatGPT about open-source software packages to deliver malicious code into a development environment. They explained that they’ve seen ChatGPT generate URLs, references, and even code libraries and functions that do not actually exist. If ChatGPT is fabricating code libraries or packages, attackers could use these hallucinations to spread malicious packages without using suspicious and already detectable techniques like typosquatting or masquerading, they noted. . Analysts revealed the potential for AI-generated delusions to take advantage of vulnerabilities in public software and threaten corporate safety.. Enterprise Security, AI Exploitation, Software Supply Chain, Malicious Code, Open Source Risks. . Brittany Day
The tech industry is readying solutions to the security risks posed by the collaborative software that underpins modern-day computing — but aid from Washington could be essential to the project’s success. . The cyber community’s scramble to address major vulnerabilities in the widely used code library Log4j is just the latest wake-up call about the security risks of the open-source software ecosystem — and it’s fueling new calls for more government support in plugging those gaps. The discovery of the Log4j flaw early this month spawned immediate alarm throughout the cyber world because of the enormous number of internet-connected systems it exposed to potential attacks. CISA estimated that “hundreds of millions” of devices run software that uses the Java-language logging tool. The link for this article located at Politico is no longer available. . The recent rush within the tech sector to address significant flaws in OpenSSL underscores a pressing demand for enhanced government assistance.. Log4j Vulnerabilities, Open Source Risks, Cybersecurity Support. . Brittany Day
There was much mocking in the Linux camp this weekend when it was discovered that the Sir Cam virus will run under the Open Source operating system - but only under the Wine Windows emulator.. . .. There was much mocking in the Linux camp this weekend when it was discovered that the Sir Cam virus will run under the Open Source operating system - but only under the Wine Windows emulator. Although Wine (Wine Is Not an Emulator) is not technically a Windows emulator for Linux, it is a compatibility layer allowing Windows binaries to run on the Linux OS. It is that compatibility that enables it to run the Sir Cam virus. Reports emerging over the weekend have confirmed that the Sir Cam virus, which spread across the internet throughout July, runs under Wine. The link for this article located at vnunet is no longer available. . Tech analysts chuckled as Linux specialists stumbled upon the Sir Cam malware operating via the Wine emulator, questioning their security protocols.. Wine Compatibility, Linux Malware, Open Source Risk, Emulation Threat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.