A large number of servers running the Kubernetes API have been left exposed to the internet, which is not great: they're potentially vulnerable to abuse. . Nonprofit security organization The Shadowserver Foundation recently scanned 454,729 systems hosting the popular open-source platform for managing and orchestrating containers, finding that more than 381,645 – or about 84 percent – are accessible via the internet to varying degrees thus providing a cracked door into a corporate network. "While this does not mean that these instances are fully open or vulnerable to an attack, it is likely that this level of access was not intended and these instances are an unnecessarily exposed attack surface," Shadowserver's team stressed in a write-up . "They also allow for information leakage on version and build." . The Cyber Defense Coalition analyzed 512,310 devices, uncovering unprotected Docker Hub repositories.. Kubernetes Api Exposure, Shadowserver Scanning, Network Vulnerabilities. . LinuxSecurity.com Team
App security vendor Watchfire and anti-malware vendor Panda Software both launched web-based apps this week. Watchfire's new release, Appscan Enterprise 5, checks source code under development for security problems. The latest version includes a new . After the security scan, Quickscan presents programmers with a developer task list showing what code needs to be re-written to secure the application. "The industry is in wide agreement now that security testing must be built into the software development lifecycle, but too often companies mistakenly throw complex security solutions at [program] developers as the answer," said Watchfire chief technology officer, Michael Wieder. "It's simply not feasible to expect developers, who are already overtaxed with go-to-market pressures, to take on the role of security experts too." The link for this article located at IT Week is no longer available. . SecureScan offers programmers a checklist for code enhancements following vulnerability assessments to strengthen application defense.. App Security, Web Applications, Code Review, Development Practices, Anti-Malware. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.