• UAE
  • Pakistan
  • World
  • Health
  • Fitness
  • Automobile
  • Technology – IT World
  • Cryptocurrency
Facebook Twitter Instagram
Trending
  • At $7,400, is this 93 Mercury Capri XR2 also a premium vehicle?
  • 6 consensus mechanisms you need to know
  • Nobu Hotel, Restaurant, and Residences Al Marjan Island announced for UAE
  • United Arab Emirates: Zayed Prize announces winners of $1 million prize – News
  • Following East Coast success, Rumailah Farm set to expand across UAE
  • Foreign Exchange (Forex) Opening Rate In Pakistan 31 January 2023
  • UAE has built a civil society that passes Mahatma Gandhi’s test: Sheikh Nahyan – News
  • 2023 Infiniti QX60 Review | Now worth a detour
  • UAE
  • Pakistan
  • World
  • Health
  • Fitness
  • Automobile
  • Technology – IT World
  • Cryptocurrency
24/7 News
Tuesday, January 31
  • UAE
  • Pakistan
  • World
  • Health
  • Fitness
  • Automobile
  • Technology – IT World
  • Cryptocurrency
24/7 News
Home»Tech

Report: 96% of vulnerable open source downloads are preventable

November 26, 2022 Tech No Comments3 Mins Read

Check out the on-demand sessions from the Low-Code/No-Code Summit to learn how to successfully innovate and gain efficiencies by improving and scaling citizen developers. look now.


As the industry’s reliance on open source software has grown, the number of known software software supply chain attacks, with a 742% increase over the past three years, according to Sonatype eighth annual report on the state of the software supply chain. 1.2 billion vulnerable dependencies are downloaded each month, according to the report. Of these, 96% had a non-vulnerable option. Consumer behavior, not open source maintainers, is often cited in public discussions as the cause.

One of the reasons for this trend is the increase and evolution of software supply chain attacks. Report reveals 633% year-over-year increase in malicious attacks aimed at open-source in public repositories – and a 742% average annual increase in software supply chain attacks since 2019.

Image source: Sonatype.

Whereas cybercriminals are nothing new, the frequency, severity and sophistication of these malicious attacks are becoming a major issue plaguing developers and organizations around the world. Developers are urged to maintain a working knowledge of software quality, multiple open source ecosystems, fluctuating regulations, and nearly 1,500 dependency changes per year, per application, all in the face of ever-changing attacks.

So what can be done? Minimizing dependencies and keeping update times short are key factors in reducing the risk of transitive vulnerabilities, the most common source of security risk.

Event

Smart Security Summit

Learn about the critical role of AI and ML in cybersecurity and industry-specific case studies on December 8. Sign up for your free pass today.

Register now

However, reducing vulnerabilities is not limited to project security: it also affects job satisfaction. In a survey of engineering professionals, people from organizations with higher levels of software supply chain maturity were 2.7 times more likely to strongly agree with the statement “I am satisfied with my work”.

Interestingly, there is a clear disconnect between the security measures in place and what IT people think has passed. Sixty-eight percent of respondents were confident that their applications did not use vulnerable libraries. However, in a random scan of enterprise applications, 68% had known vulnerabilities in their open source software components.

IT managers were 2.4 times more likely than respondents working in information security to strongly agree with “We approach resolving security issues as a regular part of development “.

To innovate faster and grow at scale, organizations need to make it as easy as possible for developers to build secure and maintainable software, which includes providing them with smarter tools that provide more visibility into their systems and automate their process.

Sonatype’s eighth annual State of the Software Supply Chain report combines a wide range of public and proprietary data and analysis, including 131 billion Maven Central downloads, survey results from 662 software engineering and evaluation of 85,000 enterprise applications.

Read it full report by Sonatype.

VentureBeat’s mission is to be a digital public square for technical decision makers to learn about transformative enterprise technology and conduct transactions. Discover our Briefings.

Keep Reading

Logitech is working on a Project Starline-like video chat booth called Project Ghost

Yes, we have enough materials to power the world with renewable energy

Finley closes $17M to turn 100-page loan capital agreements into software-managed code • TechCrunch

Amazon Third Party "seller service"a large and growing portion of the company’s revenue, which is also profitable, has filled its marketplace with unwanted products (John Herrman/New York Magazine)

The best iPhone 14 camera accessories for 2023

Labor officials found Apple executives violated workers’ rights

Add A Comment

Leave A Reply Cancel Reply

Latest

At $7,400, is this 93 Mercury Capri XR2 also a premium vehicle?

January 31, 2023

6 consensus mechanisms you need to know

January 31, 2023

Nobu Hotel, Restaurant, and Residences Al Marjan Island announced for UAE

January 31, 2023
Categories
  • Automobile (1,601)
  • Cryptocurrency (1,524)
  • Fitness (647)
  • Health (693)
  • Pakistan (1,675)
  • Tech (1,565)
  • UAE (5,143)
  • World (1,632)
Other News
  • UAE
  • Pakistan
  • World
  • Health
  • Fitness
  • Automobile
  • Technology – IT World
  • Cryptocurrency
Trending News

At $7,400, is this 93 Mercury Capri XR2 also a premium vehicle?

January 31, 2023

6 consensus mechanisms you need to know

January 31, 2023

Nobu Hotel, Restaurant, and Residences Al Marjan Island announced for UAE

January 31, 2023
World News Catch Up

6 consensus mechanisms you need to know

Cryptocurrency January 31, 2023

Understanding what consensus mechanisms are and what they do can be a difficult task for…

Panama’s Crypto Bill Could Get A Second Wind In Nation’s Highest Court CryptoGlobe

January 31, 2023

SEC Settles Security Claim in LBRY Case, Community Calls It Big Victory for Crypto

January 31, 2023
© 2023 Designed by gulfnews .

Type above and press Enter to search. Press Esc to cancel.