Technology

Open Source Groups Warn of Potential Cybersecurity Threats

An alert issued by two prominent open-source groups, the Open Source Security Foundation and the OpenJS Foundation, has raised concerns about potential threats to critical digital infrastructure following a recent attempt to sabotage widely used software. The attempted insertion of a secret backdoor into XZ Utils, a lesser-known program integrated into Linux operating systems globally,

Open-Source-Groups-Warn-of-Potential-Cybersecurity-Threats-

Open-Source-Groups-Warn-of-Potential-Cybersecurity-Threats-

Share
Picture: Inkl
Advertisement

An alert issued by two prominent open-source groups, the Open Source Security Foundation and the OpenJS Foundation, has raised concerns about potential threats to critical digital infrastructure following a recent attempt to sabotage widely used software.

The attempted insertion of a secret backdoor into XZ Utils, a lesser-known program integrated into Linux operating systems globally, has prompted speculation that it may not be an isolated incident, according to the joint statement published on Monday.

The groups highlighted that at least three different JavaScript projects were targeted by unidentified individuals, who demanded suspicious updates or sought to become maintainers of the software in question. Given the widespread use of the JavaScript programming language in powering various aspects of the modern web, the potential impact of such infiltrations could be significant. Omkhar Arasaratnam, the General Manager of the Open Source Security Foundation, emphasized that one of the targeted packages alone saw tens of millions of downloads weekly.

However, Arasaratnam refrained from disclosing the names of the JavaScript projects, citing the need to protect an ongoing investigation into the matter. He expressed concerns that the suspected malicious actors may have aimed to build backdoors into these projects as well, though the extent of their intentions remains unclear.

In response to the threat, the OpenJS and Open Source Security Foundations have alerted the US Cybersecurity & Infrastructure Security Agency (CISA) about the suspected infiltration. As of now, the agency has not provided any immediate comment on the matter.

TechnologyAfrican startups
Greg Stewart

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Africa is getting more Big Tech investment, but the basics are still holding it back
Read nextTechnology

Africa is getting more Big Tech investment, but the basics are still holding it back

Google, Meta, Microsoft, Amazon and Starlink are putting more money into Africa's digital infrastructure. Subsea cables are reaching more parts of the continent, satellite internet is expanding and cloud companies are adding services for African customers. For businesses that have spent years dealing with unreliable connections, that is useful. There is still a problem underneath

Vutomi Manzini · 4 min readContinue reading