article thumbnail

Open source developer corrupts widely-used libraries, affecting tons of projects

The Verge

A developer appears to have purposefully corrupted a pair of open-source libraries on GitHub and software registry npm — “ faker.js ” and “ colors.js ” — that thousands of users depend on, rendering any project that contains these libraries useless, as reported by Bleeping Computer. million weekly downloads on npm, and color.js

article thumbnail

Government Employees and Contractors: Attend 10 Apr Dialog With @LorenSiebert on Open Source DigitalGov Search Tech

CTOvision

The kind of things he has been involved in include helping government agencies understand the power of open source technologies for search solutions. It’s no longer enough to make our government data available for simple browsing or downloads. Popular open source search technologies. Who should attend.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Over 144,000 Phishing Packages Posted to Open-Source Repositories

SecureWorld News

Security researchers at Checkmarx and Illustria recently discovered a campaign in which a threat actor(s) managed to post over 144,000 phishing packages to popular open source platforms, including NPM, PyPi, and NuGet. The descriptions for these packages contained links to phishing campaigns.

article thumbnail

Hack together your own e-paper smartwatch with this $50 open-source kit

The Verge

If you’ve ever wanted to be like Steve Wozniak and have your own custom-made, geeky watch, Squarofumi (stylized SQFMI) may have the product for you: an open-source, Arduino-powered smartwatch with a 1.54-inch Image: SQFMI. inch e-paper screen ( via Gizmodo ).

article thumbnail

NGA and DigitalGlobe Release Powerful Application To Community Under Open Source License

CTOvision

From NGA''s Press Release: NGA, DigitalGlobe application a boon to raster data storage, processing. Releasing MrGeo helps further the agency’s goal of increasing and streamlining co-creation efforts in software and unclassified data, said Rasmussen. January 13, 2015. SPRINGFIELD, Va. —

article thumbnail

Architecture Matters in Big Data Modernization: See why in our examination of the Cloudera and Intel partnership

CTOvision

CTOlabs.com , the research arm of CTOvision.com , produced a White Paper for the federal technology community titled: Enhancing Functionality and Security of Enterprise Data Holdings: Examining new, mission-enabling design patterns made possible by the Cloudera-Intel partnership. Download the paper here: Cloudera-Intel Partnership.

CTO 280
article thumbnail

Lazarus APT Continues to Exploit Log4j Vulnerability

SecureWorld News

Log4j is a widely-used open source Java logging library, and the vulnerability allowed threat actors to execute remote code on servers, potentially leading to unauthorized access and data breaches. Among these are two remote access trojans (RATs) named NineRAT and DLRAT, and a malware downloader dubbed BottomLoader.