@OSTIFofficial is proud to share the results of our security audit of Scala, executed by a team of three auditors from Quarkslab. We want to thank our very own Derek Zimmer of OSTIF for advocating for this audit for a long time!
#OSTIF#Quarkslab#SovereignTechAgency#Scala
During a security audit of vLLM managed by https://t.co/AMH2wxZAuw, a bug was discovered through manual analysis by a senior security expert at X41 D-Sec.
#OSTIF#BadHost#vLLM#X41DSec
A lack of input sanitization on host header paths in Starlette leads to bypassing auth with a single character across a huge swath of Python LLM infrastructure.
In 2023, @DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC), a massive undertaking by dozens of organizations with the goal to safeguard open source software used in critical infrastructure throughout America. #OSTIF#DARPA#AI
With the help of Ada Logics, 7ASecurity, and the Sovereign Tech Agency, this project received expert security review, testing, and custom documentation contributing to DEfO’s ongoing development and security.
The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”).
https://t.co/jU8dgaLhoG
#OSTIF#DEfO#AdaLogics#7ASecurity#SovereignTechAgency
With that in mind, our Executive Director Derek Zimmer proposed a new program: a Bug of the Year trophy, given to the individual who finds the best bug published by OSTIF in a calendar year.
While reflecting on our past 10 years, we revisited vulnerabilities discovered during OSTIF audits. As a result of our work, several hundred bugs a year are discovered on average.
Miss our last OSTIF meetup?
You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
#OSTIF#OpenSource#bitcoin
Don't miss tomorrow's @OSTIFofficial meetup with Robin David, Software Security Researcher and Research Lead at @quarkslab , presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
#OSTIF#OpenSource#bitcoin
With the help of @7aSecurity, this project received custom security testing, documentation, and tooling contributing to Stork’s ongoing security and development work.
Full post here: https://t.co/WPzoWCeo7e
@OSTIFofficial is proud to share the results of our security audit of Stork.
Stork is an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers.
#OSTIF#7ASecurity
While there is a lot to address, an important point of this story sticks out to us at OSTIF- that it was best practices, the secondary review of code before a push, that caught this before disaster struck.
We, like everyone else, couldn't look away from the Veritasium video on the XZ vulnerability.
Watch the video here https://t.co/JQqB7r05bN to learn more details about this incredible story of open source security and community.
#OSTIF#Veritasium#XZ