Close Menu
    What's Hot

    How the S&P 500 Stock Index Became So Skewed to Tech and A.I.

    February 27, 2026

    Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

    February 27, 2026

    OpenAI Announces Major Expansion of London Office

    February 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Trend Alerts – Stay Ahead of the Trends!
    Subscribe
    • Home
    • Trending

      Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

      February 27, 2026

      OpenAI Announces Major Expansion of London Office

      February 26, 2026

      Everyone Speaks Incel Now | WIRED

      February 26, 2026

      Samsung Galaxy S26, S26+, and S26 Ultra: Specs, Features, Price, Release Date

      February 25, 2026

      H&R Block Coupons and Deals: $25 Off Tax Prep in 2026

      February 25, 2026
    • Worldwide

      Rhine Freight Market: Rising Water Levels Remove Pressure, Market Turns Defensive

      February 19, 2026

      ARA Freight Market: IE Week Dampens Demand as Rates Drift Lower

      February 18, 2026

      Rhine Freight Market: Improving Water Levels Shift the Balance Toward Softer Rates

      February 12, 2026

      ARA Freight Market: Higher Deal Count Fails to Halt Gradual Rate Softening

      February 11, 2026

      January 2026: A Volatile Start to the Year as Geopolitics Collide with Oversupply Risks

      February 6, 2026
    • Finance

      How the S&P 500 Stock Index Became So Skewed to Tech and A.I.

      February 27, 2026

      Bank not cutting your home loan rate? Should you consider loan refinancing?

      February 25, 2026

      Finance charge in credit card explained

      February 24, 2026

      How it works and why it can be dangerous

      February 23, 2026

      Bank not cutting your home loan rate? Should you refinance?

      February 22, 2026
    • Business

      5 Steps for Building Strategic Partnerships in Your Negotiations

      February 20, 2026

      How CLIMB Helped Emmanuel Aniemeke Apply Vital Business Lessons

      February 19, 2026

      How to List Certifications & Credentials on Your Resume

      February 14, 2026

      How to Build Trust in Workplace Relationships

      February 11, 2026

      5 Soft Skills to Put on a Resume & How to Prove Them

      February 10, 2026
    • News

      World’s Most Unbelievable Events That No One Expected

      March 16, 2025

      Biggest Space Discoveries That Went Viral This Year

      March 16, 2025

      AI Just Did This! The Most Shocking AI Development Yet

      March 16, 2025

      Mind-Blowing Tech Innovations That Went Viral in 2025

      March 16, 2025

      Top 10 Viral Moments That Broke the Internet in 2025

      March 16, 2025
    Trend Alerts – Stay Ahead of the Trends!
    Home»Trending»Security Researchers Warn a Widely Used Open Source Tool Poses a ‘Persistent’ Risk to the US
    Trending

    Security Researchers Warn a Widely Used Open Source Tool Poses a ‘Persistent’ Risk to the US

    Elon MarkBy Elon MarkMay 5, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Nation states take on a strategic positioning,” says George Barnes, a former deputy director at the National Security Agency, who spent 36 years at the NSA and now acts as a senior advisor and investor in Hunted Labs. Barnes says that hackers within Russia’s intelligence agencies could see easyjson as a potential opportunity for abuse in the future.

    “It is totally efficient code. There’s no known vulnerability about it, hence no other company has identified anything wrong with it,” Barnes says. “Yet the people who actually own it are under the guise of VK, which is tight with the Kremlin,” he says. “If I’m sitting there in the GRU or the FSB and I’m looking at the laundry list of opportunities… this is perfect. It’s just lying there,” Barnes says, referencing Russia’s foreign military and domestic security agencies.

    VK Group did not respond to WIRED’s request for comment about easyjson. The US Department of Defense did not respond to a request for comment about the inclusion of easyjson in its software setup.

    “NSA does not have a comment to make on this specific software,” a spokesperson for the National Security Agency says. “The NSA Cybersecurity Collaboration Center does welcome tips from the private sector—when a tip is received, NSA triages the tip against our own insights to fully understand the threat and, if corroborated, share any relevant mitigations with the community.” A spokesperson for the US Cybersecurity and Infrastructure Security Agency, which has faced upheaval under the second Trump administration, says: “We are going to refer you back to Hunted Labs.”

    GitHub, a code repository owned by Microsoft, says that while it will investigate issues and take action where its policies are broken, it is not aware of malicious code in easyjson and VK is not sanctioned itself. Other tech companies’ treatment of VK varies. After Britain sanctioned the leaders of Russian banks who own stakes in VK in September 2022, for example, Apple removed its social media app from its App Store.

    Dan Lorenc, the CEO of supply chain security firm Chainguard, says that with easyjson, the connections to Russia are in “plain sight” and that there is a “slightly higher” cybersecurity risk than those of other software libraries. He adds that the red flags around other open source technology may not be so obvious.

    “In the overall open source space, you don’t necessarily even know where people are most of the time,” Lorenc says, pointing out that many developers do not disclose their identity or locations online, and even if they do, it is not always possible to verify the details are correct. “The code is what we have to trust and the code and the systems that are used to build that code. People are important, but we’re just not in a world where we can push the trust down to the individuals,” Lorenc says.

    As Russia’s full-scale invasion of Ukraine has unfolded, there has been increased scrutiny on the use of open source systems and the impact of sanctions upon entities involved in the development. In October last year, a Linux kernel maintainer removed 11 Russian developers who were involved in the open souce project, broadly citing sanctions as the reason for the change. Then in January this year, the Linux Foundation issued guidance covering how international sanctions can impact open source, saying developers should be cautious of who they interact with and the nature of interactions.



    Source link

    Open Persistent Poses Researchers Risk Security Source Tool Warn Widely
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleCardinal Erdo of Hungary Is a Favorite of Conservatives to Become Pope
    Next Article 18 States Sue Over Trump’s Halting of Wind Power Projects
    Elon Mark
    • Website

    Related Posts

    Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

    February 27, 2026

    OpenAI Announces Major Expansion of London Office

    February 26, 2026

    Everyone Speaks Incel Now | WIRED

    February 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    TrendAlerts is your go-to platform for the latest trending news, covering global events, technology, business, entertainment, and more. Stay informed with real-time updates and in-depth analysis on what’s shaping the world today! 🚀

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 Trend Alerts. All Rights Are Reserved.
    • Home
    • Trending
    • Worldwide
    • Finance
    • Business
    • News

    Type above and press Enter to search. Press Esc to cancel.