Close Menu
Newstech24.com
  • Home
  • News
  • Arabic News
  • Technology
  • Economy & Business
  • Sports News
What's Hot

RTX: Backlog Power And Tariff Challenges Form Maintain Ranking

June 25, 2025

الذهب يرتفع مع تراجع الدولار وعوائد سندات الخزانة الأمريكية

June 25, 2025

 السفارة الأمريكية في إسرائيل تعلن رفع القيود واستئناف العمل مع استمرار الحذر الأمني

June 25, 2025
Facebook X (Twitter) Instagram
Wednesday, June 25
Facebook X (Twitter) Instagram
Newstech24.com
  • Home
  • News
  • Arabic News
  • Technology
  • Economy & Business
  • Sports News
Newstech24.com
Home»Technology»Security Researchers Warn a Widely Used Open Source Tool Poses a ‘Persistent’ Risk to the US
Technology

Security Researchers Warn a Widely Used Open Source Tool Poses a ‘Persistent’ Risk to the US

AdminBy AdminMay 5, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Security Researchers Warn a Widely Used Open Source Tool Poses a 'Persistent' Risk to the US
Share
Facebook Twitter LinkedIn Pinterest Email

“Nation states take on a strategic positioning,” says George Barnes, a former deputy director at the National Security Agency, who spent 36 years at the NSA and now acts as a senior advisor and investor in Hunted Labs. Barnes says that hackers within Russia’s intelligence agencies could see easyjson as a potential opportunity for abuse in the future.

“It is totally efficient code. There’s no known vulnerability about it, hence no other company has identified anything wrong with it,” Barnes says. “Yet the people who actually own it are under the guise of VK, which is tight with the Kremlin,” he says. “If I’m sitting there in the GRU or the FSB and I’m looking at the laundry list of opportunities… this is perfect. It’s just lying there,” Barnes says, referencing Russia’s foreign military and domestic security agencies.

VK Group did not respond to WIRED’s request for comment about easyjson. The US Department of Defense did not respond to a request for comment about the inclusion of easyjson in its software setup.

“NSA does not have a comment to make on this specific software,” a spokesperson for the National Security Agency says. “The NSA Cybersecurity Collaboration Center does welcome tips from the private sector—when a tip is received, NSA triages the tip against our own insights to fully understand the threat and, if corroborated, share any relevant mitigations with the community.” A spokesperson for the US Cybersecurity and Infrastructure Security Agency, which has faced upheaval under the second Trump administration, says: “We are going to refer you back to Hunted Labs.”

GitHub, a code repository owned by Microsoft, says that while it will investigate issues and take action where its policies are broken, it is not aware of malicious code in easyjson and VK is not sanctioned itself. Other tech companies’ treatment of VK varies. After Britain sanctioned the leaders of Russian banks who own stakes in VK in September 2022, for example, Apple removed its social media app from its App Store.

Dan Lorenc, the CEO of supply chain security firm Chainguard, says that with easyjson, the connections to Russia are in “plain sight” and that there is a “slightly higher” cybersecurity risk than those of other software libraries. He adds that the red flags around other open source technology may not be so obvious.

“In the overall open source space, you don’t necessarily even know where people are most of the time,” Lorenc says, pointing out that many developers do not disclose their identity or locations online, and even if they do, it is not always possible to verify the details are correct. “The code is what we have to trust and the code and the systems that are used to build that code. People are important, but we’re just not in a world where we can push the trust down to the individuals,” Lorenc says.

As Russia’s full-scale invasion of Ukraine has unfolded, there has been increased scrutiny on the use of open source systems and the impact of sanctions upon entities involved in the development. In October last year, a Linux kernel maintainer removed 11 Russian developers who were involved in the open souce project, broadly citing sanctions as the reason for the change. Then in January this year, the Linux Foundation issued guidance covering how international sanctions can impact open source, saying developers should be cautious of who they interact with and the nature of interactions.


{content}

Source: {feed_title}

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
Open Persistent Poses researchers Risk Security source Tool warn Widely
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Admin
  • Website

Related Posts

Ironheart evaluate: a reminder that Marvel’s younger heroes are the long run

June 25, 2025

Most Britons view US as safety menace after Trump’s election

June 24, 2025

DJI ‘stays dedicated to the US market’ as cabinets go naked of drones

June 24, 2025
Leave A Reply Cancel Reply

Don't Miss
Economy & Business

RTX: Backlog Power And Tariff Challenges Form Maintain Ranking

By AdminJune 25, 20250

RTX: Backlog Power And Tariff Challenges Form Maintain Ranking

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X

الذهب يرتفع مع تراجع الدولار وعوائد سندات الخزانة الأمريكية

June 25, 2025

 السفارة الأمريكية في إسرائيل تعلن رفع القيود واستئناف العمل مع استمرار الحذر الأمني

June 25, 2025

ترامب يهاجم تغطية “سي إن إن” و”نيويورك تايمز” للضربات على إيران

June 25, 2025

D-backs’ Ketel Marte in tears after fan’s taunt about late mother

June 25, 2025

تشيلسي يفوز بثلاثية على الترجي ويحرم العرب من مقعد جديد في دور الـ16 بكأس العالم للأندية

June 25, 2025

استشهاد مسنة برصاص الاحتلال في مخيم شعفاط شمال القدس

June 25, 2025

Whale-watching the stablecoin commerce in ersatz roubles for sort-of {dollars}

June 25, 2025

معاقبة نادي أولمبيك ليون الفرنسي بالهبوط للدرجة الثانية

June 25, 2025

Chelsea 3-0 ES Tunis (Jun 24, 2025) Sport Evaluation

June 25, 2025
Advertisement
About Us
About Us

NewsTech24 is your premier digital news destination, delivering breaking updates, in-depth analysis, and real-time coverage across sports, technology, global economics, and the Arab world. We pride ourselves on accuracy, speed, and unbiased reporting, keeping you informed 24/7. Whether it’s the latest tech innovations, market trends, sports highlights, or key developments in the Middle East—NewsTech24 bridges the gap between news and insight.

Company
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Disclaimer
  • Terms Of Use
Latest Posts

RTX: Backlog Power And Tariff Challenges Form Maintain Ranking

June 25, 2025

الذهب يرتفع مع تراجع الدولار وعوائد سندات الخزانة الأمريكية

June 25, 2025

 السفارة الأمريكية في إسرائيل تعلن رفع القيود واستئناف العمل مع استمرار الحذر الأمني

June 25, 2025

ترامب يهاجم تغطية “سي إن إن” و”نيويورك تايمز” للضربات على إيران

June 25, 2025

D-backs’ Ketel Marte in tears after fan’s taunt about late mother

June 25, 2025
Newstech24.com
Facebook X (Twitter) Tumblr Threads RSS
  • Home
  • News
  • Arabic News
  • Technology
  • Economy & Business
  • Sports News
© 2025 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.