Tag: software vulnerability

  • Scribe Security Unveils Pair of Tools to Secure Software Supply Chains

    Scribe Security Unveils Pair of Tools to Secure Software Supply Chains

    Scribe Security today unveiled a Scribe Integrity tool that scans software artifacts to make sure they comply with IT organizations’ security policies before they are integrated into an application.

    The Scribe Integrity tool authenticates open source and proprietary source code before it is uploaded into a build. It assumes that all artifacts are “guilty” until they can prove their innocence, said Rubi Arbel, CEO of Scribe Security. That approach makes it possible to ensure the integrity of the overall software supply chain is maintained in a way that doesn’t adversely impact the productivity of developers, he added.

    In addition, the company launched GitGat, an open source policy-as-code tool based on Open Policy Agent (OPA) agent software that enables DevOps teams to periodically run reports that surface insights into the security posture of code residing in GitHub repositories.

    Arbel said that, in time, GitGat’s reach will be extended to add support for additional continuous integration/continuous delivery (CI/CD) platforms.

    The first release of Scribe Integrity addresses Node.js code and the npm package manager with support for additional types of code planned.

    The Scribe Integrity tool also identifies all dependencies to enable DevOps teams to generate an accurate software bill of materials (SBOM) as each software artifact is included in the application, he noted. That’s critical because it enables developers, IT operations and cybersecurity teams to simultaneously see what artifacts, including containers, make up an application, noted Arbel. In the future, the company plans to make available a Scribe Hub that will make it easier to share insights into those software artifacts, he added.

    A series of high-profile security breaches clearly demonstrated cybercriminals’ skill at injecting malware into software artifacts and compromise any application that incorporates that artifact into an application. That malware can then be activated at some later date to potentially compromise any number of downstream applications.

    Those incidents resulted in a greater appreciation for DevSecOps best practices to maintain the integrity of software supply chains. The issue that DevOps teams are trying to address is how to build more secure applications without slowing down the rate at which those applications are built and deployed. As such, DevOps teams are adding tools to the application development process that make it easier for developers to scan code before it is included in an application and verify the integrity of any software component that becomes part of a DevOps workflow.

    It’s unknown how long it may be before the adoption of DevSecOps best practices has a meaningful impact on application security. However, waiting to focus on security until after an application has been deployed is way too late. Cybercriminals today can discover flaws and misconfigurations in applications in a matter of minutes. As more applications are deployed, developers can find themselves spending more of their time fixing vulnerabilities than they do writing new code. A new approach to building applications that are secure from the ground up is clearly required.

  • BluBracket Community Edition of Secrets Discovery Tool now Available

    BluBracket Community Edition of Secrets Discovery Tool now Available

    BluBracket today announced general availability of a community edition of a tool that employs machine learning algorithms to discover passwords, tokens and other security vulnerabilities in code.

    Prakash Linga, BluBracket’s CEO, said application secrets stored in code enable cybercriminals to compromise applications in ways that can impact an entire software supply chain. The community edition of the company’s namesake tool scans commits to determine if any new risks were introduced, and will then block the staged files from being committed. It works with any continuous integration/continuous delivery (CI/CD) platform or integrated development environment (IDE) that supports pre-commit hooks, including VSCode, Jetbrains IntelliJ and PyCharm.

    Developers are then presented with a risk score based on the number of secrets discovered in their code. For example, an active token for Amazon Web Services (AWS) would receive a high score, while a a password in a test environment would be rated low.

    The Community Edition of BluBracket can be accessed via GitHub. The free version of BluBracket can be employed to scan up to 10 repositories and sharing reports in real-time, covering more than 50 types of secrets that might be employed using any programming language.

    Linga said BluBracket also cuts down on false positives by combining machine learning algorithms with a built-in rules engine. In contrast to open source tools, BlueBracket generates far fewer false positives, said Linga.

    Linga said the Community Edition is intended to help foster adoption of DevSecOps best practices among individual developers, in hopes that when those developers are hired, their organizations eventually license the full instance of BluBracket. The company views its tools as being complementary to both tools that surface vulnerabilities in code as well as secrets management platforms, which are often not employed as widely within an organization, Linga said.

    In the wake of recent high-profile breaches that embedded malware in widely-distributed applications, there’s increased focus on securing software supply chains. In some of those instances, Linga said, it’s probable cybercriminals discovered passwords and other secrets that were inadvertently exposed in code.

    However those breaches were enabled, it is apparent cybercriminals are becoming more adept at exploiting a weakness in one application to inflict maximum damage across an entire environment. It’s hard to say exactly what role secrets discovery is playing, but cybercriminals tend to prefer the path of least resistance when it comes to exploiting application vulnerabilities.

    Of course, the hope is that adoption of DevSecOps best processes will reduce the number of breaches by shifting responsibility for cybersecurity further left toward developers. However, that’s difficult to achieve without finding the simplest way possible of getting the security tools required into the hands of the developers that need them most.

  • Top 10 Common Software Vulnerabilities

    Top 10 Common Software Vulnerabilities

    An essential part of an effective software security process is being familiar with software vulnerabilities, which are flaws or weaknesses in your code. Often, testing and manual code reviews are unable to identify every single vulnerability, which can impact the performance and security of your software. For that reason, it is important to have a working understanding of software vulnerabilities as it will enable you to more effectively manage potential security threats.

    The top 10 most common security vulnerabilities are as follows:

    1. Insufficient Logging and Monitoring: Insufficient logging and monitoring process are dangerous as they leave your data vulnerable to tampering, extraction, or even destruction.
    2. Injection Flaws: Injection flaws can trick the targeted system into executing unintended commands as well as provide untrustworthy agents access to protected data.
    3. Sensitive Data Exposure: Sensitive data—which includes addresses, passwords and account numbers—must be adequately protected against human-error and security breaches to avoid potential exposures.
    4. Using Components with Known Vulnerabilities: Components—which are made up of libraries, frameworks and other software modules—are often run on the same privileges as your application. Which means if a component is vulnerable, those weaknesses can be exploited in an effort to access your application.
    5. Cross-Site Scripting (XSS) Flaws: Cross-site scripting flaws can be exploited by untrustworthy agents in an effort to execute their own scripts in your system.
    6. Broken Authentication: If authentication and session management application functions are implemented incorrectly, a software vulnerability can be created.
    7. Broken Access Control: If user restrictions are broken, it can create a software vulnerability that can be exploited.
    8. XML External Entities (XXE): In order to properly understand an XML data, an XML parser is necessary. However, if the parser is poorly configured and the XML input that contains a reference to an external entity, it can provide a flaw that an untrustworthy agent can exploit.
    9. Security Misconfiguration: Security misconfigurations are often brought upon for numerous reasons, including: insecure default configurations, incomplete or impromptu configurations, open cloud storage, misconfigured HTTP headers and wordy error messages that contain sensitive information.
    10. Insecure Deserialization: Deserialization flaws often result in remote code executions, which enables untrustworthy agents to perform replay, injection and privilege escalation attacks.

    Prevent Software Vulnerabilities

    In order to efficiently and effectively prevent software vulnerabilities, we recommend the following best practices:

    • Establish software design requirements.
    • Use a coding standard.
    • Test your software.

    To read more, please visit: https://www.perforce.com/blog/kw/common-software-vulnerabilities