• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Google Pledges $1m to Secure Open Source Project

You are here: Home / General Cyber Security News / Google Pledges $1m to Secure Open Source Project
October 5, 2021

Google has announced economical backing for a new initiative intended to incentivize proactive security improvements to open resource code.

Not like bug bounty packages which offer you fiscal benefits to scientists who discover critical software package bugs, the Safe Open Resource (SOS) venture will do the very same for builders whose get the job done prevents big vulnerabilities showing up in the first area.

“SOS benefits a pretty broad array of improvements that proactively harden critical open up resource initiatives and supporting infrastructure from application and source chain attacks,” Google described.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“To complement present systems that reward vulnerability administration, SOS’s scope is comparatively wider in the style of function it rewards, in get to support challenge developers.”

The collection course of action for in-scope jobs will just take into account NIST recommendations and the new Presidential govt purchase on cybersecurity, as very well as criteria these as how numerous people will be affected, and how major an impression a compromise would have.

The first record of jobs contains application supply chain enhancements this kind of as hardening of CI/CD pipelines, adoption of software artifact signing and verification, and enhancements that create higher OpenSSF Scorecard results.

SOS will also glimpse at initiatives which use OpenSSF Allstar and remediate any learned issues, and kinds capable of earning a CII Very best Exercise Badge.

Google’s $1m financial commitment will enable to fund awards of $10,000 or much more for “complicated, high-effects and lasting enhancements that practically absolutely avoid big vulnerabilities in the affected code or supporting infrastructure.”

Scaled-down quantities ranging from $505 to $10,000 are available relying on the complexity and gains.

“This $1 million financial investment is just the starting — we visualize the SOS pilot software as the starting up position for potential endeavours that will ideally provide together other significant companies and convert it into a sustainable, extensive-expression initiative beneath the OpenSSF,” Google concluded.

“We welcome neighborhood feed-back and interest from some others who want to lead to the SOS application. Alongside one another we can pool our support to give back to the open resource neighborhood that makes the modern internet attainable.”

A recent report from Sonatype exposed a 650% 12 months-on-yr boost in upstream source chain attacks impacting open up resource software program parts.


Some areas of this posting are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Text Message Giant Reveals Five-Year Breach
Next Post: New Study Links Seemingly Disparate Malware Attacks to Chinese Hackers new study links seemingly disparate malware attacks to chinese hackers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.