Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Grab it
Learn about a critical cybersecurity incident in a 45-minute conference talk that examines the social engineering takeover attempts targeting open source projects in early 2024. Explore how these attacks exposed systemic vulnerabilities in open source security management and challenged traditional assumptions about the open source community's immunity to cyber threats. Discover how critical open source projects became potential vectors for industrial espionage, ransomware attacks, and cyberwarfare, necessitating enhanced security practices comparable to those of major organizations. Examine the unique challenges of implementing robust security measures while maintaining the distributed nature and volunteer-based model of open source communities. Through a detailed post-mortem analysis of the OpenJS Foundation attack, gain insights into industry gaps and explore solutions for improving security at scale while preserving the essential characteristics of open source communities that drive innovation.
Read more
The Missing Post Mortem: Social Engineering Attacks on Open Source Projects