Skip to main content

Report Shines Spotlight on 91 Vulnerabilities Fixed in Latest Update to Spring Framework

A report published by Sonatype identifies more than 91 vulnerabilities that have been remediated in the latest update to the open source Spring framework for deploying Java applications mashed available by Broadcom earlier this month.

Released earlier this month, the 91 vulnerabilities affect 209,569 software components that will need to be updated.

Sonatype CTO Brian Fox said this large number of vulnerabilities that are being simultaneously released is another indication the providers of major software platforms are racing to pay down massive amounts of technical debt before vulnerabilities are discovered and exploited by cybercriminals that are gaining access to advanced artificial intelligence (AI) models.

Providers of platforms such as Spring already have access to those same AI models, which has given them a head start to find and remediate vulnerabilities before adversaries exploit them. In fact, Broadcom between March and April increased the number of advisories it has issued by more than 1,700%, according to the Sonatype report.

DevSecOps teams, in the meantime, are being tasked with making often simultaneous large-scale updates to multiple frameworks and platforms as providers rush to pay down technical debt that has been allowed to accrue for decades, noted Fox. Those teams, as a result, will need to find ways to automate the deployment of what will be a wave of patches that will need to be installed as quickly as possible. In many instances, DevSecOps teams will find they will be coping with tidal waves of updates to frameworks and platforms for multiple years to come, noted Fox.

Eventually, however, there can only be so many issues to fix, so following those waves of updates, the overall state of application security should substantially improve, he added. In the meantime, however, instead of applying patches to applications a couple of days a month, DevSecOps teams for the foreseeable future may find that they now need to continuously update applications, said Fox.

The challenge, of course, is that today exploits in many cases are being built faster than a patch can be created and applied. Adversaries are also becoming more adept at using AI to chain together low-level vulnerabilities to create a more lethal exploit. As such, DevSecOps teams are likely going to need to be able to apply virtual patches and other controls to mitigate threats while waiting for patches that, with the aid of AI coding tools, will now be made available much faster.

The proverbial fly in that ointment is that many of the maintainers of smaller open-source software projects that an application may depend on may not be able to keep pace. Multiple initiatives have been launched to aid those maintainers; however, many of those projects were created by a volunteer labor force that might not have the time, resources, or inclination to build, test and apply a software patch in a matter of days or, if needed, hours. Many enterprise IT organizations may need to rationalize the amount of open source software they have deployed because, as an unpaid labor force to keep pace with building, testing and applying patches is silly on its face, noted Fox.

At this juncture, it may not be possible to fix every application before it is exploited. Hopefully, however, organizations will be able to prioritize making updates to their most critical applications to, at the very least, limit the potential havoc that otherwise will most certainly soon ensue.



from DevOps.com https://ift.tt/4dw5XVf

Comments

Popular posts from this blog

AWS Adds Agentic Workspace to Kiro AI Coding Tool

Amazon Web Services (AWS) this week added an open source workspace for its Kiro artificial intelligence (AI) coding tool that enables application developers to asynchronously assign tasks to an AI agent that is capable of autonomously performing tasks, such as testing code as it is created, in a way that maintains context across multiple sessions. Darko Mesaros, a distinguished developer advocate at AWS, said the Kiro Crew workspace is also capable of creating reusable AI skills by observing the tasks developers assign to Kiro as they write code. Kiro Crew orchestrates agents using the Agent Client Protocol (ACP) to ensure every step is observable in real time as sub-agents are spawned. For example, developers can also hand off a ticket queue to Kiro Crew for it to triage issues and flag what needs their attention or ask it to investigate the root cause of an incident while a developer continues to work on another task. An Activity view shows each agent’s reasoning, every tool call,...

Exadel Records Strong Year with Surge in Client Roster, Additions to Executive Team and Record-Breaking Company Growth

Success comes from growing need for digital transformation solutions and services amidst the COVID-19 pandemic WALNUT CREEK, Calif., January 12, 2021 — Exadel (www.exadel.com), a global provider of digital engineering solutions and services, announces a successful 2020 including a burgeoning client portfolio, continued growth, including new executive team members and 2020 sales projections. This year, […] The post Exadel Records Strong Year with Surge in Client Roster, Additions to Executive Team and Record-Breaking Company Growth appeared first on DevOps.com . from DevOps.com https://ift.tt/2LMO6eg

CircleCI CEO Sees Growing Need for Developer Experience Engineers

There is no shortage of titles to go with all the tasks that make up a DevOps workflow, but given the critical role developers now play within any organization, it might be time for organizations to start creating a developer experience engineer (DXE) function within DevOps teams that is specifically tasked with increasing developer productivity. […] The post CircleCI CEO Sees Growing Need for Developer Experience Engineers appeared first on DevOps.com . from DevOps.com https://ift.tt/2UGhIhX