{"id":3665,"date":"2024-05-20T19:52:11","date_gmt":"2024-05-21T00:52:11","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/openssf-siren-to-share-threat-intelligence-for-open-source-software"},"modified":"2024-05-20T19:52:11","modified_gmt":"2024-05-21T00:52:11","slug":"openssf-siren-to-share-threat-intelligence-for-open-source-software","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/20\/openssf-siren-to-share-threat-intelligence-for-open-source-software\/","title":{"rendered":"OpenSSF Siren to Share Threat Intelligence for Open Source Software"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfd407741ae55d1f0\/65e60298a44bc4040a91644a\/MaximP-email-security-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Open Source Security Foundation has launched an email mailing list to share threat intelligence regarding vulnerabilities in open source software.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Siren aims to \u201caggregate and disseminate threat intelligence\u201d to provide real-time security warning bulletins and deliver a community-driven knowledge base, according to OpenSSF. Members could use the mailing list to provide and receive information such as tactics, techniques, and procedures used in attacks on open source software, as well as indicators of compromise from real incidents.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The initiative is driven in part by the recent discovery of a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/xz-utils-backdoor-implanted-in-intricate-multi-year-supply-chain-attack\" rel=\"noopener\">backdoor in the XZ Utils library<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, when it became clear that there is no centralized method for open source projects to distribute and receive threat intelligence. As different researchers dug into the backdoor in XZ Utils, their findings were shared in various forums and independent blogs. There was no central location for people to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/xz-utils-scare-exposes-hard-truths-in-software-security\" rel=\"noopener\">find relevant information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Various industry sectors rely on information sharing and analysis centers (ISAC) to facilitate the distribution of threat information regarding attacks against that sector. The existing oss-security mailing list is useful for communicating vulnerabilities within the community, but there is a &#8220;lack of efficient channels for sharing information about exploits with a broader audience, including open source projects, distributors, security researchers, and developers,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/docs.google.com\/document\/d\/12KxpC8ecAlM68QedB_1_a26jpOYIsHVvftFea3OIGQA\/edit#heading=h.i35rc5i6altj\" rel=\"noopener\">OpenSSF said<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">OpenSSF&#8217;s hope is that the mailing list could fill this gap for open source projects and give the community a centralized location to find information about threats as they occur. Siren will not be a place to disclose new flaws, but rather a &#8220;post-disclosure means of keeping the community informed of threats and activities after the initial sharing and coordination.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Siren will be publicly available. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/lists.openssf-vuln.org\/g\/siren\" rel=\"noopener\">Registration will be required<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> only to post on the list. OpenSSF encouraged people across the community, &#8220;a developer, maintainer, or security enthusiast,&#8221; to sign up.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/openssf-siren-to-share-threat-intelligence-for-open-source-software\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Open Source Security Foundation has launched an email mailing<\/p>\n","protected":false},"author":12,"featured_media":3666,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3665","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=1600%2C1067&ssl=1",1600,1067,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=1600%2C1067&ssl=1",1600,1067,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/openssf-siren-to-share-threat-intelligence-for-open-source-software.jpg?fit=1600%2C1067&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3665"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3665\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3666"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}