{"id":8766,"date":"2026-06-24T04:00:00","date_gmt":"2026-06-24T09:00:00","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=89536"},"modified":"2026-06-24T04:00:00","modified_gmt":"2026-06-24T09:00:00","slug":"open-source-security-is-posing-challenges-governments-cant-easily-solve","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2026\/06\/24\/open-source-security-is-posing-challenges-governments-cant-easily-solve\/","title":{"rendered":"Open-source security is posing challenges governments can\u2019t easily solve"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v24.5 (Yoast SEO v27.1.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ --> <title>Open-source security is posing challenges governments can&#8217;t easily solve | CyberScoop<\/title> <meta name=\"description\" content=\"An epidemic of cyberattacks exposes widening gaps in open source software security, as experts warn that U.S. government defense efforts have stalled.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/open-source-software-security-crisis\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"Open-source security is posing challenges governments can't easily solve\"> <meta property=\"og:description\" content=\"An epidemic of cyberattacks exposes widening gaps in open source software security, as experts warn that U.S. government defense efforts have stalled.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/open-source-software-security-crisis\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cyberscoop\/\"> <meta property=\"article:published_time\" content=\"2026-06-24T09:00:00+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg\"> <meta property=\"og:image:width\" content=\"1920\"> <meta property=\"og:image:height\" content=\"1017\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Tim Starks\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@timstarks\"> <meta name=\"twitter:site\" content=\"@CyberScoopNews\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1778775768g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1780345453g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1782279570g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=9519dd464d894b805a10\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" title=\"JSON\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/89536\"><meta name=\"generator\" content=\"WordPress 6.8.5\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=89536\">\n<link rel=\"alternate\" title=\"oEmbed (JSON)\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fopen-source-software-security-crisis%2F\">\n<link rel=\"alternate\" title=\"oEmbed (XML)\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fopen-source-software-security-crisis%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"wp-singular post-template-default single single-post postid-89536 single-format-standard wp-theme-scoopnewsgroup wp-child-theme-cyberscoop\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/open-source-software-security-crisis\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"27.032397408207\">\n<div class=\"single-article__header-content\" readability=\"37.507177033493\">\n<p> A diffuse landscape, fruitful targets, companies not stepping up, AI\u2019s influence and flagging U.S. government efforts all figure into a shifting threat. <\/p>\n<p> <!-- Listen to this article section --> <!-- Audio Element --><br \/>\n<audio id=\"audio-player\" src=\"https:\/\/wp-tts-cdn.api.scpnewsgrp.com\/cyberscoop\/89536\/english.openai.mp3\"><\/audio> <\/p>\n<div readability=\"11\">\n<div>\n<p>Listen to this article<\/p>\n<p> <!-- Countdown Timer --> <\/p>\n<p>0:00<\/p>\n<\/p><\/div>\n<p> <!-- Tooltip --> <\/p>\n<p> <span id=\"tts-tooltip\">Learn more.<\/span> <span> This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. <\/span> <\/p>\n<\/div>\n<p> <!-- End of audio player --> <\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"339\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve.jpg?resize=640%2C339&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=300,159 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=768,407 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=1024,542 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=1536,814 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=600,318 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=1200,636 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-2.jpg?resize=1500,795 1500w\" sizes=\"(max-width: 1200px) 100vw, 1200px\"><figcaption> Nadezhda Buravleva, iStock\/Getty Images Plus <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"145.60135543179\"><body readability=\"304.10456954591\"><\/p>\n<p>An <a href=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/\">epidemic of cyberattacks<\/a> on open-source software has mounted in recent months, making clear how uniquely difficult it is to protect the publicly available code, from both a policy and a technical perspective, that serves as the foundation for so much of the digital world.<\/p>\n<p>While open-source software security got a boost in attention under President Joe Biden \u2014 whose administration grappled with the fallout from the potentially catastrophic Log4j flaw that emerged in 2021 \u2014 a number of open-source experts say that government protection efforts have suffered setbacks under President Donald Trump. Many also say companies that heavily rely on open-source software, which is basically all of them, haven\u2019t shouldered enough of the responsibility for safeguarding it.<\/p>\n<p>\u201cWhat we\u2019re seeing is years of lack of investment sustainment in open-source software that is finally starting to catch up to us, where it seems like every week there\u2019s a new supply chain compromise,\u201d said Jack Cable, who held a role at the Cybersecurity and Infrastructure Security Agency where he worked on open-source security before departing under Trump.<\/p>\n<p>The advancements of frontier artificial intelligence models stand to exacerbate the risk further, while simultaneously illustrating what makes defending open source difficult: Project Glasswing <a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\">said shortly after its announcement<\/a> that it had uncovered 6,202 high- or critical-severity vulnerabilities in a scan of more than 1,000 open-source projects, but that it had disclosed only 502 of them to open-source project maintainers and only 75 had been patched as of May 22 (albeit some due to typical patching lagtimes).<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>At the same time, there are questions about how much the government can help, even as overseas governments seek to focus on open-source security.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-the-evolution-of-open-source-risk-nbsp\">The evolution of open-source risk&nbsp;<\/h4>\n<p>There are a series of factors contributing to the current threat to open-source software, experts say.<\/p>\n<p>One is simply that attackers go to the area where they can get the highest return on their work. Compromising open-source software gives them the chance to get into the supply chain and exploit additional targets.<\/p>\n<p>\u201cTwenty years ago, open source was still fairly niche,\u201d said \u00c6va Black, who also worked on open-source security at CISA but left when Trump came back into power. \u201cThe potential blast radius if you managed to compromise open source was relatively small, because back then the world didn\u2019t run on open source. Now almost everything runs on open source,\u201d she said, from modern cars to satellites.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Another part is the nature of open-source software itself.<\/p>\n<p>\u201cIt\u2019s a symptom [of having] lots of open source [that] is a little bit under-maintained or not cared for enough, so that we spend too little effort and money and infrastructure on them,\u201d said Daniel Stenberg, who is the creator and maintainer of cURL, a popular open-source project. \u201cLots of open source is being maintained by small teams, lots of volunteers, and I think that that\u2019s a tough situation.\u201d<\/p>\n<p>That doesn\u2019t mean the maintainers are to blame, Stenberg said. The companies that rely on open-source need to be diligent about using it, Black said.<\/p>\n<p>\u201cWhat we\u2019re seeing in that realm right now is not new; it is more advanced and far more widespread,\u201d she said. \u201cThe problem remains that companies who use open source \u2014 because open source is by far the most efficient way to collaborate on non-product value features \u2014 most companies are not implementing a responsible and safe utilization pathway.\u201d<\/p>\n<p>Open-source projects lack a systematic way to handle coordinated vulnerability disclosures, unlike companies or industry groups with formal processes, said Dan Lorenc, CEO and co-founder of Chainguard. Project maintainers sometimes aren\u2019t reachable, and those who are available are flooded with reports, many of them unverified findings from AI tools that waste their time without adding value..<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Of course, some of those vulnerability reports turn out to be legitimate. \u201cMythos and AI models have contributed to an uptick in the number of vulnerabilities and things that we\u2019re able to find\u201d in open-source software, said Alex Zenia, chief technology officer for the cybersecurity company Edera.<\/p>\n<p>All of that leaves more room for companies, non-profits and world governments to improve open-source security.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-a-moment-of-momentum\">A moment of momentum<\/h4>\n<p>While open-source software security isn\u2019t a new issue, the 2021 discovery of the Log4j flaw sounded alarms within the cybersecurity community. Jen Easterly, then the director of CISA, <a href=\"https:\/\/cyberscoop.com\/log4j-cisa-easterly-most-serious\/\">called it<\/a> \u201cone of the most serious I\u2019ve seen in my entire career, if not the most serious,\u201d with the potential to affect hundreds of millions of devices given the ubiquitous nature of the popular open-source logging library.<\/p>\n<p>A year later, the Cyber Safety Review Board <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CSRB-Report-on-Log4-July-11-2022_508.pdf\">released its report<\/a> on the incident, concluding that swift action from industry and government averted a disaster. But the incident \u201ccalled attention to security risks unique to the thinly-resourced, volunteer-based open source community,\u201d it wrote. \u201cThis community is not adequately resourced to ensure that code is developed pursuant to industry-recognized secure coding practices and audited by experts.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The U.S. government actions after included some steps focused specifically on open-source software such as creation of the <a href=\"https:\/\/cyberscoop.com\/white-house-securing-open-source-software\/\">Open-Source Software Security Initiative<\/a> and hires of well-regarded open-source security experts at CISA such as Black, but also some steps that could be applied more generally and still help with open-source security, such as greater promotion of secure-by-design, memory-safe languages and software bills of materials (SBOMs).<\/p>\n<p>Some of the Biden administration work on open-source security started before Log4j, such as provisions from an <a href=\"https:\/\/www.presidency.ucsb.edu\/documents\/executive-order-14144-strengthening-and-promoting-innovation-the-nations-cybersecurity\">executive order<\/a> he issued in 2021 that directed CISA along with the Office of Management and Budget and General Services Administration to issue guidance to agencies.&nbsp;<\/p>\n<p>The administration\u2019s <a href=\"https:\/\/bidenwhitehouse.archives.gov\/wp-content\/uploads\/2023\/03\/National-Cybersecurity-Strategy-2023.pdf\">2023 cybersecurity strategy<\/a> also stepped into the long, thorny discussions over software liability, with a mention of open-source security: \u201cResponsibility must be placed on the stakeholders most capable of taking action to prevent bad outcomes, not on the end-users that often bear the consequences of insecure software nor on the open-source developer of a component that is integrated into a commercial product.\u201c The Biden administration always indicated that addressing software liability would take a prolonged battle ahead.<\/p>\n<p>Under Trump, many of the Biden administration\u2019s efforts have languished. CISA\u2019s splashy hires on open-source are gone, including Black, Tim Pepper and Anjana Rajan. Also departed are leading figures on secure-by-design and SBOMs, with CISA personnel cutbacks slicing deep.&nbsp;<\/p>\n<p>No one has seen any sign that the national cyber director-led Open-Source Software Security Initiative is active, with few participants remaining in government today. The Trump administration <a href=\"https:\/\/cyberscoop.com\/trump-cybersecurity-strategy\/\">cyber strategy<\/a> doesn\u2019t mention open-source.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cThe loss of open-source experts at CISA \u201cis unfortunate, and it will be hard for the government to try to rebuild capacity, but I do think now more than ever CISA has a core role to play to secure open source software,\u201d Cable said.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-the-pressure-is-mounting\">The pressure is mounting<\/h4>\n<p>It\u2019s not that the issue is getting zero attention from those in a position to make a difference. Nick Andersen, the acting director of CISA, said last month that open-source security was an area of <a href=\"https:\/\/cyberscoop.com\/cisa-chief-frets-about-open-source-vulnerabilities-delayed-security-improvements\/\">particular concern<\/a> for him.<\/p>\n<p>Andersen responded to concerns about CISA staffing levels on open-source security and spoke more broadly on the topic in a statement to CyberScoop.<\/p>\n<p>\u201cAs artificial intelligence and other technologies have the power to transform how vulnerabilities are discovered and exploited, CISA recognizes that the open source software (OSS) that underpins much of the nation\u2019s critical infrastructure will need to be hardened,\u201d he said. \u201cCISA actively collaborates with our partners on shared priorities, including OSS security, to ensure time and resources are spent where they matter the most.&nbsp; We have an immensely talented team, but are also accelerating our hiring in critical areas, to strengthen the nation\u2019s defenses against cyber threats.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The Office of the National Cyber Director did not respond to requests for comment.<\/p>\n<p>There\u2019s been some activity on Capitol Hill, too. The <a href=\"https:\/\/www.congress.gov\/bill\/118th-congress\/senate-bill\/917\/text\">Securing Open Source Software Act<\/a>, which Cable worked on during a stint as a Senate staffer, would direct CISA and other agencies to take actions to mitigate open-source software security risks, but the legislation has stalled since <a href=\"https:\/\/www.washingtonpost.com\/politics\/2022\/09\/22\/senators-introduce-bill-protect-open-source-software\/\">its introduction<\/a> in 2022. A portion of the bill, however, was included in the Department of Homeland Security funding law Trump signed in April, <a href=\"https:\/\/docs.house.gov\/billsthisweek\/20260119\/DEF%20LHHS%20HS%20THUD%20-%20JES%20-%20Division%20C%20-%20Homeland%20-%201-19-2026%20-%20Reduced%20File%20Size_.pdf\">directing CISA<\/a> to brief Congress on the value of establishing something like an <a href=\"https:\/\/en.wikipedia.org\/wiki\/Open_Source_Program_Office\">open source program office<\/a>, which some companies use to manage open source within a given firm.<\/p>\n<p>Senate Intelligence Committee Chairman Tom Cotton, R-Ark., has <a href=\"https:\/\/cyberscoop.com\/tom-cotton-open-source-software-foreign-influence-national-cyber-director\/\">pushed the executive branch<\/a> to improve its awareness of foreign adversaries playing roles in open-source software used by national security-focused agencies.<\/p>\n<p>The annual defense policy bill in the House calls on the Defense Department\u2019s chief information officer to report to Congress on a plan to secure open-source software supply chains, saying lawmakers are \u201cconcerned that the Department lacks sufficient visibility into the origins, maintenance, and security of OSS applications and software dependencies.\u201d<\/p>\n<p>That defense authorization bill language is \u201creally beneficial, and I think it signals acknowledgement of this changing of culture\u201d around open-source security risks, said Hayden Smith, founder of HuntedLabs, whose company <a href=\"https:\/\/www.businesswire.com\/news\/home\/20250319842719\/en\/Red-Cell-Partners-Launches-Hunted-Labs-to-Harden-Software-Supply-Chains-and-Protect-Organizations-from-Attacks\">won a contract<\/a> with the Space Development Agency on supply chain security \u2014 agency work that the defense bill singled out.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cThe report language is the first time the Hill is trying to get a true handle on foreign influence in open source code where they have oversight,\u201d he said, saying it was a \u201cpiece of the puzzle\u201d along with Cotton\u2019s letter and <a href=\"https:\/\/media.defense.gov\/2025\/Jul\/22\/2003759081\/-1\/-1\/1\/ENHANCING-SECURITY-PROTOCOLS-FOR-THE-DEPARTMENT-OF-DEFENSE.PDF\">a memo<\/a> from Secretary of Defense Pete Hegseth last year about foreign influence in the Pentagon supply chain. \u201cIt\u2019s good and would trickle down into everyone who provides software to the department.\u201d<\/p>\n<p>Zenia, though, believes trying to isolate China from open-source systems isn\u2019t in and of itself a good idea.&nbsp;<\/p>\n<p>\u201cI don\u2019t think that that makes a lot of sense, because they\u2019re actually pretty good things that people contribute to open source,\u201d she said. \u201cNot everyone is malicious, and what are we going to do, spy on every single open source maintainer?\u201d It\u2019s more about doing things like making sure that highly-classified systems are set up in a separate way, she said.<\/p>\n<p>Europe is also taking action to secure open-source software that the United States doesn\u2019t seem ready or willing to do right now. Germany, for instance, <a href=\"https:\/\/interoperable-europe.ec.europa.eu\/collection\/open-source-observatory-osor\/document\/funding-open-source-case-study-sovereign-tech-fund\">devotes grants<\/a> to the security of <a href=\"https:\/\/www.prototypefund.de\/en\">open-source projects<\/a>, although Stenberg pointed out that sometimes money doesn\u2019t equate to maintainers being able to fix flaws more quickly, depending on the project\u2019s size.<\/p>\n<p>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-open-source\">Cyber Resilience Act<\/a> (CRA) adopted by the Council of the European Union in 2024 could offer another road on open-source security. The CRA requires those who use open-source software products as part of any <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-manufacturers\">commercial activity<\/a> to take certain security measures.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Black said that when she was at CISA, there were discussions between the agency and European counterparts about finding compatible ideas on open-source security, but that momentum died with the Trump administration.<\/p>\n<p>But \u201cEurope kept rolling, and now has in place a new legal framework that is set to really reshape open-source security for potentially the whole world, but certainly for anyone who wants to work with Europe on open source,\u201d she said.<\/p>\n<p>Lorenc <a href=\"https:\/\/www.chainguard.dev\/unchained\/the-hardest-fork\">recently wrote<\/a> that \u201copen source isn\u2019t governable.\u201d He said an organization like a neutral nonprofit, possibly using some government funding, should take responsibility for things like coordinating vulnerability disclosure into one pipeline. He also said there needs to be one authority in charge of \u201cforking\u201d \u2014 that is, taking a project and assigning stewardship elsewhere \u2014 when a maintainer isn\u2019t responsive to vulnerabilities.&nbsp;<\/p>\n<p>There are differing opinions on how much past government warnings, advisories and guidance have helped. Smith gave some credit to government agencies that \u201chave all responded to open source attacks using the means they have.\u201d<\/p>\n<p>Stenberg said that \u201cI don\u2019t think they make any big dent at all in the big scheme of things.\u201d They might get some attention initially, \u201cthen two years later we all forgot about them, and they actually didn\u2019t change much.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Ideally, everyone could get on the same page, Zenia said. \u201cThe best way to do this is if people actually collaborated on a global scale on some sort of regulation around this, but that seems nearly impossible at the current moment,\u201d she said. (The United Nations\u2019 <a href=\"https:\/\/www.unopensource.org\/\">Open Source Week<\/a> runs all this week.)<\/p>\n<p>But if there\u2019s an upside to the spate of attacks on open-source software, it\u2019s the energy it gives to how better to secure it, Lorenc said, invoking the political saying to never let a good crisis go to waste.<\/p>\n<p>\u201cEveryone knows the industry has to change,\u201d he said. \u201cThis is a really good crisis, and the right things are happening in the right places, and organizations are rethinking their culture around software development, and they know what they have to do. It\u2019s just something that\u2019s never been top of the priority list for the last 10 years. Now it is, and they\u2019re doing it, and it\u2019s, \u2018Can we do it fast enough?\u2019\u201d<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\">\n<div class=\"author-card\" readability=\"7.7216117216117\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/open-source-security-is-posing-challenges-governments-cant-easily-solve-1.jpg?w=640&#038;ssl=1\" alt=\"Tim Starks\"> <\/figure>\n<\/p><\/div>\n<div class=\"author-card__details\" readability=\"10.901098901099\">\n<h4 class=\"author-card__name\">Written by Tim Starks<\/h4>\n<p> Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he&#8217;s covered cybersecurity since 2003. Email Tim here: <a href=\"mailto:tim.starks@cyberscoop.com\">tim.starks@cyberscoop.com<\/a>. <\/div>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<p> <!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/open-source-software-security-crisis\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Open-source security is posing challenges governments can&#8217;t easily solve |<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6911,235,622,3687,655,1072,6912,757,5623,452,1351,293,5245,1024,1599,5086,302,1733,117,6913,3490,722,3427,1304,3287,656,2560,1571,521,1073,3288,3745,439,6331,5889,1276,2054,310,2565,290,871],"tags":[6914,236,627,3689,657,1075,6915,759,5626,454,1353,299,5247,1025,1601,5088,306,1735,119,6916,3491,723,3429,1306,3289,658,2576,1572,524,1076,3290,3751,443,6336,5895,1278,2055,311,2581,296,872],"class_list":["post-8766","post","type-post","status-publish","format-standard","hentry","category-aeva-black","category-ai","category-biden-administration","category-chainguard","category-congress","category-curl","category-cyber-resilience-act","category-cyber-safety-review-board","category-cyber-strategy","category-cybersecurity-and-infrastructure-security-agency-cisa","category-department-of-defense-dod","category-department-of-homeland-security-dhs","category-edera","category-europe","category-executive-order","category-general-services-administration","category-geopolitics","category-germany","category-government","category-huntedlabs","category-jack-cable","category-jen-easterly","category-liability","category-log4j","category-memory-safe-language","category-national-cyber-director","category-nick-andersen","category-office-of-management-and-budget","category-office-of-the-national-cyber-director","category-open-source","category-open-source-software","category-pete-hegseth","category-policy","category-project-glasswing","category-sbom","category-secure-by-design","category-senate-intelligence-committee","category-technology","category-tom-cotton","category-trump-administration","category-united-nations","tag-aeva-black","tag-ai","tag-biden-administration","tag-chainguard","tag-congress","tag-curl","tag-cyber-resilience-act","tag-cyber-safety-review-board","tag-cyber-strategy","tag-cybersecurity-and-infrastructure-security-agency-cisa","tag-department-of-defense-dod","tag-department-of-homeland-security-dhs","tag-edera","tag-europe","tag-executive-order","tag-general-services-administration","tag-geopolitics","tag-germany","tag-government","tag-huntedlabs","tag-jack-cable","tag-jen-easterly","tag-liability","tag-log4j","tag-memory-safe-language","tag-national-cyber-director","tag-nick-andersen","tag-office-of-management-and-budget","tag-office-of-the-national-cyber-director","tag-open-source","tag-open-source-software","tag-pete-hegseth","tag-policy","tag-project-glasswing","tag-sbom","tag-secure-by-design","tag-senate-intelligence-committee","tag-technology","tag-tom-cotton","tag-trump-administration","tag-united-nations"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/aeva-black\/\" rel=\"category tag\">\u00c6va Black<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ai\/\" rel=\"category tag\">AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/biden-administration\/\" rel=\"category tag\">Biden administration<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/chainguard\/\" rel=\"category tag\">Chainguard<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/congress\/\" rel=\"category tag\">Congress<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/curl\/\" rel=\"category tag\">curl<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cyber-resilience-act\/\" rel=\"category tag\">Cyber Resilience Act<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cyber-safety-review-board\/\" rel=\"category tag\">Cyber Safety Review Board<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cyber-strategy\/\" rel=\"category tag\">cyber strategy<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity-and-infrastructure-security-agency-cisa\/\" rel=\"category tag\">Cybersecurity and Infrastructure Security Agency (CISA)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/department-of-defense-dod\/\" rel=\"category tag\">Department of Defense (DOD)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/department-of-homeland-security-dhs\/\" rel=\"category tag\">Department of Homeland Security (DHS)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/edera\/\" rel=\"category tag\">Edera<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/europe\/\" rel=\"category tag\">Europe<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/executive-order\/\" rel=\"category tag\">Executive order<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/general-services-administration\/\" rel=\"category tag\">General Services Administration<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/geopolitics\/\" rel=\"category tag\">Geopolitics<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/germany\/\" rel=\"category tag\">germany<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/government\/\" rel=\"category tag\">Government<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/huntedlabs\/\" rel=\"category tag\">HuntedLabs<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/jack-cable\/\" rel=\"category tag\">Jack Cable<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/jen-easterly\/\" rel=\"category tag\">Jen Easterly<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/liability\/\" rel=\"category tag\">liability<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/log4j\/\" rel=\"category tag\">log4j<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/memory-safe-language\/\" rel=\"category tag\">memory safe language<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/national-cyber-director\/\" rel=\"category tag\">National Cyber Director<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/nick-andersen\/\" rel=\"category tag\">Nick Andersen<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/office-of-management-and-budget\/\" rel=\"category tag\">office of management and budget<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/office-of-the-national-cyber-director\/\" rel=\"category tag\">Office of the National Cyber Director<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/open-source\/\" rel=\"category tag\">open source<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/open-source-software\/\" rel=\"category tag\">open source software<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/pete-hegseth\/\" rel=\"category tag\">Pete Hegseth<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/policy\/\" rel=\"category tag\">Policy<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/project-glasswing\/\" rel=\"category tag\">Project Glasswing<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/sbom\/\" rel=\"category tag\">SBOM<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/secure-by-design\/\" rel=\"category tag\">secure-by-design<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/senate-intelligence-committee\/\" rel=\"category tag\">Senate Intelligence Committee<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/technology\/\" rel=\"category tag\">Technology<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/tom-cotton\/\" rel=\"category tag\">tom cotton<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/trump-administration\/\" rel=\"category tag\">Trump administration<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/united-nations\/\" rel=\"category tag\">United Nations<\/a>","tag_info":"United Nations","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=8766"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8766\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=8766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=8766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=8766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}