Connect with us

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website. .

Top Stories

BLACK DUCK RELEASES THREAT CHECK FOR STRUTS; FREE-USE TOOL ALLOWS ORGANISATIONS WORLDWIDE TO AUTO-DETECT EQUIFAX VULNERABILITY

BLACK DUCK RELEASES THREAT CHECK FOR STRUTS; FREE-USE TOOL ALLOWS ORGANISATIONS WORLDWIDE TO AUTO-DETECT EQUIFAX VULNERABILITY

CEO – “Equifax breach shouldn’t have happened. Further exploits must be avoided”

Black Duck, the global leader in automated solutions for securing and managing open source software, today announced availability of a free-use tool that enables organisations to determine if they are at risk from the Apache Struts vulnerability that was exploited in the recent, high-profile Equifax breach.

Black Duck said Threat Check for Struts can rapidly and accurately analyse applications or containers to detect Struts vulnerabilities, including CVE-2017-5638 that was exploited at Equifax, resulting in the theft of the personal data of 143 million consumers.

“The Equifax breach never should have happened,” said Black Duck CEO Lou Shipley. “Equifax has acknowledged that. Even though a patch for the exploited Apache Struts vulnerability had been for two months available when the breach occurred, it hadn’t been applied. Unfortunately, this is something we see time and again – a known, fixable open source vulnerability not being remediated.”

Shipley said that because Apache Struts is so widely used, including by Fortune 100 companies, to build corporate websites and web applications in sectors including education, government, financial services, retail and media, “we wanted to avoid any additional exploits that could be even more costly and damaging than the one at Equifax.”

Black Duck said it encourages companies to make use of Threat Check for Struts to address this current issue as quickly as possible.

Although open source software – such as Apache Struts – comprises 80 to 90 percent of the code in modern applications, Shipley said most organisations lack good visibility into the open source they are using. He said that even when patches/fixes for known open source vulnerabilities are available, because most companies lack automated processes for identifying and monitoring their open source, they are often unaware that they are using a vulnerable open source component, or that there is a fix available.

Global Banking & Finance Review

 

Why waste money on news and opinions when you can access them for free?

Take advantage of our newsletter subscription and stay informed on the go!


By submitting this form, you are consenting to receive marketing emails from: Global Banking & Finance Review │ Banking │ Finance │ Technology. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Recent Post