{"id":76200,"date":"2022-09-22T11:01:43","date_gmt":"2022-09-22T10:01:43","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2022\/09\/22\/trellix-launches-trellix-advanced-research-center-finds-estimated-350000-open-source-projects-at-risk\/"},"modified":"2023-05-25T10:25:26","modified_gmt":"2023-05-25T09:25:26","slug":"trellix-launches-trellix-advanced-research-center-finds-estimated-350000-open-source-projects-at-risk","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2022\/09\/22\/trellix-launches-trellix-advanced-research-center-finds-estimated-350000-open-source-projects-at-risk\/","title":{"rendered":"Trellix launches Trellix Advanced Research Center, finds estimated 350,000 open-source projects at risk"},"content":{"rendered":"\n<p>Trellix, the cybersecurity company delivering the future of extended detection and response (XDR), has announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.<\/p>\n\n\n\n<p>Comprised of hundreds of the world\u2019s most elite security analysts and researchers, the Advanced Research Centre produces actionable real-time intelligence and threat indicators to help customers detect, respond and remediate the latest cybersecurity threats. &nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Aparna-Rayasam-CPO-Trellix-Web.jpg\" alt=\"\" class=\"wp-image-76233\" width=\"-153\" height=\"-153\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Aparna-Rayasam-CPO-Trellix-Web.jpg 450w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Aparna-Rayasam-CPO-Trellix-Web-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Aparna-Rayasam-CPO-Trellix-Web-150x150.jpg 150w\" sizes=\"(max-width: 450px) 100vw, 450px\" \/><figcaption>Aparna Rayasam, CPO, Trellix<\/figcaption><\/figure><\/div>\n\n\n<p>\u201cThe threat landscape is scaling in sophistication and potential for impact,\u201d said Aparna Rayasam, Chief Product Officer, Trellix. \u201cWe do this work to make our digital and physical worlds safer for everyone. With adversaries strategically investing in talent and technical know-how, the industry has a duty to study the most combative actors and their methods to innovate at a faster rate.\u201d<\/p>\n\n\n\n<p>Trellix Advanced Research Center has the cybersecurity industry\u2019s most comprehensive charter and is at the forefront of emerging methods, trends and actors across the threat landscape. The premier partner of security operations teams across the globe, Trellix Advanced Research Center provides intelligence and cutting-edge content to security analysts while powering our leading XDR platform.<\/p>\n\n\n\n<p><strong>Python tarfile vulnerability highlights software supply chain complexities<\/strong><\/p>\n\n\n\n<p>In coordination with today\u2019s launch, Trellix Advanced Research Center also published its research into CVE-2007-4559, a vulnerability estimated to be present in over 350,000 open-source projects and prevalent in closed-source projects.<\/p>\n\n\n\n<p>It exists in the Python tarfile module which is a default module in any project using Python and is found extensively in frameworks created by Netflix, AWS, Intel, Facebook, Google and applications used for Machine Learning, automation and docker containerisation.<\/p>\n\n\n\n<p>The vulnerability can be exploited by uploading a malicious file generated with two or three lines of simple code and allows attackers arbitrary code execution, or control of a target device. &nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Christiaan-Beek-Head-of-Adversarial-Vulnerability-Research-Trellix-Web.jpg\" alt=\"\" class=\"wp-image-76232\" width=\"-152\" height=\"-152\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Christiaan-Beek-Head-of-Adversarial-Vulnerability-Research-Trellix-Web.jpg 450w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Christiaan-Beek-Head-of-Adversarial-Vulnerability-Research-Trellix-Web-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/09\/Christiaan-Beek-Head-of-Adversarial-Vulnerability-Research-Trellix-Web-150x150.jpg 150w\" sizes=\"(max-width: 450px) 100vw, 450px\" \/><figcaption>Christiaan Beek, Head of Adversarial and Vulnerability Research, Trellix<\/figcaption><\/figure><\/div>\n\n\n<p>\u201cWhen we talk about supply chain threats, we typically refer to cyberattacks like the SolarWinds incident, however building on top of weak code foundations can have an equally severe impact,\u201d said Christiaan Beek, Head of Adversarial and Vulnerability Research, Trellix.<\/p>\n\n\n\n<p>\u201cThis vulnerability\u2019s pervasiveness is furthered by industry tutorials and online materials propagating its incorrect usage. It\u2019s critical for developers to be educated on all layers of the technology stack to properly prevent the reintroduction of past attack surfaces.\u201d<\/p>\n\n\n\n<p>Open-source developer tools, like Python, are necessary to advance computing and innovation and protection from known vulnerabilities requires industry collaboration. Trellix is working to push code via GitHub pull request to protect open-source projects from the vulnerability. A free tool for developers to check if their applications are vulnerable is available on Trellix Advanced Research Center\u2019s GitHub.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trellix, the cybersecurity company delivering the future of extended detection and response (XDR), has announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence. Comprised of hundreds of the world\u2019s most elite security analysts and researchers, the Advanced Research Centre produces actionable real-time intelligence and threat indicators to help customers detect, [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":76192,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14804,6,13],"tags":[15029,3279,20,15030,14445],"class_list":["post-76200","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-insights","category-top-stories","tag-aparna-rayasam","tag-christiaan-beek","tag-gitex","tag-python-tarfile","tag-trellix"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/76200","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=76200"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/76200\/revisions"}],"predecessor-version":[{"id":76234,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/76200\/revisions\/76234"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/76192"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=76200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=76200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=76200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}