Open-source software forms the backbone of much of today's digital infrastructure, powering browsers, applications, and critical business systems. Security leaders are increasingly aware of the risks associated with integrating open-source components into their environments, as vulnerabilities can be present even in widely used and actively maintained projects. A recent study by James Cusick at Ritsumeikan University compared the security of open-source and proprietary software by scanning millions of lines of code. The analysis revealed that large open-source projects like Chromium, despite their robust contributor communities, still contained over 1,400 potential issues, though only a few were deemed critical or high severity. In contrast, smaller open-source projects such as Genann exhibited a much higher density of potential issues, with one problem for every 27 lines of code. Proprietary software, while not immune, generally fell between these extremes, with most issues rated as medium or low severity. These findings highlight the importance of static code scanning and rigorous review processes for all software, regardless of its origin. The integration of open-source components without thorough vetting can introduce significant supply chain risks, as vulnerabilities may remain undetected and exploitable. In response to these challenges, regulatory frameworks like the European Union's Cyber Resilience Act (CRA) have been developed to enhance software security and transparency. According to Greg Kroah-Hartman, a leading Linux kernel maintainer and member of the CRA working group, the Act has evolved to be more accommodating to open-source developers. The CRA now requires producers of products with digital elements to document, secure, and maintain their software supply chains, including the generation of Software Bills of Materials (SBOMs) and proactive vulnerability management. While initial drafts of the CRA raised concerns among open-source communities about potential legal liabilities, subsequent revisions have made the regulations more palatable and beneficial for open-source contributors. Organizations like the Linux Foundation and Mozilla are required to comply with these rules, but individual contributors are generally exempt unless they are acting as commercial entities. The CRA aims to foster greater transparency and accountability in software development, ultimately benefiting both open-source and proprietary ecosystems. Security leaders are encouraged to adopt comprehensive code scanning and supply chain management practices to mitigate the risks associated with open-source software. The evolving regulatory landscape underscores the need for organizations to stay informed and proactive in addressing software security challenges. By combining technical diligence with compliance efforts, businesses can better protect themselves against the hidden risks inherent in modern software supply chains. The ongoing dialogue between regulators, open-source communities, and industry stakeholders is shaping a more resilient and secure digital environment for all.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
By late September 2025, foundations and large open source projects were reported to be working with EU authorities on checklists and templates to help clarify Cyber Resilience Act compliance. Further clarification on commercial versus non-commercial obligations was expected over the following year.
In a September 2025 discussion of the EU Cyber Resilience Act, Linux stable kernel maintainer Greg Kroah-Hartman said the revised law mainly targets commercial producers of products with digital elements rather than unpaid individual open source contributors. He said non-commercial developers generally face minimal obligations, while manufacturers and funded legal entities bear the main compliance burden.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetheregister.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.