Risky Bulletin Newsletter
August 19, 2022
Risky Biz News: Clarifying the "DOD can't use software with vulnerabilities" misunderstanding
Presented by
![Catalin Cimpanu](/static/img/catalin-cimpanu.jpg)
News Editor
But one thing that came out of yesterday's misunderstanding is that the Twitter thread also helped surface another section in next year's NDAA, namely that the DOD can now issue funding for open-source projects and help them improve their security posture.
According to section 323 (k), the DOD will soon be able to issue grants to sponsor security audits in open-source projects, fund developers to patch certain vulnerabilities in their projects, and even fund FOSS infrastructure and code overhauls, such as "rewrites of open source software components in memory-safe programming languages." 😎
WestJet app leak: Canadian airline WestJet suffered a glitch in its mobile app that logged in users into its mobile app into different profiles, allowing them to view other people's personal details.