Kawaiicon 2025

Join the next Kawaiicon, New Zealand’s premier hacker conference, happening November 6–8, 2025 in Wellington. This year’s edition dives deep into modern exploit techniques, particularly automated memory corruption attacks and emerging mitigation strategies in native languages and runtimes.

Why it matters for SoS‑VO:

OpenSSF Launches “Memory Safety Continuum” to Guide Incremental Security Improvements

OpenSSF Launches “Memory Safety Continuum” to Guide Incremental Security Improvements

The Open Source Security Foundation (OpenSSF) has released The Memory Safety Continuum, a practical framework that helps developers, organizations, and security teams assess and improve their memory safety posture. Unveiled on April 28, 2025, the document positions memory safety not as a binary goal but as an evolving journey—enabling teams to advance their practices in phases through language adoption, mitigation, and testing.

The Continuum guides readers through four core states:

Submitted by Regan Williams on

NSA & CISA Urge Adoption of Memory‑Safe Languages to Prevent Critical Vulnerabilities

NSA & CISA Urge Adoption of Memory‑Safe Languages to Prevent Critical Vulnerabilities

The NSA and CISA have jointly issued a Cybersecurity Information Sheet (CSI), titled Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development, published on June 24, 2025. The guidance emphasizes that memory safety is "critical to a holistic approach to software security", and that using memory-safe languages (MSLs) can significantly lower the risk of memory-based exploits such as buffer overflows, use-after-free, and data races.

Submitted by Regan Williams on

WSU Tri-Cities Integrates AI into Cybersecurity Education and Research

WSU Tri-Cities Integrates AI into Cybersecurity Education and Research

Since 2022, the university has offered classes centered around machine learning and artificial intelligence, reflecting the growing importance of these technologies across multiple industries. The program represents WSU Tri-Cities' commitment to providing cutting-edge education that matches current market demands and technological trends.

Submitted by Regan Williams on

TSA Issues Warning About Cybersecurity Risks At The Airport

TSA Issues Warning About Cybersecurity Risks At The Airport

As Bostonians prepare to travel during the summer, the Transportation Security Administration is issuing warnings about cybersecurity threats to consider. In a social media post, TSA cautioned travelers about charging their devices using the USB ports found throughout airports. Hackers can install malware on the ports, infecting your devices once connected, also known as juice/port jacking.

"I always thought it was safe, to be able to use that in the airport," said one traveler at Logan airport.

Submitted by Regan Williams on

New Tool Portal: Automated Rapid Certification Of Software (ARCOS)

New Tool Portal: Automated Rapid Certification Of Software (ARCOS)

We're excited to announce the launch of the Automated Rapid Certification Of Software (ARCOS) Tool Portal — a new DARPA-supported virtual resource for the research and development and certification communities.

The ARCOS Tool Portal provides open access to simulators, verification tools, and tool suites that enable high-quality software assurance evidence generation and evaluation.

🔗 https://arcos-tools.org/

 

Submitted by Katie Dey on
Subscribe to