
Security Researchers Warn a Widely Used Open Source Tool Poses a 'Persistent' Risk to the US
Matt Burgess
created: May 5, 2025, 10 a.m. | updated: May 8, 2025, 11:21 a.m.
Now cybersecurity researchers are warning that a widely used piece of open source code—which is linked to Kiriyenko’s company and managed by Russian developers—may pose a “persistent” national security risk to the United States.
The open source software (OSS), called easyjson, has been widely used by the US Department of Defense and “extensively” across software used in the finance, technology, and healthcare sectors, say researchers at security company Hunted Labs, which is behind the claims.
For decades, open source software has underpinned large swathes of the technology industry and the systems people rely on day to day.
Open source technology allows anyone to see and modify code, helping to make improvements, detect security vulnerabilities, and apply independent scrutiny that’s absent from the closed tech of corporate giants.
Research from Hunted Labs details how code serialization tools could be abused by malicious hackers.
1 month ago: WIRED