Launch of Software Security Score (3S) Research Program
Article Content
- •The Cyberagentur launched the Software Security Score (3S) program on April 28, 2026.
- •3S aims to create a measurable and comparable framework for software security evaluation.
- •Applications for participation in the program are open until June 11, 2026.
On April 28, 2026, the Cyberagentur announced the call for proposals for the Software Security Score (3S) research program. This initiative aims to enhance the transparency, measurability, and comparability of software security for end users. The program seeks to develop a novel metric that consolidates security-relevant properties of software into a comprehensible score, moving beyond abstract quality seals. The initiative addresses the growing complexity of software security in everyday applications, such as banking and connected devices, where users often lack clarity on security levels. Interested parties from academia, industry, and startups can apply to participate until June 11, 2026. The program emphasizes a dynamic understanding of security, factoring in usage context and lifecycle. It aims to provide a more nuanced evaluation of software security, overcoming binary classifications. The goal is to empower users with better information for decision-making regarding software security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…