Tony Baer reports that Fortify has identified a new class of bug (via Matt Assay) in open source projects. The miscreants now attack at a point when the development is done and the software is prepared using a build. A build consists of constructing a software program out of its source code files. [Continue]

