Tag: open-source
-
Der Aufstieg von Open Source – 35 Jahre Linux: Vom Garagenprojekt zum Milliardengeschäft
First seen on security-insider.de Jump to article: www.security-insider.de/35-jahre-linux-vom-garagenprojekt-zum-milliardengeschaeft-a-566fb3b1cc3b99bd3aa13e47c1e18233/
-
Der Aufstieg von Open Source – 35 Jahre Linux: Vom Garagenprojekt zum Milliardengeschäft
First seen on security-insider.de Jump to article: www.security-insider.de/35-jahre-linux-vom-garagenprojekt-zum-milliardengeschaeft-a-566fb3b1cc3b99bd3aa13e47c1e18233/
-
Dubai Unveils Open-Source Deepfake Detection AI
Cybersecurity Regulator Says Saraab AI Model Can Spot Deepfakes With 91% Accuracy. The Dubai Electronic Security Center, the Middle Eastern emirate’s cybersecurity regulator, has built an AI model called Saraab that detects deepfake videos, and plans to open source it by the end of the year so it can be improved by researchers, AI companies…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…
-
Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Software Supply Chain Security – Wenn Open-Source-Pakete zur Hintertür werden
First seen on security-insider.de Jump to article: www.security-insider.de/operation-navy-ghost-backdoor-supply-chain-a-a7aef14bca7ea71dbb268aaf312f2b5f/
-
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).A sender with no credentials can crash the server process, named, with a single request that…
-
AI is adding to the review load on open-source projects, many of them thinly funded
AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery’s Technology … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/ai-and-open-source-projects/
-
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded First…
-
DeepZero: Open-source hunting for vulnerable Windows drivers
DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
-
Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
Tags: attack, cyber, email, infrastructure, mail, malicious, malware, open-source, phishing, servicePhishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the…
-
12 Best CWPP Solutions Compared (2026): Features Pricing
Quick Answer: Sysdig (built on open-source Falco) leads container/K8s runtime depth; Prisma Cloud leads workload breadth including serverless; Aqua leads cloud-native lifecycle security; Wiz and CrowdStrike lead platform correlation. Category notes: Illumio is microsegmentation and Fidelis is NDR/XDR containment and detection layers rather than classic CWPP. CSPM tells you how the cloud is configured; CWPP…
-
Permify: Open-source authorization as a service
Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/permify-open-source-authorization-as-a-service/
-
Permify: Open-source authorization as a service
Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/permify-open-source-authorization-as-a-service/
-
AWS AI Symposium: Public sector must shape AI, use open source
As frontier models outpace cyber defences, two public sector voices set out different answers to the same security question transparency and procurement leverage First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650031/AWS-AI-symposium-Public-sector-must-shape-AI-use-open-source
-
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. Adobe assigned the vulnerability a CVSS score of 10.0 and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/imperva-customers-protected-against-stylesmuggler-cve-2026-75650-in-adobe-commerce-and-magento-open-source/
-
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide.LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential.Anyone who holds…
-
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe”¯Commerce and”¯Magento Open Source that has come under active exploitation in the wild.The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.”This update resolves a critical First seen on thehackernews.com…
-
Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal administration. This initiative, announced to the Federal Council on September 2, aims to establish an open-source workplace platform that will operate alongside Microsoft 365 without…
-
Sicherheits-Tools für Server: Clawforge hilft, wenn Fail2ban und CrowdSec an ihre Grenzen kommen
Das Open-Source-Projekt Clawforge verbindet Sicherheitsereignisse aus mehreren Diensten und bewertet sie anhand eigener Regeln. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/softwareentwicklung/sicherheits-tools-fuer-server-clawforge-hilft-wenn-fail2ban-und-crowdsec-an-ihre-grenzen-kommen-333316.html
-
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Tags: adobe, attack, cyber, exploit, Internet, open-source, rce, remote-code-execution, vulnerability, zero-daySecurity researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers to inject PHP payloads into Magento’s template system and execute them via standard application workflows. Sansec’s Forensics Team reported that attacks began on September 4, targeting internet-facing…
-
ToolHive: The open-source way to run any MCP server securely
ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/toolhive-open-source-mcp-server-security/
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Tags: adobe, advisory, attack, backdoor, exploit, flaw, malicious, open-source, vulnerability, zero-dayAttackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4.…
-
Most of the bugs Claude Mythos found have never been checked by a human
Tags: open-sourceAnthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/echo-claude-mythos-vulnerability-findings/
-
Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/
-
JFrog bringt SoftwareChain-Kontrolle bis an den Netzwerkrand
JFrog bringt Software-Supply-Chain-Security an den Netzwerkrand und kontrolliert Open-Source-Pakete von Entwicklern und KI-Agenten über SASE-Plattformen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/jfrog-bringt-software-supply-chain-kontrolle-bis-an-den-netzwerkrand/a46307/

