Tag: open-source
-
Angriffspfade mit ‘Attack Chaining” gezielt analysieren und absichern
Filigran, das europäische Open-Source-Unternehmen für Bedrohungsmanagement, hat ‘Attack Chaining” vorgestellt. Dabei handelt es sich um eine Funktion zur Validierung von Angriffspfaden, die Penetrationstests und Red-Teaming-Aktivitäten mit OpenAEV automatisiert. OpenAEV ist ein Produkt zur Validierung von Sicherheitslücken durch simulierte Angreifer. Die neue Funktionalität ist ab sofort in OpenAEV v3 verfügbar. Angreifer wenden Techniken nicht isoliert an, sondern…
-
Flamingo Looks To Build Autonomous MSPs With Open Source, AI And $4.5M In New Funding
Flamingo expects its new $4.5 million seed round will help advance an AI-native, open-source IT security platform to help MSPs automate service delivery and support. First seen on crn.com Jump to article: www.crn.com/news/security/2026/flamingo-looks-to-build-autonomous-msps-with-open-source-ai-and-4-5m-in-new-funding
-
FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs
FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a “huge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature…
-
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.GeoNetwork originated at the United Nations Food and…
-
DuckDB stays open source while the team behind it goes to work for Amazon
Tags: open-sourceHannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/duckdb-aws-acquisition-open-source/
-
OWASP Launches OASIS to Use AI and AppSec Experts to Fix Open-Source Vulnerabilities
OWASP has launched the Open Automated Security Initiative for Software (OASIS), a new community project aimed at accelerating the remediation of vulnerabilities in open-source software through AI-generated patches and human application-security validation. Announced on August 26, 2026, OWASP OASIS seeks to address a longstanding security gap: organizations and researchers can identify vulnerabilities faster than maintainers…
-
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/
-
Attacks Targeting Langflow AI Agent-Building Tool Surge
Tags: access, ai, attack, credentials, exploit, framework, ibm, intelligence, open-source, software, tool, vulnerabilityTool’s Access to Compute Resources, Keys and Credentials Make It a Repeat Target. Open-source framework Langflow, designed to build artificial intelligence agents and workflows, is under fire again, with attackers now wielding exploit code for a vulnerability first detailed in January. Outdated versions of the IBM-maintained software with known vulnerabilities appear to abound. First seen…
-
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Tags: ai, credentials, exploit, flaw, framework, open-source, openai, remote-code-execution, threat, vulnerabilityThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
-
The Security Interviews: Abby Kearns, ActiveState
ActiveState CEO Abby Kearns discusses open source’s ‘existential crisis’, how AI is changing the secure software playbook, and why it’s time to have a different conversation about open source security First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649338/The-Security-Interviews-Abby-Kearns-ActiveState
-
The OpenClaw 2.0 release moves your sessions into SQLite
OpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/openclaw-2-0-released/
-
Halo-record: Open-source audit trails for AI agents
Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/halo-record-open-source-ai-agent-audit-trail/
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
Escaping the SIEM Cost Trap: A Data-First Architecture for Security Analytics
SOFTSWISS rebuilt security analytics around ClickHouse, open-source collection and tiered storage to improve query speed, extend retention and cut SIEM costs in a high-volume environment. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/escaping-the-siem-cost-trap-a-data-first-architecture-for-security-analytics-2/
-
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/27/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor-openai-and-others/
-
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. >>Two West…
-
Two alleged TeamPCP hackers arrested over global supply chain attacks
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia/
-
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Tags: attack, cybercrime, data, extortion, group, hacker, identity, malicious, open-source, software, supply-chainAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were…
-
‘HTTP Terminator’ Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/http-terminator-hunts-novel-desync-attacks
-
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared…
-
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.”The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics,”…
-
Cyber Novice Takes Top Prize in SANS AI Forensics Contest
Find Evil! Contest Winners Show That Evidence Controls Matter More Than AI Speed. SANS challenged participants to turn an experimental AI forensic agent into a trustworthy open-source tool. Entries had to investigate digital evidence autonomously while restricting system access, documenting their actions and correcting unsupported conclusions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-novice-takes-top-prize-in-sans-ai-forensics-contest-a-32662
-
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, open-source, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/hottest-cybersecurity-open-source-tools-august-2026/
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
Why Financial Services Is the Canary in the Code Mine
<div cla Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-financial-services-is-the-canary-in-the-code-mine/
-
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/hol-guard-open-source-antivirus-ai-agents/
-
BSidesCharm 2026 BSidesCharm 2026 Illuminating Shadow Al: An Open-Source Tool For CustomGPT Risk Assessment
Presenter: Sharon Shama Our thanks to BSidesCharm for publishing their Creators, Authors and Presenter’s outstanding BSidesCharm 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidescharm-2026-bsidescharm-2026-illuminating-shadow-al-an-open-source-tool-for-customgpt-risk-assessment/

