Tag: open-source
-
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency. First seen on wired.com Jump to article: www.wired.com/story/defcon-34-badge-baochip-andrew-bunnie-huang/
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
CISA issues recommendations to federal agencies on open-source software security
One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisa-open-source-software-security-guidance/
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/
-
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
-
Open Secure AI Alliance: Warum Microsoft, OpenAI und Nvidia plötzlich auf Open-Source-KI setzen
Trotz der durchaus sinnvollen Forderungen der Tech-Konzerne zur Abwehr von KI-Gefahren drängen sich auch andere Motive auf. First seen on golem.de Jump to article: www.golem.de/news/open-secure-ai-alliance-warum-microsoft-openai-und-nvidia-ploetzlich-auf-open-source-ki-setzen-2607-211359.html
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand’s Ministry of Finance. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance
-
Nvidia Launches Open-Source AI Security Alliance
Anthropic, OpenAI and Google Absent as 37 Firms Back Open AI Security Tools. Nvidia and 36 other technology giants launched the Open Secure AI Alliance to build and share open-source AI security tools, arguing open models are critical defensive assets – while Anthropic, OpenAI and Google, makers of the most capable closed models, are absent…
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
Tech industry giants say US must embrace openness, transparency in AI
Open-source and open-weight AI models are essential cybersecurity tools, two groups of major AI and security firms said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-open-source-weights-tech-industry-promote/826240/
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
-
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
-
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. First seen on cyberscoop.com Jump to article: cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/
-
IBM Bets on Multi-Billion-Dollar Open-Source Patch Business
IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches. IBM is betting that AI can transform legacy open-source vulnerability remediation into a multibillion-dollar business by delivering validated, backported security patches for software versions enterprises continue to run years after upstream support ends. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ibm-bets-on-multi-billion-dollar-open-source-patch-business-a-32317
-
Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/
-
ChatGPT und Fable vs. Kimi K3: Wie mächtig sind chinesische Open-Source-Modelle?
First seen on t3n.de Jump to article: t3n.de/news/openai-anthropic-kimi-k3-open-source-modelle-alternative-1749657/
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).”The filename parameter is concatenated into First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
-
Snowpick: Open-source ServiceNow exposure scanner
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner/
-
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.Researchers demonstrated that chain, plus six other attacks,…
-
Open-source maintainers still work underfunded as sponsorship crosses $100 million
Tags: open-sourceA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián RamÃrez and Caleb Porzio spent years in that position. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/open-source-github-sponsors-100-million/
-
Autonomer KI-Agent hackt Hugging Face
Die Open-Source-Plattform Hugging Face wurde Opfer eines Angriffs durch einen autonomen KI-Agenten. Interne Datensätze und Zugangsdaten waren betroffen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hugging-face-von-ki-agent-gehackt
-
AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/gnome-security-disclosure-update/
-
Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things,…
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/microsoft-dusseldorf-out-of-band-application-security-testing-oast-platform/
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…

