Tag: open-source
-
Anthropic’s AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic’s Mythos findings ignite debate over how to secure the open-source software supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/anthropic-s-ai-finds-bugs-ibm-bets-5b-it-can-fix-them-
-
What the AI patch gap means for enterprise security
Open-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/open-source-ai-patch-gap/
-
GitHub’s new tool helps prevent costly open-source license violations
GitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/github-license-compliance-feature/
-
Langflow Flaws Exposed AI Servers to Takeover
Rubrik Decries Lack of Fundamental Cybersecurity in AI Platforms. Rubrik Zero Labs found four vulnerabilities in Langflow, including flaws that allowed unauthenticated attackers to execute code, read sensitive files and steal credentials under specific conditions. The open-source AI orchestration platform patched the vulnerabilities between February and May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/langflow-flaws-exposed-ai-servers-to-takeover-a-32125
-
84 Prozent der Angriffe treffen vermeidbare Schwachstellen
Filigran, das europäische Open-Source-Unternehmen für Bedrohungsmanagement, hat den Bericht ‘The State of Threat Management Report” veröffentlicht. Die weltweite Studie wurde unter 550 Entscheidungsträgern und Fachleuten im IT-Sicherheitsbereich und vom unabhängigen Marktforschungsunternehmen Vanson Bourne durchgeführt. Dabei deckt die Untersuchung eine auffällige Diskrepanz auf: Während sich das Continuous-Threat-Exposure-Management (CTEM) als Branchenstandard zunehmend durchsetzt, lässt die operative Reife…
-
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents
Researchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled >>GuardFall: a universal shell injection vulnerability in open-source AI agents,<< of eleven open-source AI coding and computer-use agents, and the headline finding is uncomfortable: ten of them leave…
-
Fluentd Security Flaws Enable Remote Code Execution, SSRF, DoS, and Credential Exposure
Tags: credentials, cyber, data, dos, flaw, github, open-source, remote-code-execution, service, vulnerabilityFluentd, a widely used open-source data collector for unified logging, has reported several high-impact vulnerabilities that could enable attackers to achieve remote code execution (RCE), server-side request forgery (SSRF), denial-of-service (DoS), and the exposure of sensitive credentials. These issues, documented in multiple GitHub Security Advisories, affect Fluentd versions up to 1.19.2 and have been resolved…
-
Nika: Open-source code analysis tool
Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/01/nika-open-source-code-analysis-tool/
-
Deloitte joins IBM and Red Hat’s initiative to secure open-source software
First seen on scworld.com Jump to article: www.scworld.com/brief/deloitte-joins-ibm-and-red-hats-initiative-to-secure-open-source-software
-
New coalition aims to streamline open source bug fixes
Tags: open-sourceFirst seen on scworld.com Jump to article: www.scworld.com/brief/new-coalition-aims-to-streamline-open-source-bug-fixes
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades.New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use…
-
OpenAI oder Anthropic: Sind Open-Source-Modelle eine gute Alternative?
First seen on t3n.de Jump to article: t3n.de/news/openai-oder-anthropic-sind-open-source-modelle-eine-gute-alternative-1749657/
-
OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad
OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/openclaw-ios-app-iphone-ipad/
-
Hottest cybersecurity open-source tools of the month: June 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/hottest-cybersecurity-open-source-tools-of-the-month-june-2026/
-
Vulnerability reports are arriving faster than GitHub can review them
Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/github-advisory-database-review/
-
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App.The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation First seen on thehackernews.com Jump to article: thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
-
DarkMoon: Open-source AI pentesting platform
Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/29/darkmoon-open-source-ai-pentesting-platform/
-
New Initiative Tackles Security for EndLife Open Source Software
The Open Source Sustainability Initiative’s goal is to help enterprises manage and secure aging open source projects while maintaining regulatory compliance. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/initiative-tackles-security-end-of-life-open-source
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
Software, AI companies form alliance to tackle open-source security flaws
The emergence of frontier AI models has increased the speed and capabilities of malicious hackers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/software-ai-alliance-open-source-security-flaws/823889/
-
23 Top Open Source Penetration Testing Tools in 2026
Review and compare 23 of the best open-source pen testing tools in 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/applications/open-source-penetration-testing-tools/
-
Critical open-source projects get a new security framework
Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/akrites-open-source-security-framework/
-
Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure
A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infrastructure across Southeast Asia during 2025. The recent campaign combines common open-source tooling with bespoke malware. Operators consistently leverage publicly available utilities SoftEther VPN for tunneling, VNT and yuze for covert command-and-control,…
-
Modelplane: Open-source control plane for AI inference
Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/modelplane-open-source-control-plane-ai-inference/
-
Open-Source Coalition Pushes California to Rework AI Act
Developers Warn Clause in AI Transparency Act Collides With Open-Source Licensing. A coalition of open-source artificial intelligence players are pressing California to rewrite a license-revocation provision in the state’s AI Transparency Act, warning that the language as drafted clashes with how open-source licensing works and could seed uncertainty across the software supply chain. First seen…
-
Nvidia adopts OpenBao, open source fork of HashiCorp’s Vault
Nvidia’s adoption is among the signs of growing interest in the OpenSSF-governed Vault alternative, amid mounting digital sovereignty worries globally. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366644831/Nvidia-adopts-OpenBao-open-source-fork-of-HashiCorps-Vault
-
Best practices for AI in open-source work
Free and open source software developers us AI coding assistants such as Claude Code, Copilot CLI, Antigravity, and OpenCode in their daily work. The Software Freedom … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/25/foss-ai-in-open-source/
-
Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication
Tags: ai, authentication, cve, cyber, data-breach, exploit, flaw, framework, open-source, rce, remote-code-execution, vulnerabilityA critical unauthenticated remote code execution (RCE) vulnerability in Langflow, tracked as CVE-2026-33017, is being actively exploited in the wild within hours of its disclosure. This vulnerability allows attackers to execute arbitrary Python code on exposed instances without any authentication. It affects the widely used open-source AI workflow framework designed for building large language model…
-
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Tags: apache, attack, control, cybersecurity, flaw, github, google, microsoft, open-source, supply-chainCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and First seen…

