Tag: open-source
-
Nvidia Launches Open-Source AI Security Alliance
Anthropic, OpenAI and Google Absent as 37 Firms Back Open AI Security Tools. Nvidia and 36 other technology giants launched the Open Secure AI Alliance to build and share open-source AI security tools, arguing open models are critical defensive assets – while Anthropic, OpenAI and Google, makers of the most capable closed models, are absent…
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
Tech industry giants say US must embrace openness, transparency in AI
Open-source and open-weight AI models are essential cybersecurity tools, two groups of major AI and security firms said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-open-source-weights-tech-industry-promote/826240/
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
-
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
-
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. First seen on cyberscoop.com Jump to article: cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/
-
IBM Bets on Multi-Billion-Dollar Open-Source Patch Business
IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches. IBM is betting that AI can transform legacy open-source vulnerability remediation into a multibillion-dollar business by delivering validated, backported security patches for software versions enterprises continue to run years after upstream support ends. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ibm-bets-on-multi-billion-dollar-open-source-patch-business-a-32317
-
Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/
-
ChatGPT und Fable vs. Kimi K3: Wie mächtig sind chinesische Open-Source-Modelle?
First seen on t3n.de Jump to article: t3n.de/news/openai-anthropic-kimi-k3-open-source-modelle-alternative-1749657/
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).”The filename parameter is concatenated into First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
-
Snowpick: Open-source ServiceNow exposure scanner
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner/
-
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.Researchers demonstrated that chain, plus six other attacks,…
-
Open-source maintainers still work underfunded as sponsorship crosses $100 million
Tags: open-sourceA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián RamÃrez and Caleb Porzio spent years in that position. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/open-source-github-sponsors-100-million/
-
Autonomer KI-Agent hackt Hugging Face
Die Open-Source-Plattform Hugging Face wurde Opfer eines Angriffs durch einen autonomen KI-Agenten. Interne Datensätze und Zugangsdaten waren betroffen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hugging-face-von-ki-agent-gehackt
-
AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/gnome-security-disclosure-update/
-
Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things,…
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…
-
Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/microsoft-dusseldorf-out-of-band-application-security-testing-oast-platform/
-
Containerd – Kritische Schwachstelle in Open-Source-Software für Container-Runtime
First seen on security-insider.de Jump to article: www.security-insider.de/containerd-schwachstellen-kubernetes-cri-plugin-a-ff000657e310717ca6ed5b9de656deab/
-
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/mozilla-open-source-ai-adoption-report/
-
Kimi K3 Highlights Limits of AI Benchmark Leaderboards
Open-source model impresses on tests but enterprise performance remains unproven. Moonshot AI’s Kimi K3 has climbed AI benchmark leaderboards and challenged leading U.S. models on coding tasks. But benchmark scores offer only a narrow view of model performance, fueling calls for independent testing and enterprise evaluations before organizations make deployment decisions. First seen on govinfosecurity.com…
-
SpaceXAI Open-Sources Grok Build After Privacy Backlash
SpaceXAI open-sourced Grok Build under Apache 2.0 after privacy backlash over broad directory uploads from its terminal AI coding agent. The post SpaceXAI Open-Sources Grok Build After Privacy Backlash appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-spacexai-grok-build-open-source-privacy/
-
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as >>bandcampro<< used a jailbroken Gemini CLI, Google's open-source terminal-based AI agent, to deploy and operate a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/
-
Chatto: Open-source team messenger with privacy at its core
Teams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/chatto-self-hosted-chat-app-privacy/
-
The AI Supply Chain Is Your Latest Unguarded Attack Surface
When You Consume AI, You Inherit Every Upstream Risk You Can’t See Most enterprises don’t build AI, they consume it through APIs, open-source models and orchestration frameworks. Each layer inherits upstream risk with little visibility. This piece maps the four-layer AI supply chain and the existing security disciplines that bring it under control. First seen…

