Tag: open-source
-
Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User
Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across shared tenants. Both flaws were discovered by Miggo Security’s autonomous research system,…
-
Turning the Tables on Email Scammers With ‘ScamBuster’
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/turning-tables-email-scammers-scambuster
-
Schutz von Open Source Software in KRITIS – Linux Foundation startet Brancheninitiative Akrites
First seen on security-insider.de Jump to article: www.security-insider.de/linux-foundation-startet-brancheninitiative-akrites-a-13bea32919c906bc6aa25fbc37695cab/
-
Cynative: Open-source deep research agent
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/cynative-open-source-deep-research-agent/
-
(g+) Open Source, Zero Knowledge: So gelingt Passwortmanagement mit Bitwarden
Bitwarden soll Kontrolle über Passwörter, Identitäten und Zugänge geben. Die wichtigste Entscheidung ist jedoch nicht, ob dieser Passworttresor läuft, sondern wo. First seen on golem.de Jump to article: www.golem.de/news/open-source-zero-knowledge-so-gelingt-passwortmanagement-mit-bitwarden-2607-210563.html
-
Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-plant-ai-agents/
-
Open-source collaboration is growing worldwide and putting pressure on maintainers
Developers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/github-open-source-collaboration/
-
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker’s code on your own machine instead.That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls “Friendly Fire.” It works against Anthropic’s Claude Code and OpenAI’s Codex when either is…
-
DuckDuckGo Browser Blocks YouTube Ads Using uBlock Origin Filter Lists
DuckDuckGo has quietly expanded its privacy-first browser capabilities by introducing a YouTube ad-blocking feature. This feature uses community-driven uBlock Origin filter lists to detect and remove video ads. From a security and privacy standpoint, this approach is significant because it relies on open-source filtering rules maintained by an active community, rather than proprietary, closed heuristics.…
-
20 open-source cybersecurity tools to keep your team ready for anything
AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/20-latest-open-source-cybersecurity-tools/
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, First seen…
-
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, First seen…
-
Apple Container: Open-source tool for Linux containers on the Mac
Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/
-
Sicherheitschip »Made in Germany« dient als Vertrauensanker für vernetzte Geräte
Management Summary Fraunhofer IIS, AISEC und EMFT stellen ein RISC-V Secure Element vor, das als vertrauenswürdiger Sicherheitsanker für vernetzte Geräte dient. Der Chip wurde vollständig in Deutschland designt und gefertigt und stärkt damit Transparenz, technologische Souveränität und Vertrauen entlang der Wertschöpfungskette. Die Open-Source-Hardware-Basis OpenTitan ermöglicht überprüfbare Sicherheit, langfristige Verfügbarkeit und flexible Anpassbarkeit an unterschiedliche Geräteklassen….…
-
Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk
Toronto, Canada, July 6th, 2026, CyberNewswire Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed, including the open-source components that never appear in any manifest. Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today […]…
-
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
runZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used…
-
Omnigent: Open-source AI agent framework and meta-harness
Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/omnigent-open-source-ai-agent-framework/
-
ModSecurity Security Flaws Enable WAF Rule Evasion With Crafted HTTP Requests
ModSecurity, a widely used open-source web application firewall (WAF), has multiple security vulnerabilities that allow attackers to bypass detection with specially crafted HTTP requests. These vulnerabilities, identified as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15. They have been addressed in version 3.0.16. These issues reveal significant inconsistencies in input transformation and request parsing,…
-
New ClamAV security patch closes seven scanner bugs dating back two decades
Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/clamav-security-patch-versions/
-
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data.The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file impersonating Maccy, a legitimate open-source clipboard manager. It has been codenamed PamStealer owing to its ability…
-
Anthropic’s AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic’s Mythos findings ignite debate over how to secure the open-source software supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/anthropic-s-ai-finds-bugs-ibm-bets-5b-it-can-fix-them-
-
What the AI patch gap means for enterprise security
Open-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/open-source-ai-patch-gap/
-
GitHub’s new tool helps prevent costly open-source license violations
GitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/github-license-compliance-feature/
-
Langflow Flaws Exposed AI Servers to Takeover
Rubrik Decries Lack of Fundamental Cybersecurity in AI Platforms. Rubrik Zero Labs found four vulnerabilities in Langflow, including flaws that allowed unauthenticated attackers to execute code, read sensitive files and steal credentials under specific conditions. The open-source AI orchestration platform patched the vulnerabilities between February and May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/langflow-flaws-exposed-ai-servers-to-takeover-a-32125
-
84 Prozent der Angriffe treffen vermeidbare Schwachstellen
Filigran, das europäische Open-Source-Unternehmen für Bedrohungsmanagement, hat den Bericht ‘The State of Threat Management Report” veröffentlicht. Die weltweite Studie wurde unter 550 Entscheidungsträgern und Fachleuten im IT-Sicherheitsbereich und vom unabhängigen Marktforschungsunternehmen Vanson Bourne durchgeführt. Dabei deckt die Untersuchung eine auffällige Diskrepanz auf: Während sich das Continuous-Threat-Exposure-Management (CTEM) als Branchenstandard zunehmend durchsetzt, lässt die operative Reife…
-
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents
Researchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled >>GuardFall: a universal shell injection vulnerability in open-source AI agents,<< of eleven open-source AI coding and computer-use agents, and the headline finding is uncomfortable: ten of them leave…
-
Fluentd Security Flaws Enable Remote Code Execution, SSRF, DoS, and Credential Exposure
Tags: credentials, cyber, data, dos, flaw, github, open-source, remote-code-execution, service, vulnerabilityFluentd, a widely used open-source data collector for unified logging, has reported several high-impact vulnerabilities that could enable attackers to achieve remote code execution (RCE), server-side request forgery (SSRF), denial-of-service (DoS), and the exposure of sensitive credentials. These issues, documented in multiple GitHub Security Advisories, affect Fluentd versions up to 1.19.2 and have been resolved…
-
Nika: Open-source code analysis tool
Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/01/nika-open-source-code-analysis-tool/

