Tag: open-source
-
Deloitte joins IBM and Red Hat’s initiative to secure open-source software
First seen on scworld.com Jump to article: www.scworld.com/brief/deloitte-joins-ibm-and-red-hats-initiative-to-secure-open-source-software
-
New coalition aims to streamline open source bug fixes
Tags: open-sourceFirst seen on scworld.com Jump to article: www.scworld.com/brief/new-coalition-aims-to-streamline-open-source-bug-fixes
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades.New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use…
-
OpenAI oder Anthropic: Sind Open-Source-Modelle eine gute Alternative?
First seen on t3n.de Jump to article: t3n.de/news/openai-oder-anthropic-sind-open-source-modelle-eine-gute-alternative-1749657/
-
OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad
OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/openclaw-ios-app-iphone-ipad/
-
Vulnerability reports are arriving faster than GitHub can review them
Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/github-advisory-database-review/
-
Hottest cybersecurity open-source tools of the month: June 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/hottest-cybersecurity-open-source-tools-of-the-month-june-2026/
-
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App.The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation First seen on thehackernews.com Jump to article: thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
-
DarkMoon: Open-source AI pentesting platform
Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/29/darkmoon-open-source-ai-pentesting-platform/
-
New Initiative Tackles Security for EndLife Open Source Software
The Open Source Sustainability Initiative’s goal is to help enterprises manage and secure aging open source projects while maintaining regulatory compliance. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/initiative-tackles-security-end-of-life-open-source
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
Software, AI companies form alliance to tackle open-source security flaws
The emergence of frontier AI models has increased the speed and capabilities of malicious hackers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/software-ai-alliance-open-source-security-flaws/823889/
-
23 Top Open Source Penetration Testing Tools in 2026
Review and compare 23 of the best open-source pen testing tools in 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/applications/open-source-penetration-testing-tools/
-
Critical open-source projects get a new security framework
Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/akrites-open-source-security-framework/
-
Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure
A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infrastructure across Southeast Asia during 2025. The recent campaign combines common open-source tooling with bespoke malware. Operators consistently leverage publicly available utilities SoftEther VPN for tunneling, VNT and yuze for covert command-and-control,…
-
Modelplane: Open-source control plane for AI inference
Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/modelplane-open-source-control-plane-ai-inference/
-
Open-Source Coalition Pushes California to Rework AI Act
Developers Warn Clause in AI Transparency Act Collides With Open-Source Licensing. A coalition of open-source artificial intelligence players are pressing California to rewrite a license-revocation provision in the state’s AI Transparency Act, warning that the language as drafted clashes with how open-source licensing works and could seed uncertainty across the software supply chain. First seen…
-
Nvidia adopts OpenBao, open source fork of HashiCorp’s Vault
Nvidia’s adoption is among the signs of growing interest in the OpenSSF-governed Vault alternative, amid mounting digital sovereignty worries globally. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366644831/Nvidia-adopts-OpenBao-open-source-fork-of-HashiCorps-Vault
-
Best practices for AI in open-source work
Free and open source software developers us AI coding assistants such as Claude Code, Copilot CLI, Antigravity, and OpenCode in their daily work. The Software Freedom … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/25/foss-ai-in-open-source/
-
Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication
Tags: ai, authentication, cve, cyber, data-breach, exploit, flaw, framework, open-source, rce, remote-code-execution, vulnerabilityA critical unauthenticated remote code execution (RCE) vulnerability in Langflow, tracked as CVE-2026-33017, is being actively exploited in the wild within hours of its disclosure. This vulnerability allows attackers to execute arbitrary Python code on exposed instances without any authentication. It affects the widely used open-source AI workflow framework designed for building large language model…
-
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Tags: apache, attack, control, cybersecurity, flaw, github, google, microsoft, open-source, supply-chainCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and First seen…
-
Open-source security is posing challenges governments can’t easily solve
A diffuse landscape, fruitful targets, companies not stepping up, AI’s influence and flagging U.S. government efforts all figure into a shifting threat. First seen on cyberscoop.com Jump to article: cyberscoop.com/open-source-software-security-crisis/
-
Praxen: Open-source AI agent behavior verification
Praxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/praxen-open-source-ai-agent-behavior-verification/
-
Open Source und moderne Authentifizierung: TeleTrusT-Podcast zur IT-Sicherheit und Digitalen Souveränität
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/open-source-authentifizierung-teletrust-podcast-it-sicherheit
-
DifyTap: Four Bugs Put over 1 million AI Apps at Risk
Four flaws in Dify exposed cross-tenant data, documents and AI conversations. Two critical bugs enabled unauthenticated access and data theft. Zafran Labs researchers disclosed four vulnerabilities in Dify, the open-source AI platform used by major companies like Volvo and Maersk to run over a million applications across over 60 industries. Two vulnerabilities are of critical…
-
DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
A series of critical vulnerabilities in the widely used open-source LLMOps platform Dify, which powers over one million AI applications. These vulnerabilities, collectively referred to as “DifyTap,” include four flaws, two rated as critical and two that require no authentication. They expose cross-tenant data leakage risks, allowing attackers to access private AI conversations, preview sensitive…
-
Neue Initiative von OpenAI – ‘Patch the Planet” soll kritische Open-Source-Software stärken
Bei ‘Patch the planet” sollen KI-Sicherheitsanalysen mit menschlicher Expertise kombiniert werden, um Schwachstellen schneller zu erkennen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/neue-initiative-von-openai-patch-the-planet-soll-kritische-open-source-software-staerken.98050
-
Neue Initiative von OpenAI – ‘Patch the Planet” soll kritische Open-Source-Software stärken
Bei ‘Patch the planet” sollen KI-Sicherheitsanalysen mit menschlicher Expertise kombiniert werden, um Schwachstellen schneller zu erkennen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/neue-initiative-von-openai-patch-the-planet-soll-kritische-open-source-software-staerken.98050
-
Neue Open-Source-Plattform legt Cybercrime-Netzwerke offen
Die neue Plattform Cybercrime Atlas Cosmos kartiert kriminelle Netzwerke, Werkzeuge und Geldflüsse der organisierten Cyberkriminalität. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/open-source-cybercrime-netzwerke

