open-source
391 articles with this tag
INFO
INFO
HIGH
LOW
LOW
INFO
INFO
LOW
INFO
INFO
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
INFO
INFO
HIGH
MEDIUM
HIGH
INFO
INFO
HIGH
HIGH
INFO
INFO
INFO
INFO
INFO
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
INFO
MEDIUM
MEDIUM
INFO
HIGH
INFO
HIGH
HIGH
CRITICAL
MEDIUM
INFO
CRITICAL
INFO
LOW
INFO
INFO
HIGH
HIGH
INFO
INFO
INFO
HIGH
INFO
INFO
HIGH
INFO
MEDIUM
INFO
INFO
INFO
CRITICAL
HIGH
INFO
INFO
MEDIUM
INFO
INFO
INFO
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
MEDIUM
LOW
INFO
INFO
INFO
INFO
INFO
INFO
CRITICAL
INFO
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
MEDIUM
INFO
MEDIUM
HIGH
INFO
AIs Compress Exploit Timeline
OpenSSL’s new alpha build speeds up post-quantum crypto
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
ReactOS 0.4.16 released
Haiku R1/beta6 released
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
AI-Infra-Guard: Open-source security scanner for AI systems
BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows
ToolHive: The open-source way to run any MCP server securely
Nvidia Is Buying AI Platform Hugging Face for $13 Billion
Most of the bugs Claude Mythos found have never been checked by a human
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen
[NEU] [mittel] MailPit: Schwachstelle ermöglicht Offenlegung von Informationen
[NEU] [mittel] ffmpeg: Schwachstelle ermöglicht Denial of Service
[NEU] [mittel] Filebeat: Schwachstelle ermöglicht Denial of Service
[NEU] [hoch] Elasticsearch: Mehrere Schwachstellen
DuckDB stays open source while the team behind it goes to work for Amazon
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
[NEU] [mittel] Flowise: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen und DoS
[NEU] [mittel] vllm: Mehrere Schwachstellen ermöglichen Denial of Service
[NEU] [hoch] Gitea: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode
Debian developers rejected an LLM ban and left disclosure voluntary
Halo-record: Open-source audit trails for AI agents
[NEU] [hoch] Composer: Mehrere Schwachstellen
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Kubernetes v1.37: Garhwal
Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
AROS gets official Raspberry Pi images
The Vulnerability Gap: Why Discovery Is Outrunning Repair
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
The Taiwan attack was built with two free downloads from vendors nobody rates
[NEU] [mittel] expat: Schwachstelle ermöglicht Denial of Service
[NEU] [mittel] GIMP: Mehrere Schwachstellen ermöglichen Codeausführung
[NEU] [mittel] MailPit: Schwachstelle ermöglicht Denial of Service
GLM-5.3's emergent security capabilities: 1,097 critical/high severity bugs discovered across kernels, browsers, and infrastructure, oldest flaw from 1981
Exclusive: Linux Foundation's Akrites to Go Live in September
[NEU] [mittel] CPython: Mehrere Schwachstellen
[NEU] [mittel] vllm: Mehrere Schwachstellen
Hazmat: Open-source containment for AI agents
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
LiteLLM supply chain attack impacted over 2,500 organizations
[NEU] [hoch] Snipe-IT: Mehrere Schwachstellen
[NEU] [hoch] Fleet: Mehrere Schwachstellen
[NEU] [mittel] NetBox: Schwachstelle ermöglicht Offenlegung von Informationen
PentestGPT: Open-source automated penetration testing agentic framework
[NEU] [hoch] Metabase: Mehrere Schwachstellen
Python Now Has a Post-Quantum Encryption Library
Chainloop: Open-source evidence store and policy engine for the software supply chain
Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding
Cloudflare OS goes open source with a record of everything its agents read
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
Future AGI: Open-source platform for shipping self-improving AI agents
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
Multiples vulnérabilités dans LibreNMS (04 août 2026)
Defcon badges feature new open-source chip for enhanced security
9front “THIS WAS SUPPOSED TO BE FUN” released
[NEU] [hoch] rclone: Mehrere Schwachstellen
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
CISA issues recommendations to federal agencies on open-source software security
Open Source Software: Security Principles and Practices
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Amazon identifies North Korean hacker group behind open-source supply chain attacks
Model Context Protocol releases major update to AI interaction technology
MCP gets an enterprise makeover
How we use /goal to find bugs in Patch the Planet
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack
Tech giants form alliance to put open AI in cyber defenders’ hands
Vulnérabilité dans Traefik (27 juillet 2026)
Multiples vulnérabilités dans GLPI (27 juillet 2026)
Nono: Open-source sandbox for AI agents
Microsoft, tech companies throw weight behind spread of open-source AI
Multi-patch vulnerability fixes can leave open source exposed
Snowpick: Open-source ServiceNow exposure scanner
Cisco Launches Low-Cost AI Models for Source Code Security
AI-generated reports push GNOME to shorten its disclosure window
Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
Nearly half of open-source AI projects never reach production
Follow the money, especially in open source
Ledger launches open-source toolkit for secure AI agents
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
[Security Blog] Modern Software’s Hidden Cost: Managing Risk in the Open-Source Ecosystem
1999 Called and It Wants It's Exploits Back - PSW #935
Microsoft releases its weird ’90s IRC client as open source
OWASP CVE Lite CLI Graduates to Lab Project Status
What public money does to open-source projects
NPM ecosystem hit with two new supply chain compromises
SingGuard-NSFA: Open-source guardrails for agentic AI
Chatto: Open-source team messenger with privacy at its core
Cynative: Open-source deep research agent
[NEU] [mittel] MISP: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
The open source library holding up your stack might have one maintainer
[NEU] [niedrig] RabbitMQ: Schwachstelle ermöglicht Offenlegung von Informationen
Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
Qualys Joins Chainguard Athena: Turning Coalition-Scale Findings Into Validated Action