Tag

#open source

33 stories taggedopen source.

Illustration for the story: CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
Policy & Regulation

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means

The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

4 min read
A software developer's workstation with multiple monitors displaying code repositories and vulnerability scanning tools, with notification alerts cascading acro
AI Security

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.

A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

4 min read
A government geospatial data center with map servers and portal systems, security researchers analyzing code vulnerabilities in the open-source mapping applicat
Vulnerabilities

Two Bugs in GeoNetwork Let Attackers Take Over Government Map Portals

A chain of flaws in the open-source software behind many public geoportals allowed strangers on the internet to run their own code on the server. Fixes landed in July 2026.

3 min read
A code repository dashboard on a monitor showing rapidly accumulating open-source packages and dependencies, with a growing vulnerability count meter displayed
AI Security

AI Is Writing Your Code Faster Than Your Security Team Can Read It

Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

4 min read
A security researcher at a computer workstation examines threat data on multiple monitors displaying code and threat intelligence dashboards, with a badge or cr
AI Security

Anthropic Opens Its Most Powerful AI to More Security Defenders and Puts $35 Million Behind Open-Source Safety

The company behind the Claude AI system is carefully widening access to its strongest models for cybersecurity work, while keeping ordinary users and criminals locked out.

4 min read
A security operations center dashboard flooded with alert notifications, with an AI assistant interface materializing to sort and analyze the overwhelming data
AI Security

Wazuh Adds AI Assistants to Speed Up Security Teams Drowning in Alerts

The open-source security platform is bolting large language models onto its dashboards, aiming to cut the hours analysts spend triaging attacks.

4 min read
A network traffic analyzer dashboard with cascading data streams and highlighted vulnerabilities, showing file upload processes and access control bypass attemp
Vulnerabilities

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks

The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

4 min read
A software development workspace with AI coding assistant running on one monitor displaying auto-imported open source packages at high speed, a security team's
AI Security

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them

Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

4 min read
A timeline graphic displayed on a large monitor tracing decades of software history, highlighting ancient code libraries and print-spooler systems, Stuxnet malw
Vulnerabilities

Some of the Bugs That Hid Inside Everyday Software for Decades

From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

4 min read
A GitHub repository page displayed on a monitor, a private key snippet visible in code history with a glowing red circle and X overlay, security warning banners
Identity & Access

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.

A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

3 min read
A sprawling network of interconnected open-source code repositories and libraries visible in a constellation of glowing nodes, with security cracks forming betw
Opinion

Open source grew up in a hurry, and the security bill is coming due

The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

4 min read
A developer's terminal window showing Paperclip AI agent code execution, with command-line inputs and server responses visible, overlaid with vulnerability indi
AI Security

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host

Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

4 min read
A computer screen displaying an AI model loading process with hidden code execution occurring in the background, safety switches visibly bypassed with warning i
AI Security

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine

Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

3 min read
A spacecraft control center with multiple monitors displaying NASA flight software interfaces, one screen showing a command input field and system crash notific
Vulnerabilities

NASA's Core Flight System has a flaw that can crash spacecraft software

A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

4 min read
A government office workspace with multiple screens displaying open source code repositories and security vetting checklists, with the C4 trust framework diagra
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
© 2026 Threat Vectr