#open source
33 stories taggedopen source.

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.
A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

Two Bugs in GeoNetwork Let Attackers Take Over Government Map Portals
A chain of flaws in the open-source software behind many public geoportals allowed strangers on the internet to run their own code on the server. Fixes landed in July 2026.

AI Is Writing Your Code Faster Than Your Security Team Can Read It
Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

Anthropic Opens Its Most Powerful AI to More Security Defenders and Puts $35 Million Behind Open-Source Safety
The company behind the Claude AI system is carefully widening access to its strongest models for cybersecurity work, while keeping ordinary users and criminals locked out.

Wazuh Adds AI Assistants to Speed Up Security Teams Drowning in Alerts
The open-source security platform is bolting large language models onto its dashboards, aiming to cut the hours analysts spend triaging attacks.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them
Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.
A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

Open source grew up in a hurry, and the security bill is coming due
The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.