Tag

#open-source security

20 stories taggedopen-source security.

A MacBook Pro screen displaying the Homebrew package manager interface with a vulnerability scanner panel open, security notification badges visible, and a rest
Vulnerabilities

Homebrew 7.0.0 ships a vulnerability scanner and locks down its sandbox

The macOS package manager now checks installed software against a public flaw database and blocks default access to your home folder.

4 min read
A computer workstation displaying cascading code and network diagrams in dim blue light, with forensic investigation equipment and documentation scattered acros
Threat Intelligence

Australian police arrest two alleged members of TeamPCP supply-chain crew

The pair, from Western Australia, are linked to a hacking collective that poisoned open-source software used by thousands of companies, and to the extortion crew Fulcrumsec.

4 min read
Illustration: A split-screen
Threat Intelligence

Three Security Stories You May Have Missed: Airport Attack, Fake Breach Data, and a Bank Under Pressure

A busy week in cybersecurity produced a cluster of stories worth attention: a UK airport group hit by hackers, questions over whether a clothing brand's stolen data was real, and a major US bank pushing back on ransomware claims.

3 min read
Police vehicles and law enforcement activity outside a technology-related facility in Western Australia, with digital security imagery on nearby screens
Threat Intelligence

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP

The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

4 min read
A split timeline visualization: on the left, an AI system rapidly discovering security bugs with green checkmarks appearing in seconds, on the right, a slow man
AI Security

AI Finds the Bugs in Hours. Fixing Them Still Takes Months.

Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

4 min read
A corporate development environment showing Spring framework code with security patches being silently applied in the background, while a security team at separ
Policy & Regulation

Silent Software Patches Protect Hackers, Not Users

When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

4 min read
A Java development environment showing Spring framework code with multiple security vulnerability indicators and patch notifications stacked in the interface
Vulnerabilities

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps

One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

3 min read
A code editor showing JavaScript sandbox security functions with breach points highlighted, surrounded by documentation windows displaying vulnerability details
Vulnerabilities

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it

Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

3 min read
Cybersecurity incident timeline chart on a large monitor showing the LiteLLM package compromise alongside the separate Trivy scanner vulnerability, with data da
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
A developer's desk with dual monitors displaying lines of code and git commit logs, a physical smoke detector mounted on the wall above in soft focus, morning l
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
A developer's workstation screen showing lines of code being examined under a magnifying glass, with warning symbols floating in the digital space around it, re
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
A developer's laptop showing the Paperclip AI platform interface with a registration form, suspicious command execution visible in the terminal behind it
AI Security

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines

Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

4 min read
A developer's workstation with multiple code editor windows open, repository trees visible, red error warnings cascading across displays, chaos of digital conte
Threat Intelligence

Arch Linux freezes package adoptions after wave of malware sneaks into user repository

A stealer that harvests browser logins and crypto wallets has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

4 min read
Illustration: a developer's dark desk, glowing keyboard
Threat Intelligence

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week

Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

3 min read
Extreme close-up of a glowing digital server rack in a dark data center, rows of blinking amber and green status lights stretching into deep focus, cool blue am
Policy & Regulation

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure

A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.

3 min read
© 2026 Threat Vectr