#open-source security
19 stories taggedopen-source security.

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps
One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year alone, a sharp rise tied to Broadcom's push into AI.

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it
Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

Arch Linux freezes package adoptions after wave of malware sneaks into user repository
A stealer that harvests browser logins, crypto wallets and SSH keys has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.
A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure
A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years
A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems
A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

OpenMandriva Linux Says Angry Contributor Wiped Years of Work
A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

Three Quick Hits: Canadian Hacker Jailed, Open-Source Flaws Dropped, ATM Jackpotters Sentenced
A week's worth of security stories that deserve a second look — from an Anonymous-linked arrest in Canada to cash-machine criminals facing US prison time.

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them
A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.