#open-source security
20 stories taggedopen-source security.

Homebrew 7.0.0 ships a vulnerability scanner and locks down its sandbox
The macOS package manager now checks installed software against a public flaw database and blocks default access to your home folder.

Australian police arrest two alleged members of TeamPCP supply-chain crew
The pair, from Western Australia, are linked to a hacking collective that poisoned open-source software used by thousands of companies, and to the extortion crew Fulcrumsec.

Three Security Stories You May Have Missed: Airport Attack, Fake Breach Data, and a Bank Under Pressure
A busy week in cybersecurity produced a cluster of stories worth attention: a UK airport group hit by hackers, questions over whether a clothing brand's stolen data was real, and a major US bank pushing back on ransomware claims.

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP
The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

AI Finds the Bugs in Hours. Fixing Them Still Takes Months.
Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

Silent Software Patches Protect Hackers, Not Users
When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps
One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it
Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

Arch Linux freezes package adoptions after wave of malware sneaks into user repository
A stealer that harvests browser logins and crypto wallets has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure
A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.