#open source
33 stories taggedopen source · page 2 of 3.

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In
A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands
CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

Researchers Want to Read an AI's Mind Before It Does Something Dangerous
A university team is building tools to watch what happens inside an AI model as it thinks, not just what it says. The goal: catch harmful requests that slip past every other filter.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically
VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
JFrog researchers say 148 malicious packages used npm as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into an attack campaign that ran for roughly two weeks in May 2024.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

When AI writes your code, your supply chain just got a new stranger in it
For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

Flipper Zero firmware goes into maintenance mode as company hands the wheel to volunteers
The pocket-sized hacking gadget's maker is shrinking its firmware team and letting the community vote on what gets built next.