#open source
44 stories taggedopen source · page 2 of 3.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically
VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

When AI writes your code, your supply chain just got a new stranger in it
For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

North Korean Hackers Poisoned Over 100 Open Source Packages to Spy on Developers
A campaign called PolinRider has quietly corrupted legitimate software building blocks used by developers worldwide, planting tools that steal data and leave a hidden door open for attackers.

Flipper Zero firmware goes into maintenance mode as company hands the wheel to volunteers
The pocket-sized hacking gadget's maker is shrinking its firmware team and letting the community vote on what gets built next.

IBM and Red Hat Launch $5 Billion Initiative to Secure Open-Source Software
IBM and Red Hat invest heavily in Project Lightwell to address open-source software vulnerabilities revealed by Anthropic's AI.

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos
A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, researchers say.