open source
Specter: Open-source NFC reader bug sweep for Flipper Zero
Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own …
Hugging Face breach reignites open-weights debate, raises liability questions
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident …
Tech giants form alliance to put open AI in cyber defenders’ hands
NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models …
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every …
Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A …
Snowpick: Open-source ServiceNow exposure scanner
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and …
Open-source maintainers still work underfunded as sponsorship crosses $100 million
A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. …
AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language …
Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that …
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State …
What public money does to open-source projects
Most of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine …
FreeRDP 3.29.0 security update resolves 22 advisories
FreeRDP is a free implementation of the Remote Desktop Protocol, released under the Apache license, and it runs on a large share of workstations and servers through the many …
Featured news
Resources
Don't miss
- September 2026 Patch Tuesday forecast: All we need is more time
- OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets
- Thomson Reuters reveals breach that exposed U.S. and Canadian court records
- Your threat feed is someone else’s database: What ingesting malware intel at scale takes
- When AI quietly breaks things, who pays?