software
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which …
Halo-record: Open-source audit trails for AI agents
Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each …
AI AppSec tools agree on just 5% of security findings
Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application …
Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across …
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a tool that sits between an AI assistant and the computer it runs on. Its core local runtime is free and open source. When the assistant tries something risky, …
Hazmat: Open-source containment for AI agents
Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor …
Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that …
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether …
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what …
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, …
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one …
Qodana 2026.2 adds post-quantum crypto checks for JVM code
Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at …
Featured news
Resources
Don't miss
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
- 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
- Other users can watch your browsing and time your keystrokes through OS file notifications
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
- Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts