GitHub

New GitHub, PyPI Policies Boost Supply Chain Security

New GitHub, PyPI Policies Boost Supply Chain Security 2026-07-27 at 17:26 By Ionut Arghire Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek. This article is an excerpt from […]

New GitHub, PyPI Policies Boost Supply Chain Security Read More »

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub revamps bug bounty program with new VIP tier, payout changes 2026-07-23 at 11:35 By Anamarija Pogorelec GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the […]

GitHub revamps bug bounty program with new VIP tier, payout changes Read More »

Small teams are the heaviest users of AI coding agents

Small teams are the heaviest users of AI coding agents 2026-07-22 at 09:00 By Sinisa Markovic The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually […]

Small teams are the heaviest users of AI coding agents Read More »

Snowpick: Open-source ServiceNow exposure scanner

Snowpick: Open-source ServiceNow exposure scanner 2026-07-22 at 08:30 By Mirko Zorz An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances […]

Snowpick: Open-source ServiceNow exposure scanner Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) […]

AI agents tricked into recommending malicious GitHub repositories Read More »

Open-source maintainers still work underfunded as sponsorship crosses $100 million

Open-source maintainers still work underfunded as sponsorship crosses $100 million 2026-07-21 at 11:37 By Anamarija Pogorelec A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend […]

Open-source maintainers still work underfunded as sponsorship crosses $100 million Read More »

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform 2026-07-20 at 09:00 By Anamarija Pogorelec Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package […]

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform Read More »

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process 2026-07-16 at 10:45 By Anamarija Pogorelec Developers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host. […]

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process Read More »

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware 2026-07-15 at 16:52 By Zeljka Zorz A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, […]

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware Read More »

SingGuard-NSFA: Open-source guardrails for agentic AI

SingGuard-NSFA: Open-source guardrails for agentic AI 2026-07-15 at 08:30 By Anamarija Pogorelec SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidentiality, […]

SingGuard-NSFA: Open-source guardrails for agentic AI Read More »

Cynative: Open-source deep research agent

Cynative: Open-source deep research agent 2026-07-13 at 09:00 By Mirko Zorz Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on […]

Cynative: Open-source deep research agent Read More »

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Ghost Accounts Abuse GitHub API in Mass Recon Campaign 2026-07-11 at 20:30 By Ionut Arghire Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ghost Accounts Abuse GitHub API in Mass Recon Campaign Read More »

Network of 200 GitHub Repositories Used for Malware Infection

Network of 200 GitHub Repositories Used for Malware Infection 2026-07-10 at 11:00 By Ionut Arghire A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek. This article is an […]

Network of 200 GitHub Repositories Used for Malware Infection Read More »

Your coding agent says no in chat and yes in the code

Your coding agent says no in chat and yes in the code 2026-07-09 at 13:44 By Mirko Zorz Millions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these […]

Your coding agent says no in chat and yes in the code Read More »

Open-source collaboration is growing worldwide and putting pressure on maintainers

Open-source collaboration is growing worldwide and putting pressure on maintainers 2026-07-09 at 08:10 By Sinisa Markovic Developers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, […]

Open-source collaboration is growing worldwide and putting pressure on maintainers Read More »

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection 2026-07-08 at 13:30 By Ionut Arghire Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek. This article […]

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Read More »

20 open-source cybersecurity tools to keep your team ready for anything

20 open-source cybersecurity tools to keep your team ready for anything 2026-07-08 at 08:30 By Anamarija Pogorelec AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent […]

20 open-source cybersecurity tools to keep your team ready for anything Read More »

Apple Container: Open-source tool for Linux containers on the Mac

Apple Container: Open-source tool for Linux containers on the Mac 2026-07-07 at 08:00 By Anamarija Pogorelec Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and […]

Apple Container: Open-source tool for Linux containers on the Mac Read More »

Omnigent: Open-source AI agent framework and meta-harness

Omnigent: Open-source AI agent framework and meta-harness 2026-07-06 at 08:30 By Sinisa Markovic Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way […]

Omnigent: Open-source AI agent framework and meta-harness Read More »

Flipper Zero firmware development gets a fresh set of community rules

Flipper Zero firmware development gets a fresh set of community rules 2026-07-06 at 07:57 By Sinisa Markovic Owners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has […]

Flipper Zero firmware development gets a fresh set of community rules Read More »

Scroll to Top