open source

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Hottest cybersecurity open-source tools of the month: August 2026

Hottest cybersecurity open-source tools of the month: August 2026 2026-08-26 at 07:30 By Anamarija Pogorelec Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from

Hottest cybersecurity open-source tools of the month: August 2026 Read More »

HOL Guard: Open-source antivirus for AI agents

HOL Guard: Open-source antivirus for AI agents 2026-08-25 at 08:30 By Anamarija Pogorelec HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your

HOL Guard: Open-source antivirus for AI agents Read More »

Hazmat: Open-source containment for AI agents

Hazmat: Open-source containment for AI agents 2026-08-17 at 08:00 By Anamarija Pogorelec Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the

Hazmat: Open-source containment for AI agents Read More »

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers 2026-08-13 at 06:53 By Anamarija Pogorelec Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers Read More »

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT: Open-source automated penetration testing agentic framework 2026-08-12 at 08:30 By Anamarija Pogorelec PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and

PentestGPT: Open-source automated penetration testing agentic framework Read More »

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 2026-08-11 at 12:15 By Anamarija Pogorelec Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 Read More »

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub Dependabot malware alerts now cover eight ecosystems 2026-08-10 at 10:01 By Mirko Zorz GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month.

GitHub Dependabot malware alerts now cover eight ecosystems Read More »

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop: Open-source evidence store and policy engine for the software supply chain 2026-08-10 at 08:30 By Sinisa Markovic Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable

Chainloop: Open-source evidence store and policy engine for the software supply chain Read More »

Future AGI: Open-source platform for shipping self-improving AI agents

Future AGI: Open-source platform for shipping self-improving AI agents 2026-08-05 at 08:30 By Anamarija Pogorelec Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and

Future AGI: Open-source platform for shipping self-improving AI agents Read More »

Your enterprise AI footprint is about three times bigger than your model list

Your enterprise AI footprint is about three times bigger than your model list 2026-08-05 at 07:00 By Anamarija Pogorelec Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39

Your enterprise AI footprint is about three times bigger than your model list Read More »

OWASP’s subtractive security project measures the attack paths you erased

OWASP’s subtractive security project measures the attack paths you erased 2026-08-04 at 08:30 By Mirko Zorz An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz

OWASP’s subtractive security project measures the attack paths you erased Read More »

CISA lays out new guidance for using open-source software

CISA lays out new guidance for using open-source software 2026-08-03 at 14:53 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open

CISA lays out new guidance for using open-source software Read More »

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills 2026-08-03 at 08:30 By Anamarija Pogorelec SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills Read More »

CISA sets a new SBOM baseline

CISA sets a new SBOM baseline 2026-07-30 at 15:23 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). An SBOM is a

CISA sets a new SBOM baseline Read More »

Specter: Open-source NFC reader bug sweep for Flipper Zero

Specter: Open-source NFC reader bug sweep for Flipper Zero 2026-07-29 at 08:00 By Anamarija Pogorelec Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a

Specter: Open-source NFC reader bug sweep for Flipper Zero Read More »

Hugging Face breach reignites open-weights debate, raises liability questions

Hugging Face breach reignites open-weights debate, raises liability questions 2026-07-28 at 18:55 By Zeljka Zorz The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of

Hugging Face breach reignites open-weights debate, raises liability questions Read More »

Tech giants form alliance to put open AI in cyber defenders’ hands

Tech giants form alliance to put open AI in cyber defenders’ hands 2026-07-27 at 17:43 By Sinisa Markovic NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during

Tech giants form alliance to put open AI in cyber defenders’ hands Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

Snowpick: Open-source ServiceNow exposure scanner

Snowpick: Open-source ServiceNow exposure scanner 2026-07-22 at 08:30 By Mirko Zorz An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances

Snowpick: Open-source ServiceNow exposure scanner Read More »

Scroll to Top