search
open source security community
Trends
- 1Nvidia Open-Sources AI Safety Software to Catch VulnerabilitiesβΌNvidia AI Safety Software Is Open Source to Catch Vulnerabilities -- Market Talk
Nvidia has released its AI safety software as open source, a move aimed at helping developers detect and address vulnerabilities in artificial intelligence systems. By making the tooling publicly available, the company is positioning itself as a leader in AI security while inviting the broader developer community to scrutinize and improve the code. Industry watchers see it as part of a wider push for transparency in AI safety.
- 2OPAQUE's verifiable AI open source tools near half a million downloadsβΌOPAQUE's Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
OPAQUE Systems says downloads of its open source software for verifiable AI are approaching 500,000, while community code contributions have grown more than tenfold. The company, which builds privacy-preserving confidential computing tools, presented the figures as a sign of momentum behind its approach to running AI workloads securely, with adoption spreading across the developer community and coverage in technology trade press.
- 3Colitu launches open-source VPN project focused on privacyβHello, Fediverse! We're Colitu, an open-source VPN project focused on privacy, security, and reliable connectivity in ch
Colitu, a new open-source VPN project, has introduced itself online, describing its mission as providing privacy, security, and reliable connectivity in challenging network environments such as censored or restricted networks. The team says privacy tools should be transparent, accessible, and community-built, and plans to share engineering updates as development continues.
- 4Four New Full Members Join Drupal Security TeamβThrilled to announce that four provisional members have earned full membership on the Drupal Security Team! Welcome: π«π·
The Drupal Security Team has announced that four provisional members have earned full membership: Pierre Rudloff of France, Joseph Zhao of Australia, Bram Driesen of Belgium, and Swan Kalata of the United States. The team coordinates security fixes and advisories for the Drupal content management system, and the announcement congratulates the newcomers on completing the provisional period.
- 5Google pauses bug bounty submissions for open-source softwareβGoogle stellt Bug-Bounty-Programm fΓΌr Open Source vorerst ein Google nimmt seit 1. Oktober im Bug-Bounty-Programm fΓΌr Op
Google has stopped accepting vulnerability reports for open-source software through its bug bounty program as of October 1. The company will temporarily no longer pay rewards for product flaws found in open-source projects, though reports on its own flagship products continue. The move is drawing attention in the security community, as the open-source incentive program was seen as an important way to support researchers auditing widely used projects.
- 6F-Droid 2.0 launches with redesigned Android appβ# F -Droid 2.0 cambia volto: nuova # app # Android , # ricerca migliorata e piΓΉ controllo sulla # privacy # uno # sicure
F-Droid has released version 2.0 of its free and open-source Android app store, featuring a redesigned interface, improved search functionality and stronger privacy controls. The update also emphasizes user security as an alternative to big tech app stores. Early reactions among open-source enthusiasts are positive, with users welcoming the focus on privacy and greater control over installed software.
- 7Cloudflare releases open-source security audit tool for coding agentsβcloudflare/security-audit-skill
Cloudflare has published an open-source tool called security-audit-skill, a skill for coding agents that runs multi-phase security audits of code. Its findings are independently verified and produced in a machine-readable format, so other tools and developers can consume them directly. It is written in JavaScript and available on GitHub, where it has drawn early attention from the developer community.
- 8Ubuntu drops Btrfs, XFS and ZFS boot support under Secure Bootβπ£ Ubuntu drops Btrfs, XFS & ZFS boot support with Secure Boot https://www. omgubuntu.co.uk/2026/10/ubuntu -2610-secure-b
Ubuntu 26.10 no longer supports booting from Btrfs, XFS or ZFS filesystems when Secure Boot is enabled, a change tied to how GRUB handles these formats. Linux users and open source communities are debating the move, with some criticising the reduced flexibility for advanced setups and others noting Secure Boot scenarios are limited.
- 9Anthropic Launches Cyber Mission to Protect Open-Source SoftwareβAnthropic Launches Cyber Mission to Secure Open-Source and Critical Infrastructure
Anthropic has announced a new cyber mission aimed at improving the security of open-source software and critical infrastructure. The initiative reflects the AI company's push into cybersecurity, deploying its technology to help identify vulnerabilities in widely used public code and systems. The announcement has drawn attention from the tech and security communities, with observers weighing the implications of an AI firm taking a direct role in defending essential digital infrastructure.
- 10
Drop is a new open-source tool for sandboxing Linux applications without root privileges, and it supports gVisor, Google's application kernel for stronger isolation. It is currently the top post on Hacker News, where users are discussing the project and its approach to running untrusted code safely on a Linux machine. The reaction so far is mixed, with the technical community weighing its usefulness against existing sandboxing options.
- 11Anthropic offers free AI security scans for open-source projectsβΌAnthropic launches free AI security scans for open-source projects Anthropic's offering to help open-source projects tra
Anthropic has launched OSS Scanner, a free service that provides open-source projects with periodic, AI-driven security scans to help uncover vulnerabilities. Projects must opt in to receive what the company describes as thorough, recurring reviews of their code. The move positions Anthropic alongside other AI firms courting the developer community, though some observers will scrutinise how the scans handle sensitive project data.
- 12
AI company Anthropic has announced a free vulnerability scanner aimed at open-source software projects. The tool is intended to help maintainers find and fix security weaknesses in their code without paying for commercial scanning services. The announcement was reported by The Hacker News. Details on the tool's features, availability and how projects can sign up have not yet been widely reported, and security community reaction is still forming.
- 13MailAccess launches as an email OSINT frameworkβShow HN: MailAccess β the true Email OSINT framework
A new tool called MailAccess has been introduced on Hacker News, described by its developer as a full framework for open-source intelligence gathering based on email addresses. The launch is drawing attention from the security community, with debate likely around its usefulness for investigators and its potential for misuse in privacy attacks, phishing reconnaissance and doxxing.
- 14
OpenBao is an open-source tool written in Go for managing, storing, and distributing sensitive data such as passwords and API secrets, encryption keys, and digital certificates. It emerged as a community-maintained alternative to HashiCorp Vault after licensing changes. On GitHub's trending list this week it has picked up new stars and attention, with developers discussing it as a free, open option for handling secrets securely in their infrastructure.
- 15Anthropic offers free AI security scans for open-source projectsβAnthropic launches free AI security scans for open-source projects https://www.theverge.com/ai-artificial-intelligence/1
Anthropic has launched a free AI-powered security scanning service for open-source projects, according to a report by The Verge. The tool is aimed at helping maintainers find vulnerabilities in widely used code at no cost. The announcement is drawing attention from developers and security observers discussing the growing role of AI companies in open-source security.
- 16XOrg Server and Xwayland security updates patch multiple flawsβMultiple # Security Issues Patched in XOrg Server 21.1.25 and Xwayland 24.1.14, Update Now https:// 9to5linux.com/multip
New releases of XOrg Server 21.1.25 and Xwayland 24.1.14 patch multiple security vulnerabilities, and users are being urged to update their systems as soon as possible. The announcement is drawing attention in the Linux and open-source community, where these components are widely used to handle graphics display duties on Linux desktop systems.
- 17Parrot OS 7.4 Released With Linux Kernel 7.1 and AnonSurf 6.0βParrot OS 7.4 rolls out with Linux kernel 7.1, AnonSurf 6.0, refreshed security tools, updated Raspberry Pi images, and
The Parrot security team has released Parrot OS 7.4, a point update to its privacy-focused Linux distribution. The release ships with Linux kernel 7.1, the new AnonSurf 6.0 anonymity tool, refreshed security and penetration testing utilities, updated Raspberry Pi images, and broader package improvements. Users in the Linux and open-source community are welcoming the update for keeping the distro's privacy tooling current.
- 18testers try out open-source project LittleFediβGot the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,
A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.
- 19Anthropic launches free AI security scanner for open-source projectsβΌAnthropic launches free AI-powered security scanner for open-source software projects
Anthropic has released a free, AI-powered security scanner for open-source software projects, according to press coverage. The tool is intended to help developers find vulnerabilities in their code at no cost. The move is being read as part of the broader push by AI companies to position their models as practical safety tools, while also expanding Anthropic's reach among developers.
- 20Accrescent developers detail API management challengesβHow does a complex application like Accrescent manage its API? In this blog post, we discuss some of the API challenges
The developers behind Accrescent, a security-focused Android app store, have published a blog post explaining how the application manages its API. The post, titled 'A Tale of Too Many Protocols', describes the API challenges the team encountered and their efforts to build a single source of truth for the project's protocols.
- 21OpenSSF Announces Expanded Membership and Global Policy Resources in EuropeβΌOpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe
The Open Source Security Foundation (OpenSSF) announced expanded membership and new global policy resources during its Community Day Europe event. The announcement, distributed by the Linux Foundation via PR Newswire, highlights the foundation's growing base of participating organizations and its effort to provide guidance on open source security policy worldwide. Further details about the new members and resources were not included in available coverage.
- 22LSU Cyber Team Wins $750K from NSA for Digital Forensics ToolβΌLSU Cyber Team Releases First Open-Source Tool to Recover Fragmented Digital Evidence at Scale, Solves Two 20-year-old Grand Challenges, Wins $750K from NSA
A Louisiana State University cybersecurity team has released the first open-source tool capable of recovering fragmented digital evidence at scale, solving two longstanding 'grand challenges' in digital forensics that have remained open for roughly 20 years. The work has earned the team a $750,000 award from the National Security Agency, and the tool is now freely available for forensic investigators and researchers.
- 23NetBSD works to stabilize the Racoon2 IKE daemonβImproving and Stabilizing the Racoon2 IKE Daemon in NetBSD
The NetBSD Project has published a write-up on efforts to improve and stabilize the Racoon2 IKE daemon, the component that handles Internet Key Exchange for setting up secure IPsec connections. The post outlines ongoing work to make the long-standing daemon more reliable, and it is drawing attention from developers interested in networking security and open-source systems work.
- 24Flatpak 1.18.4 Patches Six Security Vulnerabilitiesβ# Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities https:// linuxiac.com/flatpak-1-18-4-re leased-wit
A new maintenance release of Flatpak, the Linux application sandboxing and distribution framework, is out with version 1.18.4 addressing six security vulnerabilities. Linux users and system administrators are being encouraged to update their installations promptly. The release is drawing attention in the free and open-source software and cybersecurity communities, where Flatpak updates are closely watched because the tool is widely used for running sandboxed desktop applications across Linux distributions.
- 25Anthropic unveils AI-powered OSS vulnerability scannerβDiscover the Anthropic OSS Scanner. Learn how AI models provide automated vulnerability scanning and remediation for ope
Anthropic has introduced the OSS Scanner, a tool that uses its AI models to automatically scan open source projects for security vulnerabilities and suggest remediations. The security community is sharing details of the release, with coverage highlighting how automated scanning could help under-resourced open source projects find and fix flaws faster.
- 26OpenSSL 4.0.3 Released as Security Patch, Update Nowβ# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 27Google suspends part of its open source bug bountyβΌWhy Google is suspending part of its open source bug bounty
Google is suspending part of its bug bounty program covering open source projects. The move means security researchers will temporarily no longer be rewarded for reporting certain vulnerabilities in Google's open source software. The announcement is drawing attention from the security community, with researchers questioning the implications for vulnerability disclosure and Google's commitment to open source security.
- 28CyclePatrol Open-Source Wi-Fi Security Tool DebutsβIntroduction: The Rise of CyclePatrol As Wi-Fi networks proliferate in public spaces, the development of CyclePatrol exe
CyclePatrol, a new open-source Bash tool built for Kali Linux, has been introduced to the cybersecurity community as public Wi-Fi networks continue to spread. Its developers frame it as an example of the sector's dual duty to innovate while maintaining ethical standards. Reaction so far centres on whether the tool will help security professionals audit public networks responsibly or invite misuse, a familiar debate whenever offensive-sounding utilities are released openly.
- 29CIRCL launches major website update with new feedsβWe did a major update to our website: https://www. circl.lu/ There are now RSS and Atom feeds available: https://www. ci
CIRCL, Luxembourg's national cybersecurity agency, has rolled out a major redesign of its website. The update adds RSS and Atom feeds for following its content, plus a complete overview page listing all of the organisation's open-source and open-standard projects. The announcement is drawing attention from the cybersecurity and open-source community, which closely follows CIRCL's freely available tools and resources.
- 30Anthropic Offers Free AI Bug Hunting for Open-Source ProjectsβAnthropic Is Offering Free AI Bug Hunting for Open-Source Projects
Anthropic is rolling out free AI-powered bug hunting for open-source software projects. The initiative would let maintainers use the company's AI tools to find security flaws and other defects in their code at no cost. The move is being read as both a contribution to the open-source community, which often lacks security resources, and a way to promote Anthropic's AI offerings to developers.
- 31
HackerNoon has published an interview with Pranshu Raghav on securing the open source AI ecosystem. The piece examines how developers and security teams can protect openly available AI models, tools and pipelines from misuse and vulnerabilities as adoption of open AI projects accelerates across the software industry.
- 32AI Finds More Vulnerabilities, But Open Source Lacks ManpowerβΌAI is Finding More Vulnerabilities But Open Source Needs More People t
AI tools are increasingly effective at discovering software vulnerabilities, but security experts warn that open source projects still lack the human maintainers needed to review, triage and fix the growing volume of reported flaws. Infosecurity Magazine highlights the widening gap between machine-generated bug reports and the limited developer capacity available to address them across widely used open source components.
- 33Google Winds Down Part of Its Open Source Bounty ProgramβΌGoogle Has Shut Down Part of its Open Source Bounty Program
Google has shut down part of its open source bounty program, which paid researchers and developers for improving open source projects. The move affects a program that had rewarded security fixes and contributions to community-driven software. It is the latest in a series of cost-cutting measures at the company, and open source advocates have criticised the decision as a step back from Google's support for the community.
- 34Nous Research raises $90M at $1.5B valuationβΌNous Research raises $90M at $1.5B valuation for open-source AI
Nous Research has raised $90 million in funding at a $1.5 billion valuation to advance its open-source AI work. The deal marks a significant milestone for the startup, which builds open models as an alternative to closed systems from major AI labs. The funding signals continued strong investor appetite for open-source artificial intelligence companies.
- 35Google pauses open source bug bounty amid flood of AI reportsβΌGoogle benches open source bug bounty program following βsignificant riseβ in AI submissions
Google has suspended its open source bug bounty program, citing a significant rise in AI-generated vulnerability submissions. The company says many of the reports flooding in are low-quality, machine-written findings that take up valuable reviewer time without adding real security value. The move has sparked debate among security researchers about the impact of automated tools on responsible disclosure programs and how bounty platforms should handle AI-created noise.
- 36MapRoulette fixes backend security vulnerabilities disclosed by researcherβ@ jakelow has disclosed a few now-fixed security issues related to the backend of @ MapRoulette . βTL;DR: # MapRoulette
Security researcher Jake Low has disclosed several now-fixed vulnerabilities in the backend of MapRoulette, the OpenStreetMap mapping challenge platform. According to the disclosure, the flaws may have exposed access credentials β though not passwords β and user email addresses to attackers. The issues have since been patched, and the disclosure is drawing attention within the OpenStreetMap and open-source mapping communities.
- 37Behind Substack: the founders Best, McKenzie and SethiβBehind Substack: Best, McKenzie, and Sethi # negativepid # digitalInvestigations # OSINT # cybersecurity # AI # tech # o
A cybersecurity-focused publication has published a profile of the people behind Substack, the newsletter platform, naming co-founders Chris Best, Hamish McKenzie and Jairaj Sethi. The piece sits within ongoing digital-investigation and open-source intelligence discussions about the company's technology, security practices and role in online publishing.
- 38Metasploit Wrap Up Highlights Eclectic New ModulesβMetasploit Wrap Up:A Collection of What Can Only Be Called Eclectic Modules https:// packetstorm.news/news/view/451 07 #
Rapid7's latest Metasploit Wrap Up rounds off another week of additions to the open-source penetration testing framework, describing the new modules as eclectic. The roundup lists freshly contributed exploits and auxiliary modules from the security research community. Security professionals follow these weekly summaries to keep their tooling current for penetration tests and vulnerability research.
- 39Infosec newcomer introduces themselves on MastodonβΌHello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 40Google Freezes Open Source Bug Bounty Until 2027 Amid AI Spam FloodβΌGoogle Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Flood
Google has paused its open source bug bounty programme until 2027, citing an overwhelming flood of AI-generated spam reports. Invalid, low-quality vulnerability submissions allegedly produced by AI tools have crowded out legitimate security research, making the programme unsustainable in its current form. The move has sparked debate in the security community about how AI is affecting vulnerability disclosure processes and whether other bounty programmes will follow suit.
Repos
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f