search
open source security community
Trends
- 1Nvidia Open-Sources AI Safety Software to Catch Vulnerabilities▼Nvidia AI Safety Software Is Open Source to Catch Vulnerabilities -- Market Talk
Nvidia has released its AI safety software as open source, a move aimed at helping developers detect and address vulnerabilities in artificial intelligence systems. By making the tooling publicly available, the company is positioning itself as a leader in AI security while inviting the broader developer community to scrutinize and improve the code. Industry watchers see it as part of a wider push for transparency in AI safety.
- 2OPAQUE's verifiable AI open source tools near half a million downloads▼OPAQUE's Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
OPAQUE Systems says downloads of its open source software for verifiable AI are approaching 500,000, while community code contributions have grown more than tenfold. The company, which builds privacy-preserving confidential computing tools, presented the figures as a sign of momentum behind its approach to running AI workloads securely, with adoption spreading across the developer community and coverage in technology trade press.
- 3F-Droid 2.0 launches with redesigned Android app●# F -Droid 2.0 cambia volto: nuova # app # Android , # ricerca migliorata e più controllo sulla # privacy # uno # sicure
F-Droid has released version 2.0 of its free and open-source Android app store, featuring a redesigned interface, improved search functionality and stronger privacy controls. The update also emphasizes user security as an alternative to big tech app stores. Early reactions among open-source enthusiasts are positive, with users welcoming the focus on privacy and greater control over installed software.
- 4
OpenBao is an open-source tool written in Go for managing, storing, and distributing sensitive data such as passwords and API secrets, encryption keys, and digital certificates. It emerged as a community-maintained alternative to HashiCorp Vault after licensing changes. On GitHub's trending list this week it has picked up new stars and attention, with developers discussing it as a free, open option for handling secrets securely in their infrastructure.
- 5
Drop is a new open-source tool for sandboxing Linux applications without root privileges, and it supports gVisor, Google's application kernel for stronger isolation. It is currently the top post on Hacker News, where users are discussing the project and its approach to running untrusted code safely on a Linux machine. The reaction so far is mixed, with the technical community weighing its usefulness against existing sandboxing options.
- 6Four New Full Members Join Drupal Security Team●Thrilled to announce that four provisional members have earned full membership on the Drupal Security Team! Welcome: 🇫🇷
The Drupal Security Team has announced that four provisional members have earned full membership: Pierre Rudloff of France, Joseph Zhao of Australia, Bram Driesen of Belgium, and Swan Kalata of the United States. The team coordinates security fixes and advisories for the Drupal content management system, and the announcement congratulates the newcomers on completing the provisional period.
- 7Google pauses bug bounty submissions for open-source software●Google stellt Bug-Bounty-Programm für Open Source vorerst ein Google nimmt seit 1. Oktober im Bug-Bounty-Programm für Op
Google has stopped accepting vulnerability reports for open-source software through its bug bounty program as of October 1. The company will temporarily no longer pay rewards for product flaws found in open-source projects, though reports on its own flagship products continue. The move is drawing attention in the security community, as the open-source incentive program was seen as an important way to support researchers auditing widely used projects.
- 8Cloudflare releases open-source security audit tool for coding agents●cloudflare/security-audit-skill
Cloudflare has published an open-source tool called security-audit-skill, a skill for coding agents that runs multi-phase security audits of code. Its findings are independently verified and produced in a machine-readable format, so other tools and developers can consume them directly. It is written in JavaScript and available on GitHub, where it has drawn early attention from the developer community.
- 9Ubuntu drops Btrfs, XFS and ZFS boot support under Secure Boot●😣 Ubuntu drops Btrfs, XFS & ZFS boot support with Secure Boot https://www. omgubuntu.co.uk/2026/10/ubuntu -2610-secure-b
Ubuntu 26.10 no longer supports booting from Btrfs, XFS or ZFS filesystems when Secure Boot is enabled, a change tied to how GRUB handles these formats. Linux users and open source communities are debating the move, with some criticising the reduced flexibility for advanced setups and others noting Secure Boot scenarios are limited.
- 10Parrot OS 7.4 Released With Linux Kernel 7.1 and AnonSurf 6.0●Parrot OS 7.4 rolls out with Linux kernel 7.1, AnonSurf 6.0, refreshed security tools, updated Raspberry Pi images, and
The Parrot security team has released Parrot OS 7.4, a point update to its privacy-focused Linux distribution. The release ships with Linux kernel 7.1, the new AnonSurf 6.0 anonymity tool, refreshed security and penetration testing utilities, updated Raspberry Pi images, and broader package improvements. Users in the Linux and open-source community are welcoming the update for keeping the distro's privacy tooling current.
- 11testers try out open-source project LittleFedi●Got the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,
A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.
- 12Accrescent developers detail API management challenges●How does a complex application like Accrescent manage its API? In this blog post, we discuss some of the API challenges
The developers behind Accrescent, a security-focused Android app store, have published a blog post explaining how the application manages its API. The post, titled 'A Tale of Too Many Protocols', describes the API challenges the team encountered and their efforts to build a single source of truth for the project's protocols.
- 13MailAccess launches as an email OSINT framework●Show HN: MailAccess – the true Email OSINT framework
A new tool called MailAccess has been introduced on Hacker News, described by its developer as a full framework for open-source intelligence gathering based on email addresses. The launch is drawing attention from the security community, with debate likely around its usefulness for investigators and its potential for misuse in privacy attacks, phishing reconnaissance and doxxing.
- 14Flatpak 1.18.4 Patches Six Security Vulnerabilities●# Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities https:// linuxiac.com/flatpak-1-18-4-re leased-wit
A new maintenance release of Flatpak, the Linux application sandboxing and distribution framework, is out with version 1.18.4 addressing six security vulnerabilities. Linux users and system administrators are being encouraged to update their installations promptly. The release is drawing attention in the free and open-source software and cybersecurity communities, where Flatpak updates are closely watched because the tool is widely used for running sandboxed desktop applications across Linux distributions.
- 15OpenSSL 4.0.3 Released as Security Patch, Update Now●# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 16XOrg Server and Xwayland security updates patch multiple flaws●Multiple # Security Issues Patched in XOrg Server 21.1.25 and Xwayland 24.1.14, Update Now https:// 9to5linux.com/multip
New releases of XOrg Server 21.1.25 and Xwayland 24.1.14 patch multiple security vulnerabilities, and users are being urged to update their systems as soon as possible. The announcement is drawing attention in the Linux and open-source community, where these components are widely used to handle graphics display duties on Linux desktop systems.
- 17OpenSSF Announces Expanded Membership and Global Policy Resources in Europe▼OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe
The Open Source Security Foundation (OpenSSF) announced expanded membership and new global policy resources during its Community Day Europe event. The announcement, distributed by the Linux Foundation via PR Newswire, highlights the foundation's growing base of participating organizations and its effort to provide guidance on open source security policy worldwide. Further details about the new members and resources were not included in available coverage.
- 18AI Finds More Vulnerabilities, But Open Source Lacks Manpower▼AI is Finding More Vulnerabilities But Open Source Needs More People t
AI tools are increasingly effective at discovering software vulnerabilities, but security experts warn that open source projects still lack the human maintainers needed to review, triage and fix the growing volume of reported flaws. Infosecurity Magazine highlights the widening gap between machine-generated bug reports and the limited developer capacity available to address them across widely used open source components.
- 19LSU Cyber Team Wins $750K from NSA for Digital Forensics Tool▼LSU Cyber Team Releases First Open-Source Tool to Recover Fragmented Digital Evidence at Scale, Solves Two 20-year-old Grand Challenges, Wins $750K from NSA
A Louisiana State University cybersecurity team has released the first open-source tool capable of recovering fragmented digital evidence at scale, solving two longstanding 'grand challenges' in digital forensics that have remained open for roughly 20 years. The work has earned the team a $750,000 award from the National Security Agency, and the tool is now freely available for forensic investigators and researchers.
- 20Infosec newcomer introduces themselves on Mastodon▼Hello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 21NetBSD works to stabilize the Racoon2 IKE daemon●Improving and Stabilizing the Racoon2 IKE Daemon in NetBSD
The NetBSD Project has published a write-up on efforts to improve and stabilize the Racoon2 IKE daemon, the component that handles Internet Key Exchange for setting up secure IPsec connections. The post outlines ongoing work to make the long-standing daemon more reliable, and it is drawing attention from developers interested in networking security and open-source systems work.
- 22CIRCL launches major website update with new feeds●We did a major update to our website: https://www. circl.lu/ There are now RSS and Atom feeds available: https://www. ci
CIRCL, Luxembourg's national cybersecurity agency, has rolled out a major redesign of its website. The update adds RSS and Atom feeds for following its content, plus a complete overview page listing all of the organisation's open-source and open-standard projects. The announcement is drawing attention from the cybersecurity and open-source community, which closely follows CIRCL's freely available tools and resources.
- 23Open source seen as key to Europe's digital sovereignty push▼Digital sovereignty has become Europe’s top priority — here's how open source is helping pave the way
Digital sovereignty has reportedly become Europe's top policy priority, with open source software playing a central role in reducing the continent's dependence on foreign technology providers. The argument is that open, community-driven tools give European governments and businesses more control over infrastructure, data and security at a time when reliance on non-European cloud and software vendors is under scrutiny.
- 24Anthropic offers free AI security scans for open-source projects●Anthropic launches free AI security scans for open-source projects
Anthropic has launched free AI-powered security scans for open-source projects, according to The Verge. The service is expected to help volunteer developers find vulnerabilities in code they maintain without dedicated security budgets. It is the latest move by an AI company to position its tools as useful for software safety rather than only productivity, and it comes as concern grows over the state of open-source security.
- 25Google suspends part of its open source bug bounty▼Why Google is suspending part of its open source bug bounty
Google is suspending part of its bug bounty program covering open source projects. The move means security researchers will temporarily no longer be rewarded for reporting certain vulnerabilities in Google's open source software. The announcement is drawing attention from the security community, with researchers questioning the implications for vulnerability disclosure and Google's commitment to open source security.
- 26Developer launches first mobile app after taxi kidnapping ordeal●Yes, the title is correct. This is really what happened to me, and today I'm going to write about... # mobile # software
A software developer says they have launched their first mobile application after surviving a kidnapping involving a taxi, and is now writing publicly about the experience. The post has drawn attention across mobile, security and open-source communities, with readers responding to the unusual link between a personal safety incident and the decision to build and release an app.
- 27Anthropic launches program to secure critical infrastructure and open source▼Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software
Anthropic has announced a new program described as a long-term commitment to improving the security of critical infrastructure and open source software. The AI company is positioning itself as a partner in protecting systems that governments, utilities and businesses depend on. Details of funding, partners and specific measures were not included in initial reports, and reactions from the security community are still emerging.
- 28Privacy-minded users question Proton Mail's ethics▼Been hearing some sketchy things about the ethics going on at # protonmail and after I just finished my gmail transition
Users in the open-source community are voicing concerns about ethical practices at Proton Mail, the Swiss privacy-focused email provider. Some say they had just switched from Google's Gmail only to hear worrying claims, and are now asking peers what alternatives to use for email and cloud storage, with suggestions including self-hosted options like Nextcloud.
- 29
HackerNoon has published an interview with Pranshu Raghav on securing the open source AI ecosystem. The piece examines how developers and security teams can protect openly available AI models, tools and pipelines from misuse and vulnerabilities as adoption of open AI projects accelerates across the software industry.
- 30Developer Launches Self-Custodial Multi-Chain Wallet Bot for Telegram●Hey everyone, I recently built VaultForgeWalletBot — a self-custodial multi-chain crypto wallet... # crypto # telegram #
An independent developer has built VaultForgeWalletBot, a self-custodial, multi-chain crypto wallet that operates inside Telegram, and published an account of how it was made. The project is open source and is being shared with crypto and software development communities. Interest centers on the unusual approach of combining self-custody of digital assets with a messaging app, a design that raises both convenience and security questions.
- 31Sovereign Tech Fund relaunches resilience programme for open source●Wir starten das # SovereignTechResilience Programm neu mit vier weiteren Dienstleistungen für kritische # OpenSource -Pr
Germany's Sovereign Tech Fund is relaunching its Sovereign Tech Resilience programme, adding four new services for critical open source projects: memory safety, post-quantum encryption, software supply chain security, and compliance with the EU Cyber Resilience Act. The move aims to strengthen the security and long-term maintenance of digital infrastructure that many public and private systems rely on.
- 32Google pauses open source bug bounty amid flood of AI reports▼Google benches open source bug bounty program following ‘significant rise’ in AI submissions
Google has suspended its open source bug bounty program, citing a significant rise in AI-generated vulnerability submissions. The company says many of the reports flooding in are low-quality, machine-written findings that take up valuable reviewer time without adding real security value. The move has sparked debate among security researchers about the impact of automated tools on responsible disclosure programs and how bounty platforms should handle AI-created noise.
- 33AI code generation speeds ahead of open source developers▼AI can generate code faster, but can open source keep up?
Discussion is growing around whether open source software projects can keep pace with AI tools that generate code far faster than human developers. The concern centres on how volunteer-driven communities, which maintain much of the world's critical software infrastructure, will absorb or compete with automated code production while still ensuring quality, security and proper review.
- 34Google Freezes Open Source Bug Bounty Until 2027 Amid AI Spam Flood▼Google Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Flood
Google has paused its open source bug bounty programme until 2027, citing an overwhelming flood of AI-generated spam reports. Invalid, low-quality vulnerability submissions allegedly produced by AI tools have crowded out legitimate security research, making the programme unsustainable in its current form. The move has sparked debate in the security community about how AI is affecting vulnerability disclosure processes and whether other bounty programmes will follow suit.
- 35CyclePatrol Open-Source Wi-Fi Security Tool Debuts●Introduction: The Rise of CyclePatrol As Wi-Fi networks proliferate in public spaces, the development of CyclePatrol exe
CyclePatrol, a new open-source Bash tool built for Kali Linux, has been introduced to the cybersecurity community as public Wi-Fi networks continue to spread. Its developers frame it as an example of the sector's dual duty to innovate while maintaining ethical standards. Reaction so far centres on whether the tool will help security professionals audit public networks responsibly or invite misuse, a familiar debate whenever offensive-sounding utilities are released openly.
- 36Google Winds Down Part of Its Open Source Bounty Program▼Google Has Shut Down Part of its Open Source Bounty Program
Google has shut down part of its open source bounty program, which paid researchers and developers for improving open source projects. The move affects a program that had rewarded security fixes and contributions to community-driven software. It is the latest in a series of cost-cutting measures at the company, and open source advocates have criticised the decision as a step back from Google's support for the community.
- 37Nous Research raises $90M at $1.5B valuation▼Nous Research raises $90M at $1.5B valuation for open-source AI
Nous Research has raised $90 million in funding at a $1.5 billion valuation to advance its open-source AI work. The deal marks a significant milestone for the startup, which builds open models as an alternative to closed systems from major AI labs. The funding signals continued strong investor appetite for open-source artificial intelligence companies.
- 38AI Finds More Software Vulnerabilities, But Open Source Fixers Are Scarce▼AI is Finding More Vulnerabilities But Open Source Needs More People to Fix Them
AI tools are increasingly effective at discovering software vulnerabilities, including many in open source projects. However, the pool of human developers able to review, verify and patch these flaws is not keeping pace, leaving security gaps open longer. The report argues that discovery is outstripping remediation capacity, and calls for more investment in open source maintenance and the people who sustain it.
- 39F-Droid Ecosystem Under Pressure as Android Verification Tightens●The Evolution of the F-Droid Ecosystem On September 24, 2026, the open source community... # android # opensource # secu
The open source community is discussing the future of F-Droid, the alternative app repository for Android. Commentary on September 24, 2026 contrasts a modernized 'F-Droid 2.0' vision with Google's app verification requirements, which many see as a barrier for sideloaded and independent software. The debate centers on whether open source Android distribution can survive tighter platform security rules.
- 40
A new model focused on cyber open-source intelligence has been released, according to a security researcher announcing it online. The release is being shared among cybersecurity and OSINT practitioners, who are taking note of what a purpose-built model for intelligence gathering could offer. Details on the model's capabilities, creators and intended use were not immediately available.
Repos
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f