MikeTrendsTrends right now

search

software security

Trends

  1. 1
    NVIDIA open-sources its agent safety platformβ–ΌNVIDIA open-sources agent safety platformβœ‰newsTechnologySoftware6 d ago

    NVIDIA has released the code of its agent safety platform as open source, making its tooling for keeping AI agents secure and controlled available to developers. Technology publications including Open Source For You and Adafruit's blog report the move, which lets companies inspect and adapt the safety software rather than rely on a proprietary product.

  2. 2
    IBM and Red Hat Patch Over 400 Hidden Open Source Vulnerabilities●IBM and Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilitiesβœ‰newsTechnologySoftware37 min ago

    IBM and Red Hat have announced the remediation of more than 400 previously unknown open source software vulnerabilities. The companies disclosed the security fixes through their official news channels, highlighting ongoing efforts to strengthen the security of widely used open source components. The announcement is being circulated across technology and cybersecurity news outlets.

  3. 3
    Is sandboxing sufficient to contain rogue AI agents?●Is sandboxing sufficient to contain rogue agents?YhnBusinessCrypto5346 min ago

    A new essay on the Cryptography Engineering blog asks whether sandboxing is enough to contain rogue AI agents. The author examines whether conventional isolation techniques, long relied on in security engineering, can hold up against autonomous software agents with growing capabilities. The piece has drawn attention among security and cryptography practitioners, who are debating the limits of containment as AI agents gain the ability to act independently online.

  4. 4
    Google pauses bug bounty submissions for open-source software●Google stellt Bug-Bounty-Programm fΓΌr Open Source vorerst ein Google nimmt seit 1. Oktober im Bug-Bounty-Programm fΓΌr OpMmastodonTechnologySoftware1217 h ago

    Google has stopped accepting vulnerability reports for open-source software through its bug bounty program as of October 1. The company will temporarily no longer pay rewards for product flaws found in open-source projects, though reports on its own flagship products continue. The move is drawing attention in the security community, as the open-source incentive program was seen as an important way to support researchers auditing widely used projects.

  5. 5
    Brazil's Electronic Voting Machines Run on Linux●Brazil’s electronic voting machines run Linux. Here's how the system works and how secure it is. Full details here: httpMmastodonWorldElections111 h ago

    Brazil's electronic voting machines are built on the Linux operating system, drawing renewed attention to how the country's electoral system works and how secure it is. Commenters in the open-source community are highlighting the machines as a notable example of public-sector use of free software, with discussion focusing on the transparency and reliability of the voting technology.

  6. 6
    Blogger migrates off WordPress using Claude after repeated hacks●I was running a wordpress blog for so long now, but with Hickups then and there by Hackers or by some... # wordpress # aMmastodonTechnologyAI313 h ago

    A long-time WordPress blogger says recurring security hiccups from hackers pushed them to move their site away from the platform, using the AI assistant Claude to help with the migration. The post also touches on automation, software development and community themes, and has drawn modest attention.

  7. 7

    AVM has announced a major software update for its FRITZ!Box routers, introducing FRITZ!OS 8.50. The German networking company says the new firmware makes its routers smarter, more secure and faster. Users in Germany are discussing what the update includes and when their devices will receive it.

  8. 8

    AVM has released FRITZ!OS 8.50, a major software update for its FRITZ!Box routers, promising smarter, more secure and faster performance. German tech media are covering the rollout, alongside news that 1&1 launched its HomeServer Pro, a new Wi-Fi 7 router for DSL and fibre connections, keeping home networking gear in the German spotlight.

  9. 9
    Greg Kroah-Hartman on security in the age of LLMs●Greg Kroah-Hartman – Security in the LLM Age [video]YhnTechnologyAI34040 min ago

    Linux kernel maintainer Greg Kroah-Hartman is featured in a talk about security in the LLM age, examining how large language models affect the security of the software supply chain and open-source development. The discussion touches on risks that AI-generated code poses to kernel-quality standards and how maintainers can respond to an influx of machine-produced patches.

  10. 10
    Windows 10 end-of-support fuels Linux migration talk●# meme # tux # software # endof10 # windows # microsoft # linux # foss # opensource # install # security # cybersecurityMmastodonTechnologySoftware71 d ago

    With Microsoft ending support for Windows 10, open-source advocates are circulating memes urging users to switch to Linux instead of upgrading to Windows 11. The posts highlight Windows 11's TPM and hardware requirements, which leave older PCs unsupported, and frame Linux and free software as a more secure, freedom-respecting option for ageing laptops and desktops.

  11. 11
    GNOME developer challenges the software industry on quality●The era of software quality, or the era of ostriches?YhnScienceBiology6429 min ago

    GNOME developer Michael Catanzaro has published a blog post asking whether the software industry is truly entering an era of better software quality, or whether developers are burying their heads in the sand like ostriches. The piece criticizes current attitudes toward bugs, testing and security practices, and is drawing discussion among developers about declining standards in modern software.

  12. 12
    WordPress.org's forced takeover of ACF plugin sparks debate●Analisis pengambilalihan paksa plugin ACF oleh WordPress.org menjadi Secure Custom Fields. Dampak etika open source danMmastodonTechnologySoftware52 d ago

    WordPress.org took over the popular Advanced Custom Fields plugin and renamed it Secure Custom Fields, prompting analysis of the ethics of the move. Commenters are weighing the impact on open-source principles, trust between maintainers and repositories, and software supply-chain security for developers who rely on plugins distributed through WordPress.org.

  13. 13
    Password Manager Switch Sparks Tech Community Interestβ–ΌMein Umzug auf einen neuen Passwort-Managerβ–ΆyoutubeTechnologySoftware108.8K37 min ago

    A German technology publication is drawing large audiences with a guide detailing a move to a new password manager. The piece walks readers through switching services, covering data export, import and the security considerations involved in migrating stored credentials. It has quickly become one of the most engaged-with software topics, suggesting many users are rethinking which password manager they trust.

  14. 14

    The OpenSSH project has released version 10.6, updating its widely used secure shell software for encrypted remote access. The release notes are published on the official OpenSSH site. Developers and system administrators are discussing the update, as OpenSSH runs on most servers and new releases typically bring security hardening and bug fixes that teams need to apply quickly.

  15. 15
    Docker and CNCF partner on open agent permissions spec●Docker and CNCF partner on an open spec for agent permissionsYhnScienceBiology76 d ago

    Docker has announced a partnership with the Cloud Native Computing Foundation to develop an open specification for agent permissions, aimed at defining how AI agents are granted and restricted access when running software. The announcement was published on Docker's blog as part of its Sandbox Kit initiative. Developer communities are discussing what a standardised permission model for autonomous agents could mean for security and interoperability in cloud-native tooling.

  16. 16

    A new blog post argues that random number generation is often not as random as it needs to be, highlighting how weaknesses in randomness can undermine security and correctness in software. The piece has drawn attention among developers, with readers debating how systems should generate unpredictable values and where common approaches fall short.

  17. 17
    Unable to Land a Tech Job, Developer Launches a Startup Insteadβ–ΌI’m Starting a Startup Because I Can’t Find a Tech Jobβ–ΆyoutubeBusinessStartups42.2K47 min ago

    A software developer is launching their own startup after failing to secure a tech job, sharing the decision publicly. The story has struck a chord amid the ongoing tech hiring slump, with many workers struggling through layoffs, frozen postings, and fierce competition for junior and mid-level roles. Reactions are a mix of sympathy and debate over whether entrepreneurship is a viable answer when the job market shuts its doors.

  18. 18
    Red Hat layoffs reported to extend beyond this week●Mass Layoffs at Red Hat Not Limited to This Week or to Oct FirstYhnEnvironmentClimate842 min ago

    Reports claim mass layoffs at Red Hat are not confined to this week or to an October 1 date, suggesting job cuts have been ongoing and may continue. The claim is drawing attention among technology workers concerned about job security at the IBM-owned Linux company, though details on the scale and departments affected remain scarce.

  19. 19
    OpenSSF Announces Expanded Membership and Global Policy Resources in Europeβ–ΌOpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europeβœ‰newsTechnologySoftware37 min ago

    The Open Source Security Foundation (OpenSSF) used its Community Day Europe event to announce expanded membership and the launch of new global policy resources aimed at strengthening open source software security. The announcements were distributed via the Linux Foundation and PR Newswire. The moves underline growing industry collaboration on securing open source supply chains, though detailed membership names and the content of the policy resources were not specified in available coverage.

  20. 20

    Debate is underway over who actually controls and profits from open source software, as major companies increasingly fund, contribute to and commercialize community-built projects. Commenters are weighing whether corporate backing undermines the open source model or secures its future, and whether maintainers get a fair share of the value they create.

  21. 21
    Reports of Tens of Thousands of OpenAI Agent Incidents Involving US Governmentβ–ΌUS Government SWARMED BY OpenAI Agents As 'Tens Of Thousands' Incidents Revealedβ–ΆyoutubeWorldPolitics625.5K1 d ago

    OpenAI's autonomous software agents have been linked to tens of thousands of reported incidents connected to the US government, according to commentary circulating online. The discussion raises questions about how federal agencies are using AI tools and what oversight exists. Critics and commentators are debating the security and accountability implications of deploying AI agents in sensitive government contexts.

  22. 22
    Office 2021 support ends this month with five options for users●Office 2021 support ends this month – you have 5 options Microsoft is ending support and updates for Office 2021 on OctoMmastodonBusinessStartups33 h ago

    Microsoft will end support and security updates for Office 2021 on October 13, leaving users of the one-time-purchase suite without patches going forward. Coverage lays out five options for affected users, including migrating to Microsoft 365, moving to Office 2024, paying for Extended Security Updates, or switching to free alternatives like LibreOffice or web-based apps.

  23. 23
    Deleting files securely is harder than it looks●Deleting a file sounds like one of the simplest actions an app can offer. Tap delete. Remove the file. Done. While buildMmastodonTechnologySoftware41 d ago

    A developer building Xsilent, an app meant to protect private photos, videos, PDFs and other files, has written about how deleting data securely is far more complicated than it sounds. The post notes that a simple delete action becomes much less simple when an app is supposed to protect sensitive private material, prompting discussion about how apps handle file removal.

  24. 24
    Greg Kroah-Hartman on security in the LLM age●Greg Kroah-Hartman – Security in the LLM Age [video] Article URL: https://www. youtube.com/watch?v=NnV_cWeoo5Q CommentsMmastodonTechnologyCybersecurity33 d ago

    Kernel developer Greg Kroah-Hartman, the maintainer of the Linux kernel stable branches, has given a talk on what large language models mean for software security. The presentation examines how AI-generated code affects vulnerability handling and maintenance work in large open source projects. The talk is circulating among developers and technology commentators, with early responses still limited but interest growing in how core infrastructure maintainers view LLM-driven risks.

  25. 25
    Post-Quantum Encryption Debate Hits Go Repositoriesβ–ΌNo Go repository decides whether its production traffic is protected by a post-quantum key exchange.... # python # finteMmastodonBusinessCrypto243 min ago

    Developers are debating whether Go repositories should decide on their own whether production traffic uses post-quantum key exchange. The argument centres on which layer of the software stack should be responsible for the choice, with some suggesting a classical handshake is only a problem if traffic was recorded for later decryption. The discussion touches on fintech and security architecture more broadly.

  26. 26
    PlayStation 2 security chip fully reverse engineered●The original PlayStation 2 security chip has been reverse engineered https://www.engadget.com/2273354/playstation-2-secuMmastodonCultureGaming33 d ago

    Engineers have reverse engineered the original PlayStation 2's security chip, uncovering how Sony's early-2000s copy protection worked at a hardware level. The breakthrough could make it easier to preserve PS2 games, improve emulation, and run homebrew software on original consoles. Retro gaming and preservation communities are celebrating the finding, two decades after the console's launch.

  27. 27
    CodeSupply Launches R&D Grants for Open-Source Software Securityβ–ΌCodeSupply Announces R and D Grants for Open-Source Software Securityβœ‰newsTechnologySoftware6 d ago

    CodeSupply has announced a new research and development grant programme focused on open-source software security. The initiative will fund projects aimed at improving the safety and resilience of open-source code, an area of growing concern following high-profile supply chain vulnerabilities. Details on grant sizes, eligibility and deadlines have not yet been widely reported.

  28. 28
    Frontline Education Data Breach Puts Spotlight on Third-Party Risksβ–ΌFrontline Education Data Breach Highlights Third-Party Risksβœ‰newsTechnologyCybersecurity39 min ago

    Frontline Education, a US provider of software for school districts, has suffered a data breach, and early reporting frames it as a warning about third-party vendor risk. The incident raises questions about how much sensitive staff and district data schools hand to outside providers, and how well those vendors secure it. Education-sector breaches have been climbing, making this another case for administrators reviewing supplier security.

  29. 29
    IBM and Red Hat Patch Over 400 Unknown Open Source Flaws●IBM and Red Hat Fix More Than 400 Previously Unknown Open Source Vulnerabilitiesβœ‰newsTechnologySoftware37 min ago

    IBM and Red Hat have fixed more than 400 previously unknown vulnerabilities in open source software. The disclosure highlights ongoing efforts to secure widely used open source components that underpin enterprise systems worldwide. Security teams at organizations relying on Red Hat platforms are expected to review and apply the patches to protect their infrastructure.

  30. 30
    Traveler says SSD vanished after TSA laptop inspection●Traveling Developer's SSD Vanishes After TSA Inspects Laptop𝕏xSE2951 d ago

    A software developer who travels frequently says a solid-state drive disappeared from his laptop bag after Transportation Security Administration officers inspected his laptop at a US airport. He recounted the incident publicly and says he filed a complaint with the TSA. Other travelers have responded with their own claims of missing items after security checks and advice on keeping valuables in view during screenings.

  31. 31
    Google rolls out Android developer verification●The Internet Last Week * Android developer verification deployment https:// developer.android.com/develope r-verificatioMmastodonTechnologyMobile41 d ago

    Google has begun deploying its Android developer verification requirement, a new security measure requiring app developers to verify their identities before distributing software. The change, announced via the Android developer portal and Google's developer blog, is intended to elevate Android security and reduce malicious apps. The news is circulating alongside reports of Apple issuing emergency security patches, making mobile platform security a hot topic this week.

  32. 32
    Study probes whether AI models judge code morally●Ask a model if code is malicious and it reaches for its morals https://www.manifold.security/blog/do-models-consider-morMmastodonTechnology47 h ago

    Security firm Manifold Security published research asking whether AI models factor morality into their judgments about malicious code. The finding: when asked to assess whether code is malware, language models appear to bring moral reasoning into their analysis rather than relying purely on technical criteria. The report is circulating among developers and security researchers interested in how AI tools evaluate potentially harmful software.

  33. 33
    IBM and Red Hat Fix Over 400 Java Vulnerabilitiesβ–ΌLightwell: How IBM & Red Hat Fixed 400+ Java Vulnerabilitiesβœ‰newsTechnologySoftware1 h ago

    IBM and Red Hat, working with Lightwell, have patched more than 400 Java vulnerabilities, according to Cyber Magazine. The scale of the remediation effort is drawing attention across the software and security community, as enterprises running Java-based systems assess what the fixes mean for their own environments and patching priorities.

  34. 34
    Google suspends part of its open source bug bountyβ–ΌWhy Google is suspending part of its open source bug bountyβœ‰newsTechnologySoftware37 min ago

    Google is suspending part of its bug bounty programme covering open source projects. The company, which pays researchers for reporting security vulnerabilities, is halting rewards for a segment of the initiative. The move is drawing attention from security researchers and developers, who are questioning what prompted the decision and what it means for independent vulnerability reporting in widely used open source software.

  35. 35
    testers try out open-source project LittleFedi●Got the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,MmastodonTechnologySoftware43 d ago

    A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.

  36. 36
    York Space Systems Hit with Fraud Suit After 10% Stock Dropβ–ΌYSS Stock Notice: York Space Stock Plummeted 10% after Satellite Software Issues Disclosed - Securities Fraud Class Action Filedβœ‰newsScienceSpace Policy28 min ago

    York Space Systems shares fell about 10% after the company disclosed problems with its satellite software. A securities fraud class action has now been filed on behalf of investors, alleging they were misled about the issues. The case adds to pressure on the satellite maker as investors watch for further disclosures about the software flaws and their financial impact.

  37. 37
    Hackers Use Chinese AI Tool to Hit South Korean Banksβ–ΌHackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk https://www.wsj.com/world/asia/hackers-use-chinMmastodonTechnologyAI218 h ago

    Hackers have attacked South Korean banks using a Chinese AI tool, according to a Wall Street Journal report, highlighting how easily accessible artificial intelligence software is being repurposed for cybercrime. The case raises concerns that state-of-the-art AI tools developed in China are creating new security risks for financial institutions abroad.

  38. 38

    Developers are embracing 'vibe coding', a practice of building software quickly by describing what they want in plain language and letting AI tools generate the code. Supporters say it dramatically speeds up prototyping and lowers the barrier for non-programmers. Critics warn it can produce untested, poorly understood code and may create maintenance and security problems as projects grow.

  39. 39
    Google Ads Flags Open-Source macOS Terminal as Malwareβ–ΌFlagged by the Machine: How Google Ads Suspended an Open-Source macOS Term as Maliciousβœ‰newsTechnologySoftware10 h ago

    Google Ads suspended an advertisement associated with iTerm, a widely used open-source terminal emulator for macOS, after automated systems classified the software as malicious. The case highlights how automated moderation on advertising platforms can penalise legitimate open-source tools, with developers and security observers questioning the accuracy of machine-driven decisions and the difficulty of appealing such takedowns.

  40. 40

    Software developers are debating the limits of "vibe coding," the practice of building software by prompting AI models rather than writing code directly. While the approach works well for prototypes and small projects, many argue it breaks down on complex systems where architecture, security and long-term maintainability demand deliberate engineering decisions. The discussion reflects a broader reassessment of how far AI-assisted development can go.

Repos