search
software security
Trends
- 1
A new roundup from ZDNET highlights seven open-source applications that the outlet argues deserve paid support in 2026. The piece makes the case that while the software is free to download, paying developers sustains updates, security fixes and long-term maintenance. It reflects a broader push to move beyond treating open-source tools as automatically free labor.
- 2
A new essay on the Cryptography Engineering blog asks whether sandboxing is sufficient to contain rogue AI agents. The author examines whether conventional isolation techniques, long used to contain malicious or buggy software, can reliably restrain autonomous systems that pursue goals and act with limited oversight. The piece is drawing attention among security engineers and AI safety readers debating how far technical containment measures can go.
- 3Xray-core hid certificate verification bypass vulnerability●Xray-core concealed a certificate verification bypass vulnerability
Xray-core, the widely used proxy tool, is under criticism for concealing a certificate verification bypass vulnerability rather than disclosing it publicly. The issue is being discussed on the net4people mailing list, where security researchers argue that a TLS verification flaw in censorship-circumvention software puts users at direct risk of detection and should have been disclosed promptly.
- 4Greg Kroah-Hartman on security in the age of LLMs●Greg Kroah-Hartman – Security in the LLM Age [video]
Greg Kroah-Hartman, the longtime Linux kernel maintainer who oversees stable releases, has given a talk examining how large language models affect software security. He discusses what the rise of AI-generated code means for vulnerabilities, code review practices, and maintaining trust in widely used open-source components. The talk is drawing attention among developers weighing the risks of AI-written code in critical infrastructure.
- 5Google rolls out October update for Pixel devices●Oktober-Update für Pixel-Geräte: Google patcht Bugs und Sicherheitslücken Das Oktober-Update für Googles Pixel-Geräte is
Google has released its October software update for Pixel smartphones. The update includes relevant security patches alongside a number of bug fixes for the devices. It is part of Google's regular monthly maintenance cycle for its in-house Android handsets, and Pixel owners are advised to install it to stay protected.
- 6IBM and Red Hat Fix Over 400 Unknown Open Source Vulnerabilities●IBM and Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities
IBM and Red Hat have remediated more than 400 previously unknown vulnerabilities in open source software. The companies disclosed the security fixes as part of their ongoing work to harden widely used open source components. The announcement is being picked up across technology and cybersecurity outlets, highlighting the scale of hidden flaws in open source code and the role large vendors play in patching them.
- 7
Apple has announced updates to how Full Disk Access works in macOS, per a notice on its developer site. The change affects how apps request and receive permission to read protected user data such as Mail, Messages and Safari files. Developers and security watchers are weighing what the tightening means for backup tools, antivirus software and utilities that rely on broad disk access.
- 8
A new blog post argues that random number generation is often not as random as it needs to be, highlighting how weaknesses in randomness can undermine security and correctness in software. The piece has drawn attention among developers, with readers debating how systems should generate unpredictable values and where common approaches fall short.
- 9
A German technology publication is drawing large audiences with a guide detailing a move to a new password manager. The piece walks readers through switching services, covering data export, import and the security considerations involved in migrating stored credentials. It has quickly become one of the most engaged-with software topics, suggesting many users are rethinking which password manager they trust.
- 10IBM and Red Hat patch over 400 open source vulnerabilities●IBM and Red Hat fix 400+ open source vulnerabilities ...
IBM and Red Hat have released fixes for more than 400 vulnerabilities across open source components in Red Hat's enterprise software products. The large-scale security update addresses flaws discovered in widely used open source libraries and tools. Administrators running Red Hat Enterprise Linux and related offerings are being urged to apply the patches promptly to reduce exposure to potential exploits.
- 11Major Banks Back OSERA Open Source Security Initiative▼Major Banks Back OSERA to Deliver Industry Wide Remediation Standards and Fixes to Secure Open Source Software
A group of major banks is backing OSERA, a new effort to establish industry-wide standards and fixes for securing open source software. The initiative aims to coordinate remediation practices across the financial sector, where reliance on open source components carries significant security risk. Financial institutions have increasingly pushed for collective approaches to software supply chain vulnerabilities.
- 12IBM and Red Hat patch over 400 unknown open source flaws▼IBM and Red Hat Fix More Than 400 Previously Unknown Open Source Vulnerabilities
IBM and Red Hat have fixed more than 400 previously unknown open source vulnerabilities, according to a report by SD Times. The disclosure highlights ongoing efforts by the companies to harden widely used open source software before flaws can be exploited. Patching this many undisclosed vulnerabilities at once underscores the scale of security maintenance behind enterprise Linux and open source platforms.
- 13OpenSSH 10.6 released●openssh-10.6 released https://www. undeadly.org/cgi?action=articl e;sid=20261007052827 # openbsd # openssh # ssh # secur
The OpenBSD project has released OpenSSH 10.6, the latest version of the widely used secure shell tool for encrypted remote login and file transfer. Announcement of the release spread quickly among system administrators, developers and security professionals, who track each OpenSSH update closely given how central the software is to internet infrastructure.
- 14LibreSSL 4.2.2 and 4.3.3 released●LibreSSL 4.2.2 and 4.3.3 released https://www. undeadly.org/cgi?action=articl e;sid=20261007052424 # openbsd # libressl
The OpenBSD project has released new LibreSSL versions 4.2.2 and 4.3.3, the open-source TLS library derived from OpenSSL. The announcement was shared on Undeadly, the OpenBSD community news site, and picked up by developers tracking cryptography and security software. Users of the portable edition are advised to update to receive the latest fixes.
- 15
Europe is being criticized for failing to establish effective governance of open source software. Techzine Global reports that the continent lags behind in coordinating how open source projects are funded, maintained and secured, leaving widely used components vulnerable to neglect and supply chain risk.
- 16New tool triages which cryptography quantum computers would break first●PQC Triage — paste a dependency manifest, see which cryptography a quantum computer breaks first,... # cryptography # qu
A developer tool called PQC Triage lets users paste a software dependency manifest and see which cryptographic algorithms in their stack would fall first to a quantum computer. It is aimed at helping teams prioritise migration to post-quantum cryptography. Discussion is circulating in open-source and security communities as organisations assess quantum-era risks.
- 17IBM and Red Hat patch 400 unknown open-source flaws●IBM and Red Hat fix 400 previously unknown open-source vulnerabilities
IBM and Red Hat have fixed roughly 400 previously unknown vulnerabilities in open-source software. The patch effort covers flaws that had not been publicly disclosed before, reducing the risk of exploitation in widely used open-source components. The companies' security teams identified and addressed the issues as part of ongoing upstream maintenance work.
- 18Firefox executive outlines enterprise security and AI strategy●Firefox's Ajit Varma on enterprise security, AI model choice and what open source makes possible
Ajit Varma, a senior figure at Mozilla's Firefox, has given an interview discussing how the browser approaches enterprise security, why organisations should be able to choose their own AI models, and the advantages open source software offers for building trustworthy products. The conversation centres on balancing privacy, flexibility and innovation for business users of the browser.
- 19Linux Foundation Launches OpenChain Automotive SBOM Framework 1.0▼Linux Foundation Releases OpenChain Automotive SBOM Framework 1.0 for Greater Reliability and Traceability in Automotive Software
The Linux Foundation has released OpenChain Automotive SBOM Framework 1.0, a standardized framework for software bills of materials aimed at improving reliability and traceability in automotive software. The release gives carmakers and suppliers a common way to document the components in vehicle software, supporting compliance and supply chain transparency as software becomes central to modern vehicles.
- 20Brazil's electronic voting machines run on Linux●Brazil’s electronic voting machines run Linux. Here's how the system works and how secure it is. Full details here: http
Brazil's electronic voting machines run on Linux, and attention is turning to how the system works and how secure it is. The open-source basis of the machines is being highlighted as a transparency point ahead of discussion around election integrity, with explanations circulating about the software architecture and safeguards built into the voting process.
- 21York Space Systems Hit with Fraud Suit After 10% Stock Drop▼YSS Stock Notice: York Space Stock Plummeted 10% after Satellite Software Issues Disclosed - Securities Fraud Class Action Filed
York Space Systems shares fell about 10% after the company disclosed problems with its satellite software. A securities fraud class action has now been filed on behalf of investors, alleging they were misled about the issues. The case adds to pressure on the satellite maker as investors watch for further disclosures about the software flaws and their financial impact.
- 22Frontline Education Data Breach Exposes Third-Party Vendor Risks▼Frontline Education Data Breach Highlights Third-Party Risks
Frontline Education, a US software provider serving school districts, has suffered a data breach, with coverage focusing on the risks organisations face from third-party vendors. The incident has renewed debate about how schools and other institutions vet suppliers and secure data shared with external partners, as attackers increasingly target supply chains rather than end users directly.
- 23Google suspends part of its open source bug bounty▼Why Google is suspending part of its open source bug bounty
Google is suspending part of its bug bounty program covering open source projects. The move means security researchers will temporarily no longer be rewarded for reporting certain vulnerabilities in Google's open source software. The announcement is drawing attention from the security community, with researchers questioning the implications for vulnerability disclosure and Google's commitment to open source security.
- 24
The OpenSSH project has released version 10.6, updating its widely used secure shell software for encrypted remote access. The release notes are published on the official OpenSSH site. Developers and system administrators are discussing the update, as OpenSSH runs on most servers and new releases typically bring security hardening and bug fixes that teams need to apply quickly.
- 25IBM and Red Hat Fix Over 400 Java Vulnerabilities●Lightwell: How IBM & Red Hat Fixed 400+ Java Vulnerabilities
IBM and Red Hat, working with Lightwell, have patched more than 400 Java vulnerabilities, according to Cyber Magazine. The scale of the remediation effort is drawing attention across the software and security community, as enterprises running Java-based systems assess what the fixes mean for their own environments and patching priorities.
Repos
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man
- modelcontextprotocol/servers Model Context Protocol Servers
- net4people/bbs Forum for discussing Internet censorship circumvention