MikeTrendsTrends right now

search

open source security community

Trends

  1. 1
    Nvidia Open-Sources AI Safety Software to Catch Vulnerabilities●Nvidia AI Safety Software Is Open Source to Catch Vulnerabilities -- Market Talkβœ‰newsTechnologySoftware6 d ago

    Nvidia has released its AI safety software as open source, a move aimed at helping developers detect and address vulnerabilities in artificial intelligence systems. By making the tooling publicly available, the company is positioning itself as a leader in AI security while inviting the broader developer community to scrutinize and improve the code. Industry watchers see it as part of a wider push for transparency in AI safety.

  2. 2
    OPAQUE's verifiable AI open source tools near half a million downloadsβ–ΌOPAQUE's Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfoldβœ‰newsTechnologySoftware6 d ago

    OPAQUE Systems says downloads of its open source software for verifiable AI are approaching 500,000, while community code contributions have grown more than tenfold. The company, which builds privacy-preserving confidential computing tools, presented the figures as a sign of momentum behind its approach to running AI workloads securely, with adoption spreading across the developer community and coverage in technology trade press.

  3. 3
    Parrot OS 7.4 Released With Linux Kernel 7.1 and AnonSurf 6.0●Parrot OS 7.4 rolls out with Linux kernel 7.1, AnonSurf 6.0, refreshed security tools, updated Raspberry Pi images, andMmastodonTechnologySoftware42 d ago

    The Parrot security team has released Parrot OS 7.4, a point update to its privacy-focused Linux distribution. The release ships with Linux kernel 7.1, the new AnonSurf 6.0 anonymity tool, refreshed security and penetration testing utilities, updated Raspberry Pi images, and broader package improvements. Users in the Linux and open-source community are welcoming the update for keeping the distro's privacy tooling current.

  4. 4
    Red Hat Layoffs Said to Extend Beyond Recent Cuts●Mass Layoffs at Red Hat Not Limited to This Week or to Oct FirstYhnEnvironmentClimate86 min ago

    Reports say mass layoffs at Red Hat are not confined to a single week or to cuts announced around October 1, suggesting job losses have been ongoing over a longer period. The claim is fueling concern among employees and open-source community members about the company's direction and the security of remaining staff.

  5. 5
    testers try out open-source project LittleFedi●Got the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,MmastodonTechnologySoftware42 d ago

    A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.

  6. 6
    Securing the Open Source AI Ecosystem: A Conversation with Pranshu Raghavβ–ΌSecuring the Open Source AI Ecosystem with Pranshu Raghavβœ‰newsTechnologySoftware1 min ago

    HackerNoon has published an interview with Pranshu Raghav on security in the open source AI ecosystem. The piece examines how vulnerabilities in open models, datasets and tooling can be addressed as artificial intelligence adoption accelerates. It highlights the growing need for security practices, governance and community coordination around freely available AI software and models.

  7. 7

    Google has paused its open source bug bounty program, citing a surge of AI-generated vulnerability reports. The company says the flood of low-quality automated submissions is making it difficult to identify genuine security flaws worth rewarding. The move has drawn attention across the security community, which has been grappling with a wave of automated, often inaccurate bug reports produced with AI tools.

  8. 8

    Drop is a new open-source tool for sandboxing Linux applications without root privileges, and it supports gVisor, Google's application kernel for stronger isolation. It is currently the top post on Hacker News, where users are discussing the project and its approach to running untrusted code safely on a Linux machine. The reaction so far is mixed, with the technical community weighing its usefulness against existing sandboxing options.

  9. 9
    Google Freezes Open Source Bug Bounty Until 2027 Amid AI Spam Floodβ–ΌGoogle Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Floodβœ‰newsTechnologySoftware2 h ago

    Google has paused its open source bug bounty programme until 2027, citing an overwhelming flood of AI-generated spam reports. Invalid, low-quality vulnerability submissions allegedly produced by AI tools have crowded out legitimate security research, making the programme unsustainable in its current form. The move has sparked debate in the security community about how AI is affecting vulnerability disclosure processes and whether other bounty programmes will follow suit.

  10. 10
    CIRCL launches major website update with new feeds●We did a major update to our website: https://www. circl.lu/ There are now RSS and Atom feeds available: https://www. ciMmastodonTechnologySoftware71 d ago

    CIRCL, Luxembourg's national cybersecurity agency, has rolled out a major redesign of its website. The update adds RSS and Atom feeds for following its content, plus a complete overview page listing all of the organisation's open-source and open-standard projects. The announcement is drawing attention from the cybersecurity and open-source community, which closely follows CIRCL's freely available tools and resources.

  11. 11
    OpenSSH Creator's Security Philosophy Draws Renewed Attention●OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One https://zbruceli.org/blog/the-man-who-trMmastodonTechnologySoftware36 h ago

    A profile of the OpenSSH project and its creator is drawing attention across the tech community. OpenSSH underpins secure remote access on virtually every Mac, Linux server and Windows machine, yet is maintained with a deliberately paranoid approach: its code is written to trust no input, no system and no contributor. The piece highlights how this rigour has kept the critical open-source tool safe for decades, prompting discussion about whether other widely used software should adopt similar discipline.

  12. 12
    RetireTui brings retirement planning to the terminal●When am I retiring? One sec, let me check my terminal... πŸ“ˆ RetireTui β€” See your financial future from the terminal πŸ₯Ά A lMmastodonBusinessFinance416 h ago

    A developer has released RetireTui, a local-first retirement planning tool that runs in the terminal. Written in Rust, it offers year-by-year financial projections, tax calculations, historical market data and Social Security optimization, with all data kept on the user's own machine. The project is drawing attention in open-source and developer communities for its unusual terminal-based take on personal finance software.

  13. 13
    Developer Launches Self-Custodial Multi-Chain Wallet Bot for Telegram●Hey everyone, I recently built VaultForgeWalletBot β€” a self-custodial multi-chain crypto wallet... # crypto # telegram #MmastodonBusinessCrypto22 d ago

    An independent developer has built VaultForgeWalletBot, a self-custodial, multi-chain crypto wallet that operates inside Telegram, and published an account of how it was made. The project is open source and is being shared with crypto and software development communities. Interest centers on the unusual approach of combining self-custody of digital assets with a messaging app, a design that raises both convenience and security questions.

  14. 14
    AI Finds More Vulnerabilities, But Open Source Lacks Manpowerβ–ΌAI is Finding More Vulnerabilities But Open Source Needs More People tβœ‰newsTechnologySoftware3 d ago

    AI tools are increasingly effective at discovering software vulnerabilities, but security experts warn that open source projects still lack the human maintainers needed to review, triage and fix the growing volume of reported flaws. Infosecurity Magazine highlights the widening gap between machine-generated bug reports and the limited developer capacity available to address them across widely used open source components.

  15. 15
    Accrescent developers detail API management challenges●How does a complex application like Accrescent manage its API? In this blog post, we discuss some of the API challengesMmastodonTechnologyMobile146 d ago

    The developers behind Accrescent, a security-focused Android app store, have published a blog post explaining how the application manages its API. The post, titled 'A Tale of Too Many Protocols', describes the API challenges the team encountered and their efforts to build a single source of truth for the project's protocols.

  16. 16
    Flatpak 1.18.4 Patches Six Security Vulnerabilities●# Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities https:// linuxiac.com/flatpak-1-18-4-re leased-witMmastodonTechnologyCybersecurity35 d ago

    A new maintenance release of Flatpak, the Linux application sandboxing and distribution framework, is out with version 1.18.4 addressing six security vulnerabilities. Linux users and system administrators are being encouraged to update their installations promptly. The release is drawing attention in the free and open-source software and cybersecurity communities, where Flatpak updates are closely watched because the tool is widely used for running sandboxed desktop applications across Linux distributions.

  17. 17
    CryptPad's C trust score flags unpatched vulnerabilities●CryptPad holds a C trust score despite just 4 CVEs. The problem is 75% remain unpatched, with one high-severity flaw atMmastodonTechnologyCybersecurity02 h ago

    CryptPad, the open-source collaborative document platform, has received a C trust score in a vendor security assessment. The rating reflects not the small number of reported vulnerabilities β€” just four CVEs β€” but the fact that roughly 75% of them remain unpatched, including one high-severity flaw rated 7.5 on the CVSS scale. Security commentators argue that low CVE counts mean little if fixes lag behind disclosures.

  18. 18
    Infosec newcomer introduces themselves on Mastodonβ–ΌHello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRadMmastodonTechnologyCybersecurity174 d ago

    A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.

  19. 19
    Privacy-minded users question Proton Mail's ethicsβ–ΌBeen hearing some sketchy things about the ethics going on at # protonmail and after I just finished my gmail transitionMmastodonLifeHome & Garden73 d ago

    Users in the open-source community are voicing concerns about ethical practices at Proton Mail, the Swiss privacy-focused email provider. Some say they had just switched from Google's Gmail only to hear worrying claims, and are now asking peers what alternatives to use for email and cloud storage, with suggestions including self-hosted options like Nextcloud.

  20. 20
    Developer launches first mobile app after taxi kidnapping ordeal●Yes, the title is correct. This is really what happened to me, and today I'm going to write about... # mobile # softwareMmastodonTechnologySoftware23 d ago

    A software developer says they have launched their first mobile application after surviving a kidnapping involving a taxi, and is now writing publicly about the experience. The post has drawn attention across mobile, security and open-source communities, with readers responding to the unusual link between a personal safety incident and the decision to build and release an app.

  21. 21
    Google Suspends Open Source Bug Bounty Program Over AI-Generated Reportsβ–ΌGoogle Suspends Open Source Bug Bounty Program Due to Surge in AI-Generated Reportsβœ‰newsTechnologySoftware13 h ago

    Google has suspended its open source bug bounty program, citing a flood of AI-generated vulnerability reports. The company says low-quality, automated submissions have overwhelmed reviewers, making it hard to identify genuine security flaws. Security researchers say the incident highlights how generative AI tools are producing mass, superficial bug reports that undermine trusted vulnerability disclosure programs.

  22. 22
    SELinux: a security tool born of paranoia●Rulers from the most paranoid realms develop useful weapons. # Linux # OpenSource https:// cromwell-intl.com/open-sourceMmastodonTechnologySoftware21 d ago

    A write-up on SELinux is circulating among Linux and open-source users, framing the US National Security Agency's security enhancements for Linux as 'weapons' built by the world's most paranoid rulers. The article covers how Security-Enhanced Linux works across RHEL, Oracle Linux, CentOS and related distributions, and why the mandatory access controls originally developed with the NSA are now considered a useful defense tool.

  23. 23
    AI Finds More Software Vulnerabilities, But Open Source Fixers Are Scarceβ–ΌAI is Finding More Vulnerabilities But Open Source Needs More People to Fix Themβœ‰newsTechnologySoftware2 d ago

    AI tools are increasingly effective at discovering software vulnerabilities, including many in open source projects. However, the pool of human developers able to review, verify and patch these flaws is not keeping pace, leaving security gaps open longer. The report argues that discovery is outstripping remediation capacity, and calls for more investment in open source maintenance and the people who sustain it.

  24. 24
    OpenSSL 4.0.3 Released as Security Patch, Update Now●# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-aMmastodonTechnologySoftware46 d ago

    The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.

  25. 25
    Pangolin 1.24 Adds Exit Nodes and Linux Subnet Routing●Pangolin 1.24 introduces full-tunnel Exit Nodes, Linux Subnet Router support, and major client improvements across desktMmastodonTechnologySoftware21 d ago

    The open-source tunneled reverse proxy Pangolin has released version 1.24, bringing full-tunnel Exit Nodes, support for Linux Subnet Routers, and significant client improvements across desktop and mobile platforms. The update extends Pangolin's capabilities as a self-hosted alternative for secure remote access, drawing attention from the open-source and VPN communities.

  26. 26
    Civil society groups automate their work on Cloudflare●Building for good: How civil society organizations are automating on Cloudflare https://blog.cloudflare.com/civil-societMmastodonTechnology33 d ago

    Cloudflare has published a blog post outlining how civil society organizations are using its platform to automate their operations. The piece highlights ways nonprofits and advocacy groups apply automation tools for security, reliability and efficiency in their work. The story is circulating among technology and open-source communities online.

  27. 27
    No-KYC privacy directory with incident-based trust scoring released●I built a no-KYC privacy directory with incident-based trust scoring (and a map of who's been sanctioned) # privacy # seMmastodonTechnologySoftware33 d ago

    An open-source developer has released a privacy directory that requires no identity verification, instead ranking participants with a scoring system based on recorded incidents. The project also includes a map showing which parties have been sanctioned. It is written in PHP and shared with the coding community as free software, with discussion so far centered on privacy, security, and whether incident-based trust can replace conventional verification.

  28. 28
    Sovereign Tech Fund relaunches resilience programme for open source●Wir starten das # SovereignTechResilience Programm neu mit vier weiteren Dienstleistungen fΓΌr kritische # OpenSource -PrMmastodonTechnologySoftware64 d ago

    Germany's Sovereign Tech Fund is relaunching its Sovereign Tech Resilience programme, adding four new services for critical open source projects: memory safety, post-quantum encryption, software supply chain security, and compliance with the EU Cyber Resilience Act. The move aims to strengthen the security and long-term maintenance of digital infrastructure that many public and private systems rely on.

  29. 29
    Tanuki open-source tool brings protocol-first Linux AD triage to AI agents●Excited to share a new open-source project: Tanuki 🦝 Protocol-first Linux Active Directory triage for AI coding agents &MmastodonTechnologyCybersecurity22 d ago

    A security researcher has released Tanuki, a new open-source tool described as protocol-first Linux Active Directory triage built for AI coding agents and operators. The developer says most coding agents hallucinate or propose noisy, dangerous tactics when handling Linux AD environments, such as recommending weak crypto settings. The project is being shared with the infosec community.

  30. 30
    AI code generation speeds ahead of open source developersβ–ΌAI can generate code faster, but can open source keep up?βœ‰newsTechnologySoftware5 d ago

    Discussion is growing around whether open source software projects can keep pace with AI tools that generate code far faster than human developers. The concern centres on how volunteer-driven communities, which maintain much of the world's critical software infrastructure, will absorb or compete with automated code production while still ensuring quality, security and proper review.

  31. 31
    Parrot OS 7.4 Released with AnonSurf 6.0 and New Raspberry Pi Imagesβ—πŸ§ Parrot OS 7.4 Released with AnonSurf 6.0, Updated Raspberry Pi Images Parrot OS 7.4 security-oriented distribution isMmastodonTechnologyAI12 d ago

    The Parrot Security team has released Parrot OS 7.4, the latest update to its security and privacy-focused Linux distribution. Version 7.4 ships with AnonSurf 6.0, updated hacking and security tools, optimized builds, and refreshed Raspberry Pi and ARM images, and is now available for download. Linux enthusiasts and privacy-focused users are welcoming the release and discussing the changes it brings.

  32. 32
    Google suspends open-source bug bounty amid flood of AI-generated reports●Google suspends open-source bug bounty program as AI slop overwhelms maintainersβœ‰newsTechnologySoftware1 d ago

    Google has suspended its open-source bug bounty program, citing an overwhelming volume of low-quality, AI-generated vulnerability reports that burden maintainers. The decision highlights a growing problem across the security industry, as automated tools flood bug-tracking systems with junk submissions, making it harder for researchers to get legitimate findings reviewed and rewarded.

  33. 33
    Open-source crypto libraries draw cybersecurity attention●Open-source crypto libraries # negativepid # digitalInvestigations # OSINT # cybersecurity # AI # tech # onlineInvestigaMmastodonTechnologyRobotics03 d ago

    Open-source cryptographic libraries are being highlighted as a key resource for digital investigations and cybersecurity work. The topic sits at the intersection of OSINT, cybercrime research and AI-assisted analysis, with commentators framing accessible crypto tooling as important for online investigators examining encrypted material. Interest reflects broader debate about how open security tools are used by both defenders and criminals.

  34. 34
    F-Droid Ecosystem Under Pressure as Android Verification Tightens●The Evolution of the F-Droid Ecosystem On September 24, 2026, the open source community... # android # opensource # secuMmastodonTechnologyMobile35 d ago

    The open source community is discussing the future of F-Droid, the alternative app repository for Android. Commentary on September 24, 2026 contrasts a modernized 'F-Droid 2.0' vision with Google's app verification requirements, which many see as a barrier for sideloaded and independent software. The debate centers on whether open source Android distribution can survive tighter platform security rules.

  35. 35
    BitShot app promo video showcases crypto tracking process●And here is promo video for BitShot app, similar to an article I wrote earlier but showcasing the whole process with scrMmastodonBusinessCrypto05 d ago

    A security researcher has shared a promotional video for BitShot, an app demonstrating a complete screen-recorded process tied to bitcoin, OSINT and data scraping. The demo follows an earlier written article by the same person and highlights the tool's open-source approach to cryptocurrency monitoring and privacy-related security research.

  36. 36

    A new model focused on cyber open-source intelligence has been released, according to a security researcher announcing it online. The release is being shared among cybersecurity and OSINT practitioners, who are taking note of what a purpose-built model for intelligence gathering could offer. Details on the model's capabilities, creators and intended use were not immediately available.

  37. 37

    Visa has released an AI-powered cyber defence tool as open source, making the technology freely available for other organisations to inspect, use and build upon. The move positions the payments giant as a contributor to shared security infrastructure, though details on the tool's capabilities and intended users have not yet been widely reported.

  38. 38
    Multikernel Linux release offers kernel isolation without hypervisorsβ–ΌMultikernel Linux's new release provides kernel isolation without hypervisors | Open Source For You - technologyβœ‰newsTechnologySoftware5 d ago

    Multikernel Linux has shipped a new release that delivers kernel isolation without relying on hypervisors, according to Open Source For You. The approach separates workloads across multiple kernels to contain failures and security issues, offering an alternative to virtualization-based isolation for Linux systems.

  39. 39
    Open-source syscall-based implant and C2 tool released●Cross-platform syscall-powered implant & C2 β€” direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No wMmastodonTechnologyCybersecurity14 d ago

    Security researchers are discussing VoidSyscall, a newly shared open-source cross-platform implant and command-and-control framework. The tool uses direct syscalls on Windows and raw syscalls on Linux, bypassing the standard WinAPI layer, and supports HTTPS, DNS and ICMP channels for communication. It is aimed at red team and penetration testing use, and is drawing attention within the infosec community for its evasion-focused design.

  40. 40
    Attackers target older Core Lightning nodes in Lightning network alert●Bitcoin Lightning security alert issued as attackers target older Core Lightning nodesβœ‰newsBusinessCrypto3 d ago

    A security alert has been issued for the Bitcoin Lightning network after attackers began targeting nodes running older versions of Core Lightning, the popular open-source routing software. Operators of Lightning nodes are being urged to update their software to a patched version. The exact nature of the attacks and the scale of any losses remain unclear, but the warning has spread across the crypto community.

Repos