search
open source security community
Trends
- 1Nvidia Open-Sources AI Safety Software to Catch VulnerabilitiesβΌNvidia AI Safety Software Is Open Source to Catch Vulnerabilities -- Market Talk
Nvidia has released its AI safety software as open source, a move aimed at helping developers detect and address vulnerabilities in artificial intelligence systems. By making the tooling publicly available, the company is positioning itself as a leader in AI security while inviting the broader developer community to scrutinize and improve the code. Industry watchers see it as part of a wider push for transparency in AI safety.
- 2OPAQUE's verifiable AI open source tools near half a million downloadsβΌOPAQUE's Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
OPAQUE Systems says downloads of its open source software for verifiable AI are approaching 500,000, while community code contributions have grown more than tenfold. The company, which builds privacy-preserving confidential computing tools, presented the figures as a sign of momentum behind its approach to running AI workloads securely, with adoption spreading across the developer community and coverage in technology trade press.
- 3IBM and Red Hat Patch Over 400 Hidden Open Source FlawsβIBM and Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities
IBM and Red Hat say they have remediated more than 400 previously unknown vulnerabilities in open source software, disclosing the results of their security work to the wider community. The announcement, carried by IBM's newsroom and picked up by wire services, highlights ongoing efforts by major vendors to find and fix flaws before attackers can exploit them, and underscores how much undiscovered risk remains in widely used open source components.
- 4Google pauses bug bounty submissions for open-source softwareβGoogle stellt Bug-Bounty-Programm fΓΌr Open Source vorerst ein Google nimmt seit 1. Oktober im Bug-Bounty-Programm fΓΌr Op
Google has stopped accepting vulnerability reports for open-source software through its bug bounty program as of October 1. The company will temporarily no longer pay rewards for product flaws found in open-source projects, though reports on its own flagship products continue. The move is drawing attention in the security community, as the open-source incentive program was seen as an important way to support researchers auditing widely used projects.
- 5F-Droid 2.0 launches with redesigned Android appβ# F -Droid 2.0 cambia volto: nuova # app # Android , # ricerca migliorata e piΓΉ controllo sulla # privacy # uno # sicure
F-Droid has released version 2.0 of its free and open-source Android app store, featuring a redesigned interface, improved search functionality and stronger privacy controls. The update also emphasizes user security as an alternative to big tech app stores. Early reactions among open-source enthusiasts are positive, with users welcoming the focus on privacy and greater control over installed software.
- 6
Drop is a new open-source tool for sandboxing Linux applications without root privileges, and it supports gVisor, Google's application kernel for stronger isolation. It is currently the top post on Hacker News, where users are discussing the project and its approach to running untrusted code safely on a Linux machine. The reaction so far is mixed, with the technical community weighing its usefulness against existing sandboxing options.
- 7
OpenBao is an open-source tool written in Go for managing, storing, and distributing sensitive data such as passwords and API secrets, encryption keys, and digital certificates. It emerged as a community-maintained alternative to HashiCorp Vault after licensing changes. On GitHub's trending list this week it has picked up new stars and attention, with developers discussing it as a free, open option for handling secrets securely in their infrastructure.
- 8Parrot OS 7.4 Released With Linux Kernel 7.1 and AnonSurf 6.0βParrot OS 7.4 rolls out with Linux kernel 7.1, AnonSurf 6.0, refreshed security tools, updated Raspberry Pi images, and
The Parrot security team has released Parrot OS 7.4, a point update to its privacy-focused Linux distribution. The release ships with Linux kernel 7.1, the new AnonSurf 6.0 anonymity tool, refreshed security and penetration testing utilities, updated Raspberry Pi images, and broader package improvements. Users in the Linux and open-source community are welcoming the update for keeping the distro's privacy tooling current.
- 9testers try out open-source project LittleFediβGot the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,
A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.
- 10MailAccess email OSINT framework launches on Hacker NewsβShow HN: MailAccess β the true Email OSINT framework
A developer is presenting MailAccess, a self-described open-source intelligence framework for investigating email addresses, to the Hacker News community. The tool, promoted at mailaccess.pro, is positioned as a way to gather information linked to an email account for OSINT purposes. The project is drawing attention and engagement from the tech community, with users weighing in on its capabilities.
- 11OpenSSF Announces Expanded Membership and Global Policy ResourcesβΌOpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe
The Open Source Security Foundation (OpenSSF) announced expanded membership and new global policy resources during its Community Day Europe event. The announcements, distributed via PR Newswire by the Linux Foundation, highlight the foundation's growing base of participating organisations and its efforts to provide policy guidance on open source software security to governments and industry worldwide.
- 12
Debate is underway over who actually controls and profits from open source software, as major companies increasingly fund, contribute to and commercialize community-built projects. Commenters are weighing whether corporate backing undermines the open source model or secures its future, and whether maintainers get a fair share of the value they create.
- 13Accrescent developers detail API management challengesβHow does a complex application like Accrescent manage its API? In this blog post, we discuss some of the API challenges
The developers behind Accrescent, a security-focused Android app store, have published a blog post explaining how the application manages its API. The post, titled 'A Tale of Too Many Protocols', describes the API challenges the team encountered and their efforts to build a single source of truth for the project's protocols.
- 14Flatpak 1.18.4 Patches Six Security Vulnerabilitiesβ# Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities https:// linuxiac.com/flatpak-1-18-4-re leased-wit
A new maintenance release of Flatpak, the Linux application sandboxing and distribution framework, is out with version 1.18.4 addressing six security vulnerabilities. Linux users and system administrators are being encouraged to update their installations promptly. The release is drawing attention in the free and open-source software and cybersecurity communities, where Flatpak updates are closely watched because the tool is widely used for running sandboxed desktop applications across Linux distributions.
- 15OpenSSL 4.0.3 Released as Security Patch, Update Nowβ# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 16CIRCL launches major website update with new feedsβWe did a major update to our website: https://www. circl.lu/ There are now RSS and Atom feeds available: https://www. ci
CIRCL, Luxembourg's national cybersecurity agency, has rolled out a major redesign of its website. The update adds RSS and Atom feeds for following its content, plus a complete overview page listing all of the organisation's open-source and open-standard projects. The announcement is drawing attention from the cybersecurity and open-source community, which closely follows CIRCL's freely available tools and resources.
- 17
HackerNoon has published an interview with Pranshu Raghav on securing the open source AI ecosystem. The piece examines how developers and security teams can protect openly available AI models, tools and pipelines from misuse and vulnerabilities as adoption of open AI projects accelerates across the software industry.
- 18AI Finds More Vulnerabilities, But Open Source Lacks ManpowerβΌAI is Finding More Vulnerabilities But Open Source Needs More People t
AI tools are increasingly effective at discovering software vulnerabilities, but security experts warn that open source projects still lack the human maintainers needed to review, triage and fix the growing volume of reported flaws. Infosecurity Magazine highlights the widening gap between machine-generated bug reports and the limited developer capacity available to address them across widely used open source components.
- 19Google pauses open source bug bounty amid flood of AI reportsβΌGoogle benches open source bug bounty program following βsignificant riseβ in AI submissions
Google has suspended its open source bug bounty program, citing a significant rise in AI-generated vulnerability submissions. The company says many of the reports flooding in are low-quality, machine-written findings that take up valuable reviewer time without adding real security value. The move has sparked debate among security researchers about the impact of automated tools on responsible disclosure programs and how bounty platforms should handle AI-created noise.
- 20
Google has paused its open-source bug bounty program, with reports linking the decision to a flood of low-quality, AI-generated submissions. The program paid researchers for finding vulnerabilities in Google's open-source projects, and the influx of trivial or fabricated reports appears to have made it harder to identify genuine security flaws. Security watchers say the move highlights how generative AI tools are straining vulnerability disclosure programs across the industry.
- 21Infosec newcomer introduces themselves on MastodonβΌHello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 22Google Freezes Open Source Bug Bounty Until 2027 Amid AI Spam FloodβΌGoogle Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Flood
Google has paused its open source bug bounty programme until 2027, citing an overwhelming flood of AI-generated spam reports. Invalid, low-quality vulnerability submissions allegedly produced by AI tools have crowded out legitimate security research, making the programme unsustainable in its current form. The move has sparked debate in the security community about how AI is affecting vulnerability disclosure processes and whether other bounty programmes will follow suit.
- 23Developer Launches Self-Custodial Multi-Chain Wallet Bot for TelegramβHey everyone, I recently built VaultForgeWalletBot β a self-custodial multi-chain crypto wallet... # crypto # telegram #
An independent developer has built VaultForgeWalletBot, a self-custodial, multi-chain crypto wallet that operates inside Telegram, and published an account of how it was made. The project is open source and is being shared with crypto and software development communities. Interest centers on the unusual approach of combining self-custody of digital assets with a messaging app, a design that raises both convenience and security questions.
- 24Developer launches first mobile app after taxi kidnapping ordealβYes, the title is correct. This is really what happened to me, and today I'm going to write about... # mobile # software
A software developer says they have launched their first mobile application after surviving a kidnapping involving a taxi, and is now writing publicly about the experience. The post has drawn attention across mobile, security and open-source communities, with readers responding to the unusual link between a personal safety incident and the decision to build and release an app.
- 25Privacy-minded users question Proton Mail's ethicsβΌBeen hearing some sketchy things about the ethics going on at # protonmail and after I just finished my gmail transition
Users in the open-source community are voicing concerns about ethical practices at Proton Mail, the Swiss privacy-focused email provider. Some say they had just switched from Google's Gmail only to hear worrying claims, and are now asking peers what alternatives to use for email and cloud storage, with suggestions including self-hosted options like Nextcloud.
- 26OpenSSH Creator's Security Philosophy Draws Renewed AttentionβOpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One https://zbruceli.org/blog/the-man-who-tr
A profile of the OpenSSH project and its creator is drawing attention across the tech community. OpenSSH underpins secure remote access on virtually every Mac, Linux server and Windows machine, yet is maintained with a deliberately paranoid approach: its code is written to trust no input, no system and no contributor. The piece highlights how this rigour has kept the critical open-source tool safe for decades, prompting discussion about whether other widely used software should adopt similar discipline.
- 27RetireTui brings retirement planning to the terminalβWhen am I retiring? One sec, let me check my terminal... π RetireTui β See your financial future from the terminal π₯Ά A l
A developer has released RetireTui, a local-first retirement planning tool that runs in the terminal. Written in Rust, it offers year-by-year financial projections, tax calculations, historical market data and Social Security optimization, with all data kept on the user's own machine. The project is drawing attention in open-source and developer communities for its unusual terminal-based take on personal finance software.
- 28Free Breach-Check Alternatives to Have I Been Pwned in 2026βBy Marcus Hale. Originally published on Meikuio on August 7, 2026. Reviewed for syndication October... # security # priv
A new guide by Marcus Hale, first published on Meikuio in August 2026 and recently reviewed for syndication, surveys free alternatives to Have I Been Pwned, the popular service for checking whether your email or credentials have appeared in data breaches. The piece covers open-source options aimed at beginners, with attention to security and privacy trade-offs, and is being shared widely in developer and open-source communities.
- 29AI Finds More Software Vulnerabilities, But Open Source Fixers Are ScarceβΌAI is Finding More Vulnerabilities But Open Source Needs More People to Fix Them
AI tools are increasingly effective at discovering software vulnerabilities, including many in open source projects. However, the pool of human developers able to review, verify and patch these flaws is not keeping pace, leaving security gaps open longer. The report argues that discovery is outstripping remediation capacity, and calls for more investment in open source maintenance and the people who sustain it.
- 30Sovereign Tech Fund relaunches resilience programme for open sourceβWir starten das # SovereignTechResilience Programm neu mit vier weiteren Dienstleistungen fΓΌr kritische # OpenSource -Pr
Germany's Sovereign Tech Fund is relaunching its Sovereign Tech Resilience programme, adding four new services for critical open source projects: memory safety, post-quantum encryption, software supply chain security, and compliance with the EU Cyber Resilience Act. The move aims to strengthen the security and long-term maintenance of digital infrastructure that many public and private systems rely on.
- 31AI code generation speeds ahead of open source developersβΌAI can generate code faster, but can open source keep up?
Discussion is growing around whether open source software projects can keep pace with AI tools that generate code far faster than human developers. The concern centres on how volunteer-driven communities, which maintain much of the world's critical software infrastructure, will absorb or compete with automated code production while still ensuring quality, security and proper review.
- 32Civil society groups automate their work on CloudflareβBuilding for good: How civil society organizations are automating on Cloudflare https://blog.cloudflare.com/civil-societ
Cloudflare has published a blog post outlining how civil society organizations are using its platform to automate their operations. The piece highlights ways nonprofits and advocacy groups apply automation tools for security, reliability and efficiency in their work. The story is circulating among technology and open-source communities online.
- 33Payload CMS vulnerability could expose hidden fieldsβπ¨ EUVD-2026-93489 π Score: 7.1/10 (CVSS v3.1) π¦ Product: payload, payload π’ Vendor: payloadcms π Updated: 2026-10-06 π P
A medium-severity vulnerability, EUVD-2026-93489, has been documented in Payload CMS, the open-source content platform by Payload. Rated 7.1 out of 10 on the CVSS v3.1 scale, the flaw involves polymorphic join queries that could disclose hidden fields. The advisory was updated on 6 October 2026, and security feeds are circulating the details.
- 34LibreOffice and OpenOffice flaws let malicious spreadsheets run codeβThe first one has been patched. The Hacker News: LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Wi
Security researchers have disclosed vulnerabilities in LibreOffice and OpenOffice that allow malicious spreadsheet files to execute code on a victim's machine without triggering the usual macro warnings. The first of the flaws has reportedly been patched, and users are being urged to update their office suites. The issue has drawn attention in the open-source and information security communities because it bypasses a long-standing protection that many users rely on when opening documents from unknown sources.
- 35No-KYC privacy directory with incident-based trust scoring releasedβI built a no-KYC privacy directory with incident-based trust scoring (and a map of who's been sanctioned) # privacy # se
An open-source developer has released a privacy directory that requires no identity verification, instead ranking participants with a scoring system based on recorded incidents. The project also includes a map showing which parties have been sanctioned. It is written in PHP and shared with the coding community as free software, with discussion so far centered on privacy, security, and whether incident-based trust can replace conventional verification.
- 36SELinux: a security tool born of paranoiaβRulers from the most paranoid realms develop useful weapons. # Linux # OpenSource https:// cromwell-intl.com/open-source
A write-up on SELinux is circulating among Linux and open-source users, framing the US National Security Agency's security enhancements for Linux as 'weapons' built by the world's most paranoid rulers. The article covers how Security-Enhanced Linux works across RHEL, Oracle Linux, CentOS and related distributions, and why the mandatory access controls originally developed with the NSA are now considered a useful defense tool.
- 37F-Droid Ecosystem Under Pressure as Android Verification TightensβThe Evolution of the F-Droid Ecosystem On September 24, 2026, the open source community... # android # opensource # secu
The open source community is discussing the future of F-Droid, the alternative app repository for Android. Commentary on September 24, 2026 contrasts a modernized 'F-Droid 2.0' vision with Google's app verification requirements, which many see as a barrier for sideloaded and independent software. The debate centers on whether open source Android distribution can survive tighter platform security rules.
- 38Google Suspends Open Source Bug Bounty Program Over AI-Generated ReportsβΌGoogle Suspends Open Source Bug Bounty Program Due to Surge in AI-Generated Reports
Google has suspended its open source bug bounty program, citing a flood of AI-generated vulnerability reports. The company says low-quality, automated submissions have overwhelmed reviewers, making it hard to identify genuine security flaws. Security researchers say the incident highlights how generative AI tools are producing mass, superficial bug reports that undermine trusted vulnerability disclosure programs.
- 39CryptPad's C trust score flags unpatched vulnerabilitiesβCryptPad holds a C trust score despite just 4 CVEs. The problem is 75% remain unpatched, with one high-severity flaw at
CryptPad, the open-source collaborative document platform, has received a C trust score in a vendor security assessment. The rating reflects not the small number of reported vulnerabilities β just four CVEs β but the fact that roughly 75% of them remain unpatched, including one high-severity flaw rated 7.5 on the CVSS scale. Security commentators argue that low CVE counts mean little if fixes lag behind disclosures.
- 40Pangolin 1.24 Adds Exit Nodes and Linux Subnet RoutingβPangolin 1.24 introduces full-tunnel Exit Nodes, Linux Subnet Router support, and major client improvements across deskt
The open-source tunneled reverse proxy Pangolin has released version 1.24, bringing full-tunnel Exit Nodes, support for Linux Subnet Routers, and significant client improvements across desktop and mobile platforms. The update extends Pangolin's capabilities as a self-hosted alternative for secure remote access, drawing attention from the open-source and VPN communities.
Repos
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f