search
software security
Trends
- 1NVIDIA Launches Open Agent Safety Platform▼NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
NVIDIA has announced an open platform aimed at securing AI agents across their full lifecycle, from testing through to production deployment. The initiative, revealed through the company's newsroom, is designed to help developers evaluate and safeguard autonomous agents before they go live. Details on partners and tooling remain limited, but the move signals NVIDIA's push into AI safety infrastructure as agentic systems see rapid adoption across enterprise software.
- 2
NVIDIA has released the code of its agent safety platform as open source, making its tooling for keeping AI agents secure and controlled available to developers. Technology publications including Open Source For You and Adafruit's blog report the move, which lets companies inspect and adapt the safety software rather than rely on a proprietary product.
- 3Nvidia launches open-source platform to improve AI agent safety▼Nvidia launches open-source platform to enhance AI agent safety
Nvidia has introduced an open-source platform designed to make AI agents safer to deploy, giving developers tools to test and guard against unsafe behaviour. The move, reported by SC Media, positions Nvidia alongside other major tech firms racing to address security and reliability concerns as autonomous AI systems spread across enterprise software.
- 4Hackers steal patient data from Polish medical software provider▼Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Hackers exploited an SQL injection flaw to steal patient data from a Polish medical software provider, according to a security news report. The attack targeted a vulnerability in the company's systems, exposing sensitive health information of patients. No details on the number of affected individuals or the provider's identity were included in the report.
- 5Nvidia launches AI safety software after Hugging Face hack▼Nvidia releases AI safety software it says could have stopped Hugging Face hack
Nvidia has released new AI safety software that the company says could have prevented the recent Hugging Face hack. The tool is aimed at protecting AI models and data pipelines from security breaches, and its launch comes as concerns grow over vulnerabilities in widely used machine learning platforms following the Hugging Face incident.
- 6Four Corners documentary shows BYD car hacked with no password●Hacking this BYD was too easy; it didn’t even have a password | Four Corners Documentary
An ABC Four Corners documentary examined cybersecurity weaknesses in vehicles made by Chinese automaker BYD, showing that one car could be hacked easily because it lacked even basic password protection. The investigation has drawn widespread attention, fueling debate about the security standards of connected cars and the risks of software-driven vehicles from Chinese manufacturers.
- 7No security agency probed breaches in Netanyahu aide's tool▼No Security Agency Probed Security Breaches in Tool Developed by Netanyahu Aide
Haaretz reports that no Israeli security agency ever examined security breaches involving a tool developed by an aide to Benjamin Netanyahu. The claim raises questions about oversight of sensitive software connected to the prime minister's inner circle. Commenters are discussing the apparent gap in accountability and what it means for cybersecurity governance in Israel's security establishment.
- 8Nvidia launches open-source tool to strengthen AI security▼Nvidia introduces open-source tool to boost AI security (NVDA:NASDAQ)
Nvidia has introduced a new open-source tool aimed at improving the security of artificial intelligence systems. The release gives developers free access to technology designed to identify and address vulnerabilities in AI applications. As Nvidia's chips and software underpin much of the AI boom, the move is being read as an effort by the company to position itself as a leader in AI safety as well as hardware and compute.
- 9
The Trump administration is moving to roll back US fuel economy standards, easing emissions and efficiency requirements for automakers. The policy shift is being reported alongside growing concern over cybersecurity in connected vehicles, as cars become increasingly software-dependent and vulnerable to hacking. The rollback is likely to reignite debate between industry groups welcoming looser rules and environmental advocates warning of higher emissions and fuel consumption.
- 10Nvidia Unveils AI Agent Safety Platform With Hardware Watchdog●📰 Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog wiredmikey shares a report from SecurityWeek: Nvi
Nvidia announced the Open Agent Safety Platform, combining open source software with a reference system design that uses a hardware-based watchdog to keep AI agents within set boundaries. The announcement, reported by SecurityWeek, comes amid growing concern over autonomous AI agents acting unpredictably, and positions Nvidia to supply safety tooling for enterprise AI deployments.
- 11Nvidia Open-Sources AI Safety Software to Catch Vulnerabilities▼Nvidia AI Safety Software Is Open Source to Catch Vulnerabilities -- Market Talk
Nvidia has released its AI safety software as open source, a move aimed at helping developers detect and address vulnerabilities in artificial intelligence systems. By making the tooling publicly available, the company is positioning itself as a leader in AI security while inviting the broader developer community to scrutinize and improve the code. Industry watchers see it as part of a wider push for transparency in AI safety.
- 12
A new exploit for the PlayStation 5, dubbed Relapse, has been published on GitHub and is drawing attention among console hackers and modding enthusiasts. The release fuels ongoing discussion about the console's security, potential firmware concerns for Sony, and the possibility of unofficial software or homebrew running on PS5 hardware.
- 13GitHub's AI agent finds 24 Android vulnerabilities●GitHub found 24 Android vulnerabilities using its open-source AI security agent: automated vulnerability discovery on re
GitHub says it discovered 24 vulnerabilities in Android using its open-source AI security agent, describing it as automated vulnerability discovery at scale on real production software. The company published details in a blog post, and the report is drawing attention as a notable demonstration of AI agents doing practical security research on widely used code.
- 14
Nvidia has released a new open-source framework aimed at improving the security of artificial intelligence systems. The tool is intended to help developers identify and address vulnerabilities in AI applications. Details about the framework's features, supported platforms, and initial adoption remain limited, but the move aligns with the broader industry push toward safer and more transparent AI development practices.
- 15Apple Products Hit by Remote Code Execution Vulnerability●Apple Products Remote Code Execution Vulnerability
Security authorities have issued an alert over a remote code execution vulnerability affecting Apple products, warning users that attackers could potentially run malicious code on affected devices. Apple is expected to address the flaw through a software update, and users are advised to install patches promptly and review official advisories for affected models and versions.
- 16CISA Warns of Active Exploitation of Critical Citrix NetScaler Flaws●CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The US Cybersecurity and Infrastructure Security Agency says attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler devices worldwide. The flaws affect NetScaler ADC and Gateway products, which are widely used by organisations to manage and secure application traffic. Security teams are being urged to patch immediately, as exploited NetScaler vulnerabilities have historically enabled large-scale breaches of governments and businesses.
- 17NVIDIA launches Open Agent Safety Platform with BlueField-4 kill switch●Will kernel isolation plus a silicon kill switch stop agents that already know how to fake their own logs? NVIDIA’s Open
NVIDIA has introduced the Open Agent Safety Platform, pairing the Apache 2.0-licensed OpenShell with Sentry running on BlueField-4 hardware, aiming to isolate AI agents at the kernel level and provide a hardware-based kill switch. More than 100 partners are on the launch list. Security commentators are debating whether such containment can stop agents capable of faking their own logs.
- 18GitHub's AI agent uncovered 24 Android app vulnerabilities▼GitHub’s AI agent found 24 Android app vulnerabilities
GitHub says its AI agent identified 24 vulnerabilities in Android applications, adding to growing evidence that autonomous coding assistants can take on security research tasks. The finding, reported by Help Net Security, highlights both the potential of AI-driven bug hunting and the questions it raises about verifying machine-discovered flaws. Security teams are watching closely as AI agents move into vulnerability discovery.
- 19
The reporting obligations under the EU Cyber Resilience Act take effect in September 2026, requiring manufacturers of products with digital elements to notify authorities of actively exploited vulnerabilities and security incidents. Companies selling connected hardware and software in the EU are preparing compliance processes ahead of the deadline, with legal commentators flagging the timeline for firms still assessing their obligations.
- 20Oxygen Forensics also worked with EU law enforcement, reports say●Oxygen Forensics, which supplied software to U.S. government agencies and Russia’s FSB, also worked with EU law enforcement
Oxygen Forensics, a digital forensics firm that supplied software to U.S. government agencies and Russia's FSB, is now reported to have also worked with European Union law enforcement. The revelation is raising questions in Brussels about how EU bodies came to rely on tools from a company serving both Western agencies and Russian security services.
- 21GitHub says its open source AI agent found 24 Android vulnerabilities▼How we found 24 Android vulnerabilities using our open source AI security agent
GitHub researchers report that an open source AI security agent they built uncovered 24 vulnerabilities in Android. The company says the tool was used to scan Android code at scale, flagging security flaws automatically. The disclosure highlights a growing trend of using AI agents to find real bugs in widely used software, and the work is being discussed as an example of AI-assisted security research.
- 22Lenovo Flaw Exposed 5,000 Dropbox Accounts▼Lenovo Flaw Exposed 5,000 Dropbox Accounts Through Identity Federation
A security flaw in Lenovo's systems reportedly exposed around 5,000 Dropbox user accounts through identity federation, according to Cybersecurity Insiders. The vulnerability allowed credentials linked across federated identity services to be put at risk, raising fresh questions about how large enterprises secure single sign-on integrations with third-party cloud services.
- 23Docker and CNCF partner on open agent permissions spec●Docker and CNCF partner on an open spec for agent permissions
Docker has announced a partnership with the Cloud Native Computing Foundation to develop an open specification for agent permissions, aimed at defining how AI agents are granted and restricted access when running software. The announcement was published on Docker's blog as part of its Sandbox Kit initiative. Developer communities are discussing what a standardised permission model for autonomous agents could mean for security and interoperability in cloud-native tooling.
- 24OPAQUE's verifiable AI open source tools near half a million downloads▼OPAQUE's Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
OPAQUE Systems says downloads of its open source software for verifiable AI are approaching 500,000, while community code contributions have grown more than tenfold. The company, which builds privacy-preserving confidential computing tools, presented the figures as a sign of momentum behind its approach to running AI workloads securely, with adoption spreading across the developer community and coverage in technology trade press.
- 25Nvidia Releases AI Safety Software After Hugging Face Hack●Nvidia releases AI safety software it says could have stopped Hugging Face hack https:// lemmy.world/post/52464191
Nvidia has released new AI safety software that the company says could have prevented the recent breach of AI platform Hugging Face. The announcement ties the product directly to that incident, positioning it as a safeguard against similar supply-chain attacks on machine learning infrastructure. Discussion so far is limited to early sharing of the news among technology communities.
- 26Apple rolls out iOS 27.0.1 update for iPhone▼Apple releases iOS 27.0.1 for iPhone, here’s what’s new
Apple has released iOS 27.0.1, a new software update for iPhone users. The point release follows iOS 27 and is expected to bring bug fixes and security patches rather than major new features. Details on the full changelog remain limited, and iPhone owners are being prompted to install the update through Settings.
- 27CodeSupply Launches R&D Grants for Open-Source Software Security▼CodeSupply Announces R and D Grants for Open-Source Software Security
CodeSupply has announced a new research and development grant programme focused on open-source software security. The initiative will fund projects aimed at improving the safety and resilience of open-source code, an area of growing concern following high-profile supply chain vulnerabilities. Details on grant sizes, eligibility and deadlines have not yet been widely reported.
- 28Clop ransomware gang relocates servers after exploiting Grav CMS flaw▼Clop ransomware gang moves to new server after Grav CMS vulnerability exploited
The Clop ransomware gang has moved to new server infrastructure after exploiting a vulnerability in Grav CMS, the open-source flat-file content management system. The extortion group, known for large-scale data-theft campaigns against corporations and government agencies, is continuing operations despite the disruption. Security teams are being urged to patch Grav CMS installations and review whether their systems were targeted.
- 29Will Discontinued EVs Keep Getting Software Updates?▼Will Discontinued EVs Continue To Get Software Support?
A question circulating among electric vehicle owners: when a carmaker discontinues an EV model, will it continue to receive software updates and support? The concern is growing as several automakers retire older electric models, leaving owners uncertain whether features, security patches and performance improvements will keep coming to cars they already bought.
- 30Greg Kroah-Hartman on security in the LLM age●Greg Kroah-Hartman – Security in the LLM Age [video] Article URL: https://www. youtube.com/watch?v=NnV_cWeoo5Q Comments
Kernel developer Greg Kroah-Hartman, the maintainer of the Linux kernel stable branches, has given a talk on what large language models mean for software security. The presentation examines how AI-generated code affects vulnerability handling and maintenance work in large open source projects. The talk is circulating among developers and technology commentators, with early responses still limited but interest growing in how core infrastructure maintainers view LLM-driven risks.
- 31PlayStation 2 security chip fully reverse engineered●The original PlayStation 2 security chip has been reverse engineered https://www.engadget.com/2273354/playstation-2-secu
Engineers have reverse engineered the original PlayStation 2's security chip, uncovering how Sony's early-2000s copy protection worked at a hardware level. The breakthrough could make it easier to preserve PS2 games, improve emulation, and run homebrew software on original consoles. Retro gaming and preservation communities are celebrating the finding, two decades after the console's launch.
- 32
Kernel maintainer Greg Kroah-Hartman discusses software security in an era when large language models are increasingly used to write code. The talk, shared as a video, examines how AI-generated contributions affect the Linux kernel's review process and the challenges of maintaining security standards as LLM-assisted development spreads. Readers are weighing how maintainers can vet code at scale when machine-written patches grow in volume.
- 33
Apple has announced changes to how Full Disk Access works in macOS, detailing the update in a note to developers on its developer news page. The change affects apps that request broad access to user files, a permission long scrutinised for privacy and security implications. Developer discussion is focused on what the new rules require and how existing software will need to adapt.
- 34Apple releases iOS 26.7.1 with security fixes for iPhone▼iOS 26.7.1 available now for iPhone with security fixes
Apple has rolled out iOS 26.7.1 to iPhones, an update focused on security fixes rather than new features. Users are advised to install it to patch vulnerabilities. The release comes as many iPhone owners continue adjusting to the broader iOS 26 software generation.
- 35testers try out open-source project LittleFedi●Got the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,
A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.
- 36Nvidia launches OpenShell to enforce AI agent permissions▼Nvidia's OpenShell enforces agent permissions
Nvidia has introduced OpenShell, a tool that enforces permissions for AI agents, according to a VentureBeat report. The software is designed to control what autonomous agents are allowed to do, addressing security concerns as companies deploy agents that act on their own. Details beyond the announcement, such as availability and adoption, have not yet been widely reported.
- 37Frontline Education Data Breach Exposes K-12 Employee Data▼Frontline Education Data Breach 2026: Third-Party Software Vulnerability Exposes K-12 School District Employee Data
Frontline Education has been linked to a data breach affecting K-12 school district employees, attributed to a vulnerability in third-party software. Reports indicate personal employee data across districts may have been exposed, raising concerns about supply-chain security in education technology and prompting calls for stronger vendor oversight and district-level data protection measures.
- 38
Developers are embracing 'vibe coding', a practice of building software quickly by describing what they want in plain language and letting AI tools generate the code. Supporters say it dramatically speeds up prototyping and lowers the barrier for non-programmers. Critics warn it can produce untested, poorly understood code and may create maintenance and security problems as projects grow.
- 39AI becomes key to clearing cybersecurity vulnerability backlog●Cybersecurity’s New AI Imperative: Attacking the Backlog of Vulnerability Alerts
Cybersecurity teams are turning to artificial intelligence to tackle the mounting backlog of vulnerability alerts that overwhelms security operations. Bain argues AI can help prioritize and resolve alerts faster, addressing a growing gap between the volume of software flaws discovered and analysts' capacity to fix them.
- 40
Software developers are debating the limits of "vibe coding," the practice of building software by prompting AI models rather than writing code directly. While the approach works well for prototypes and small projects, many argue it breaks down on complex systems where architecture, security and long-term maintainability demand deliberate engineering decisions. The discussion reflects a broader reassessment of how far AI-assisted development can go.
Repos
- modelcontextprotocol/servers Model Context Protocol Servers
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man