Advertisement
AI Coding Accelerates Open Source Risk and Remediation Debt
AI coding tools introduce open-source dependencies faster than security teams can manage, creating "remediation debt" that impacts enterprise security.
Nico Waisman: Evolution of Offensive Security and Open Source
Explore Nico Waisman's journey from self-taught hacker to pioneering offensive security and leading open source supply chain efforts.
Defending Against the 1,444% Surge in Open Source Supply Chain Attacks
GTIG reports a massive 1,444% spike in open source repository compromises. Learn how to mitigate threats from actors like UNC6780 and MIDNIGHT NEPTUNE.
OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse
OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.
Flipper Zero Transitions to Community-Led Firmware Development Model
Flipper Devices shifts firmware development to a community-centric model, raising new considerations for supply chain integrity and security update lifecycles.
Open Source Zero-Days and ATM Jackpotting: Analysis of Recent Threats
Legal actions against ATM jackpotting crews and hacktivists highlight ongoing risks in open-source security and financial infrastructure.
Advertisement
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
Miasma Worm Source Code Briefly Leaked on GitHub
Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.
Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets
New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.
RubyGems Suspends Registrations Due to Malicious Package Influx
RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.
The EOL Blind Spot: Addressing CVE Gaps in Legacy Software
Learn why end-of-life software creates critical security blind spots in CVE feeds and how to improve your SCA tool detection for legacy dependencies.
Microsoft Developer Account Suspensions Block OSS Security Patches
Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.
AI-Led Remediation Crisis: HackerOne Halts Bug Bounties
HackerOne pauses bug bounties due to an AI-driven remediation crisis, highlighting how automated vulnerability discovery overwhelms open-source project capacity to fix…
Axios Attack: Industrialized Social Engineering on NPM Maintainers
An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.
Open Source Security: Key Findings from 2025 Trust Report
Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.