<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Open Source Security</title><description>Cybersecurity articles tagged #Open Source Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI Coding Accelerates Open Source Risk and Remediation Debt</title><link>https://runtimerebel.com/blog/ai-coding-accelerates-open-source-risk-and-remediation-debt</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-accelerates-open-source-risk-and-remediation-debt</guid><description>AI coding tools introduce open-source dependencies faster than security teams can manage, creating &quot;remediation debt&quot; that impacts enterprise security.</description><pubDate>Tue, 25 Aug 2026 00:40:34 GMT</pubDate><category>Open Source Security</category><category>Supply Chain Risk</category><category>Enterprise Security</category><category>AI Coding</category><category>Remediation Debt</category></item><item><title>Nico Waisman: Evolution of Offensive Security and Open Source</title><link>https://runtimerebel.com/blog/nico-waisman-evolution-of-offensive-security-and-open-source</link><guid isPermaLink="true">https://runtimerebel.com/blog/nico-waisman-evolution-of-offensive-security-and-open-source</guid><description>Explore Nico Waisman&apos;s journey from self-taught hacker to pioneering offensive security and leading open source supply chain efforts.</description><pubDate>Tue, 18 Aug 2026 16:21:57 GMT</pubDate><category>Offensive Security</category><category>Open Source Security</category><category>Penetration Testing</category><category>Supply Chain Security</category><category>GitHub Security Lab</category></item><item><title>Defending Against the 1,444% Surge in Open Source Supply Chain Attacks</title><link>https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</guid><description>GTIG reports a massive 1,444% spike in open source repository compromises. Learn how to mitigate threats from actors like UNC6780 and MIDNIGHT NEPTUNE.</description><pubDate>Thu, 30 Jul 2026 14:10:41 GMT</pubDate><category>UNC6780</category><category>MIDNIGHT NEPTUNE</category><category>Open Source Security</category><category>GitHub Actions</category><category>NPM Security</category></item><item><title>OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse</title><link>https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</guid><description>OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.</description><pubDate>Fri, 10 Jul 2026 03:31:37 GMT</pubDate><category>OpenMandriva</category><category>Insider Threat</category><category>Open Source Security</category><category>Supply Chain Attack</category></item><item><title>Flipper Zero Transitions to Community-Led Firmware Development Model</title><link>https://runtimerebel.com/blog/flipper-zero-transitions-to-community-led-firmware-development-model</link><guid isPermaLink="true">https://runtimerebel.com/blog/flipper-zero-transitions-to-community-led-firmware-development-model</guid><description>Flipper Devices shifts firmware development to a community-centric model, raising new considerations for supply chain integrity and security update lifecycles.</description><pubDate>Sun, 05 Jul 2026 17:13:50 GMT</pubDate><category>Flipper Zero</category><category>Firmware Security</category><category>Flipper Devices</category><category>Hardware Hacking</category><category>Open Source Security</category></item><item><title>Open Source Zero-Days and ATM Jackpotting: Analysis of Recent Threats</title><link>https://runtimerebel.com/blog/open-source-zero-days-and-atm-jackpotting-analysis-of-recent-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-zero-days-and-atm-jackpotting-analysis-of-recent-threats</guid><description>Legal actions against ATM jackpotting crews and hacktivists highlight ongoing risks in open-source security and financial infrastructure.</description><pubDate>Sat, 04 Jul 2026 10:11:58 GMT</pubDate><category>ATM Jackpotting</category><category>Open Source Security</category><category>Anonymous</category><category>Zero Day Disclosures</category></item><item><title>Linux Foundation&apos;s Project Akrites: Bolstering Open Source Security</title><link>https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</guid><description>Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.</description><pubDate>Fri, 26 Jun 2026 12:52:09 GMT</pubDate><category>Linux Foundation</category><category>Akrites</category><category>Open Source Security</category><category>Vulnerability Management</category><category>Software Supply Chain</category></item><item><title>Miasma Worm Source Code Briefly Leaked on GitHub</title><link>https://runtimerebel.com/blog/miasma-worm-source-code-briefly-leaked-on-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-worm-source-code-briefly-leaked-on-github</guid><description>Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.</description><pubDate>Wed, 10 Jun 2026 20:58:55 GMT</pubDate><category>Miasma</category><category>Worm</category><category>Credential Stealing</category><category>Supply Chain Attack</category><category>GitHub</category><category>Open Source Security</category></item><item><title>Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis</title><link>https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</guid><description>Microsoft restores some GitHub repositories after 73 projects were hit by Miasma&apos;s supply chain attack to inject information stealers. Learn detection steps.</description><pubDate>Tue, 09 Jun 2026 17:00:07 GMT</pubDate><category>GitHub</category><category>Miasma</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Information Stealer</category><category>Open Source Security</category></item><item><title>Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets</title><link>https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</guid><description>New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.</description><pubDate>Mon, 08 Jun 2026 20:57:57 GMT</pubDate><category>Shai Hulud</category><category>PyPI</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Secrets</category><category>Python</category><category>Open Source Security</category></item><item><title>Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain</title><link>https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</guid><description>Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.</description><pubDate>Tue, 26 May 2026 20:47:57 GMT</pubDate><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>NPM</category><category>PyPI</category><category>Malicious Packages</category></item><item><title>RubyGems Suspends Registrations Due to Malicious Package Influx</title><link>https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</link><guid isPermaLink="true">https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</guid><description>RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.</description><pubDate>Wed, 13 May 2026 09:09:56 GMT</pubDate><category>RubyGems</category><category>Open Source Security</category><category>Package Manager</category><category>Supply Chain Security</category><category>Malicious Packages</category></item><item><title>The EOL Blind Spot: Addressing CVE Gaps in Legacy Software</title><link>https://runtimerebel.com/blog/the-eol-blind-spot-addressing-cve-gaps-in-legacy-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/the-eol-blind-spot-addressing-cve-gaps-in-legacy-software</guid><description>Learn why end-of-life software creates critical security blind spots in CVE feeds and how to improve your SCA tool detection for legacy dependencies.</description><pubDate>Tue, 05 May 2026 16:40:16 GMT</pubDate><category>EOL</category><category>SCA</category><category>Software Composition Analysis</category><category>CVE</category><category>Open Source Security</category></item><item><title>Microsoft Developer Account Suspensions Block OSS Security Patches</title><link>https://runtimerebel.com/blog/microsoft-developer-account-suspensions-block-oss-security-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-developer-account-suspensions-block-oss-security-patches</guid><description>Microsoft&apos;s suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.</description><pubDate>Thu, 09 Apr 2026 08:38:53 GMT</pubDate><category>Microsoft Partner Center</category><category>Open Source Security</category><category>Software Signing</category><category>Supply Chain Risk</category><category>Windows Development</category></item><item><title>AI-Led Remediation Crisis: HackerOne Halts Bug Bounties</title><link>https://runtimerebel.com/blog/ai-led-remediation-crisis-hackerone-halts-bug-bounties</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-led-remediation-crisis-hackerone-halts-bug-bounties</guid><description>HackerOne pauses bug bounties due to an AI-driven remediation crisis, highlighting how automated vulnerability discovery overwhelms open-source project capacity to fix…</description><pubDate>Thu, 09 Apr 2026 00:36:16 GMT</pubDate><category>HackerOne</category><category>Bug Bounty</category><category>AI Security</category><category>Vulnerability Management</category><category>Open Source Security</category><category>Remediation Crisis</category></item><item><title>Axios Attack: Industrialized Social Engineering on NPM Maintainers</title><link>https://runtimerebel.com/blog/axios-attack-industrialized-social-engineering-on-npm-maintainers</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-attack-industrialized-social-engineering-on-npm-maintainers</guid><description>An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.</description><pubDate>Tue, 07 Apr 2026 00:41:47 GMT</pubDate><category>Axios</category><category>NPM</category><category>Social Engineering</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>Maintainer Compromise</category></item><item><title>Open Source Security: Key Findings from 2025 Trust Report</title><link>https://runtimerebel.com/blog/open-source-security-key-findings-from-2025-trust-report</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-security-key-findings-from-2025-trust-report</guid><description>Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.</description><pubDate>Thu, 02 Apr 2026 12:26:52 GMT</pubDate><category>Open Source Security</category><category>Supply Chain Security</category><category>Vulnerability Management</category><category>Container Security</category><category>Software Composition Analysis</category></item><item><title>Tech Giants Pledge $12.5M to Bolster Open Source Software Security</title><link>https://runtimerebel.com/blog/tech-giants-pledge-12-5m-to-bolster-open-source-software-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tech-giants-pledge-12-5m-to-bolster-open-source-software-security</guid><description>Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.</description><pubDate>Tue, 17 Mar 2026 16:30:47 GMT</pubDate><category>OpenSSF</category><category>Linux Foundation</category><category>Open Source Security</category><category>Supply Chain Security</category><category>AI Safety</category></item></channel></rss>