Security news aggregator

Latest coverage for Open Source

Explore the latest in Open Source security, with insights on open-source software vulnerabilities, trends, and best practices in information security.

799 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Open Source is a term that denotes software for which the original source code is made freely available and may be redistributed and modified. It promotes an open exchange of ideas within the developer community to collaborate and build upon each other's work. This openness however can have various implications for information security.

In the context of information security, open source software can be both a boon and a challenge. On one hand, its transparent nature allows for more eyes to examine the code for vulnerabilities, potentially leading to more secure software. Security experts around the world can review and contribute to the security of the codebase, enhancing the overall robustness of the software.

On the other hand, the fact that the code is available to anyone can pose a risk, as malicious actors also have the opportunity to study it for exploits. Therefore, it necessitates vigilant patch management and community engagement to promptly identify and fix security issues. Ultimately, when used responsibly with proper security practices, open source software can be an asset to the cybersecurity landscape.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 799 Filtered view

Suspected Russian Crime Group Built Resilient Command-and-Control InfrastructureIn a joint operation, CrowdStrike, Google and Shadowserver Foundation disrupted infrastructure used by the Glassworm cybercrime group, cutting off attackers from victims. The group has wielded a remote access Trojan to repeatedly target developers of widely used open-source software.

CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday.  The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed to […] The post CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain appeared first on CyberScoop.

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials

The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and taking actions on your behalf across dozens of connected systems. The post Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow appeared first on Microsoft Security Blog.

Latest Mini Shai-Hulud Worm Steals Credentials, Includes Wiper, Now Open SourceA new Shai-Hulud variant has infected multiple npm repositories and jumped to other widely used JavaScript and Python packages. Designed to rapidly propagate, the worm steals over 100 different types of credentials and can wipe systems, including if developers try to delete it.

Loading more headlines...