Tag: open source software
27 articles

Australian Police Disrupt Notorious Cybercrime Group TeamPCP
In a major cybercrime crackdown, Australian authorities have arrested two alleged members of the notorious TeamPCP group, accused of infecting over a thousand organizations worldwide with malicious code. The suspects, aged 21 and 23, face serious charges, including unauthorized data modification and dealing in criminal proceeds.

Australian Police Disrupt TeamPCP Cybercrime Syndicate
Meet Ellis, a self-proclaimed cybercrime rockstar who thought "blackhatting is fun" - but his thrill-seeking days are over, thanks to the Australian Federal Police's crackdown on the notorious TeamPCP syndicate. Two young men from Western Australia have been arrested in connection with a massive software supply-chain scam that targeted thousands of global businesses.

CISA Warns of Hackers Exploiting MLflow Vulnerability
Hackers are actively exploiting a critical vulnerability in MLflow, a popular open-source AI engineering platform, that could compromise your AI applications. Federal agencies have been ordered to patch exposed instances within two weeks to avoid potential attacks.

Open Source Software Faces Reckoning
Open source software had a carefree adolescence, running wild and free for two decades, but its idyllic era is now coming to an abrupt end, forcing it to confront a harsh new reality. It's time for open source to grow up and face the challenges of a rapidly changing world.

Gitea Flaw Exposes Server Files to Unauthenticated Attackers
A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

AI-Powered Vulnerability Discovery Surges, Threatens Patch Window
In a staggering two-month sprint, Palo Alto Networks' NOVA uncovered 14,090 confirmed vulnerabilities in just 3,915 open-source software projects - a remarkable demonstration of AI-powered vulnerability discovery's rapid impact. This autonomous pipeline is revolutionizing the way we identify and tackle software vulnerabilities.

CISA Issues Guidance on Open-Source Software Security Risks
The Cybersecurity and Infrastructure Security Agency is stepping up to help manage open-source software security risks with a new guidebook titled "Open Source Software: Security Principles and Practices". This move aims to enhance the nation's cybersecurity by providing federal agencies with essential security recommendations.

Amazon Exposes North Korean Hacking Campaign Targeting Open-Source Software
A North Korea-linked hacking group has been exploiting widely-used open-source software, infecting millions of users through compromised packages like axios, which alone receives over 100 million downloads weekly. This campaign, linked to a single financially motivated actor, has been targeting major JavaScript packages since March 2025.

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution
A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

Governments Struggle to Secure Open-Source Software
The alarming reality is that years of underinvestment in open-source software security are catching up with us, with a new supply chain compromise emerging almost every week. A recent scan by Project Glasswing found over 6,000 high-risk vulnerabilities in popular open-source projects, but only a tiny fraction have been patched.

Chainguard Launches Athena to Fortify Open Source Against AI Threats
Meet Athena, a groundbreaking coalition and platform that helps safeguard open-source software from AI-driven threats by streamlining vulnerability detection, private remediation, and coordinated disclosure. By joining forces, Athena members can proactively protect the entire open-source ecosystem from emerging risks.

Gogs Fixes Zero-Day Flaw Enabling Remote Code Execution
A critical vulnerability in Gogs allows attackers to execute remote code, putting Internet-facing instances at risk of full compromise - and it's easily exploitable by anyone who can create an account. This flaw enables attackers to wreak havoc without needing admin privileges, making swift action a must.

Open Source Faces Hard Fork Amid AI-Fueled Security Crisis
The open source community is facing a daunting security crisis fueled by AI, giving rise to a new category of threat dubbed "Mythos" - a complex chain of low-level issues that can be combined to create devastating attacks. This emerging threat is not just a single bug or false positive, but a game-changing phenomenon that demands immediate attention.

Security Researcher Exploits Flaw in Pretalx Conference Tool
A security researcher recently uncovered a vulnerability in pretalx, a popular conference tool, that could let hackers inject malicious code into an organizer's interface, putting sensitive data at risk. This flaw, known as a stored cross-site scripting vulnerability, could be triggered through simple search queries.

Grafana Breach Exposes Codebase, Sparks Extortion Attempt
Grafana recently experienced a security breach, where an unauthorized party gained access to its GitHub environment, downloading its codebase, but fortunately, no customer data or personal info was compromised. The company swiftly responded, taking measures to prevent further unauthorized access and thwarting an attempted extortion by the attacker.

Google Researchers Uncover AI-Developed Zero-Day Exploit
Google researchers have made a groundbreaking discovery - a zero-day exploit that was developed with the help of artificial intelligence, which could have led to a large-scale attack if not caught in time. Thankfully, the vulnerability has been patched after Google alerted the affected vendor.

Linux Distributions Scramble to Patch Dirty Frag Kernel Vulnerabilities
A critical vulnerability known as Dirty Frag has been discovered in the Linux kernel, allowing attackers with local access to gain root privileges across major distributions. Linux distributions are now racing against the clock to patch this chained local privilege escalation flaw.

CVE Feeds Overlook End-of-Life Software Vulnerabilities
The blind spot in CVE feeds is leaving end-of-life software vulnerabilities flying under the radar, with a staggering 167,286 false negatives identified in 2025 alone. This oversight can have serious consequences, as outdated software can still be exploited, even if it's no longer receiving patches.

Hackers exploit Qinglong flaws for cryptomining deployments
Hackers are taking advantage of two major flaws in the Qinglong open-source task scheduler, CVE-2026-3965 and CVE-2026-4047, which can be combined to gain remote control of vulnerable systems. These authentication-bypass vulnerabilities affect Qinglong versions 2.20.1 and older, and have been exploited for cryptomining deployments.

Axios Breach Underscores Need for AI in Supply Chain Security
A single, sneaky change to a popular open-source software can spread like wildfire, infecting a staggering 100 million weekly downloads across businesses, startups, and government systems - and that's exactly what happened in a recent Axios breach. The lesson is clear: AI is no longer a nice-to-have, but a must-have for safeguarding supply chain security.

France Accelerates Exodus from US Tech with Open-Source Push
France is taking a bold step towards digital independence, with a push to ditch American commercial software for open-source alternatives, and all government ministries are now racing against the clock to reduce their reliance on US tech by the fall. This move signals a growing unease among European governments about Silicon Valley's influence.

Marimo Flaw CVE-2026-39987 Exploited Rapidly After Disclosure
A single line of code can drastically change the risk landscape for thousands of users - and that's exactly what happened with Marimo, an open-source Python notebook, when a critical vulnerability (CVE-2026-39987) was exploited just 10 hours after its disclosure. This severe flaw, with a CVSS score of 9.3, allows pre-authenticated remote code execution, putting all Marimo versions prior to the disclosed fix at risk.

Tech Giants Unveil AI-Powered Bid to Fix Open Source Flaws
Tech giants have launched a game-changing $100 million initiative, Project Glasswing, harnessing AI to uncover and fix hidden flaws in critical open source software, aiming to bolster security and prevent devastating exploits. Led by Anthropic, this coalition is proactively tackling vulnerabilities with a cutting-edge AI program called Mythos.

Apache ActiveMQ Flaw Exposes Systems to Remote Code Execution
A critical security flaw in Apache ActiveMQ Classic, hidden for over 13 years, allows remote code execution, putting vulnerable systems at risk of arbitrary command execution. This long-undetected vulnerability highlights the importance of staying vigilant and proactive in identifying and addressing potential security threats.