Articles Tagged “Open Source Security”
33 articles found

AI Agent Memory Files: One Prompt Blocks the Spread
Anthropic and EPFL found payloads spread between AI agents via editable memory files, and a one-paragraph prompt warning cut the spread to near zero.

Hazmat Locks AI Coding Agents Out of Your SSH Keys
Hazmat is a free open-source tool that runs AI coding agents under a separate user with a kernel sandbox and firewall, keeping SSH keys out of reach.

Signal Automates Encryption Checks With Key Transparency
Signal's Automatic Key Verification uses a key transparency log audited by Cloudflare and Trail of Bits to confirm chats without meeting in person.

Chainloop Signs Every Artifact Your CI Pipeline Builds
Chainloop is an open-source evidence store that collects, signs, and policy-checks CI output across 17 formats including CycloneDX and SPDX SBOMs.

Linux Kernel SCTP Fix Lands in All Stable Branches
An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

HTTP Terminator Hunts Request Smuggling Bugs With AI
PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Shieldstral Runs Multimodal Safety on One 16GB GPU
Mistral's Shieldstral is a 3B open-weight safety classifier covering 12 languages and images, taking plain-language policies at inference on a 16GB GPU.

OWASP Subtractive Security Scores What You Remove
OWASP launched a Subtractive Security Top 10 with nine platform lists and a Path Erasure Rate metric that counts attack paths deleted, not alerts raised.

NVIDIA SkillSpector Scans AI Agent Skills for Risk
NVIDIA's open-source SkillSpector checks AI agent skills for 64 vulnerability patterns before install, scoring risk 0-100 and exporting SARIF for CI.

CISA C4 Framework Scores Open Source Project Trust
CISA's new 35-page open source security guide introduces the C4 Framework — Code, Community, Controls, Continuity — plus SBOM and open AI model practices.

XM Cyber Open-Sources Three Exposure Hunting Tools
XM Cyber released three open-source tools on July 29 that hunt macOS XPC privilege escalation paths and overprivileged Oracle Cloud identities.

Open Secure AI Alliance Unites 40+ Firms on Defense
NVIDIA, Microsoft, IBM and 40+ others launched the Open Secure AI Alliance on July 27, pooling five open-source projects to defend AI agents.

Snowpick Open-Source Scanner Checks ServiceNow Exposure
Bishop Fox released Snowpick, a free Go tool that tests your own ServiceNow portal for unauthenticated data exposure across 26 table checks.

AI Agent Sandbox Design: 4 Lessons From New Research
Pillar Security's seven disclosures across Cursor, Codex CLI and Gemini CLI reveal four sandbox failure modes AI agent builders can design against.

Microsoft Dusseldorf Brings Open-Source OAST to Your Servers
Microsoft open-sourced Dusseldorf, a self-hosted OAST platform catching 4 blind bug classes while keeping callback data on your own servers.

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

VulnHunter Open-Sources Capital One's AI Bug Hunting
Capital One released VulnHunter under Apache 2.0 — an agentic security tool that traces exploit paths and tries to disprove its own findings first.

SingGuard-NSFA Brings Open Guardrails to AI Agents
Ant Group open-sourced SingGuard-NSFA under Apache 2.0 — four guardrail models covering 185 threat scenarios across 133 languages, free to download.

Rustinel Is a Fast Open-Source EDR Built in Rust
Rustinel, launched July 8, is an open-source endpoint detection tool in Rust that unifies Windows and Linux monitoring into one clean codebase.

CVE Lite CLI Scans npm Projects Right in Your Terminal
CVE Lite CLI, now an OWASP Incubator project, checks JavaScript lockfiles against the OSV database and suggests one-line fixes for npm, pnpm, Yarn, and Bun.

New Open-Source Tools Help Blue Teams Defend AI Agents
A fresh wave of open-source security tools gives blue teams free, community-built defense for the AI agent era, protecting the newest attack surface.

Kali Linux 2026.2 Ships New Tools and Faster Boots for Security Pros
Kali Linux 2026.2 adds nine open-source penetration testing tools, roughly 3x faster VM boot, and fresh desktops for defenders and learners.

New Open-Source Tools Help Defenders Secure AI Agents
June's open-source security roundup brings free tools for the AI-agent era: DockSec's AI-powered container fixes and detections for prompt injection.

Linux Foundation Launches Akrites to Defend Open Source From AI Threats
On June 25, 2026, the Linux Foundation and 20 industry leaders launched Akrites to find, fix, and disclose open-source vulnerabilities ahead of AI-enabled threats.

Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.

Filigran's XTM One Puts AI Agents to Work on Threat Exposure
Filigran's XTM One uses AI agents to automate the full threat-exposure lifecycle through plain language, with bring-your-own-LLM and air-gapped deployment support.

depthfirst's Dependency Firewall Blocks Malicious Packages Before They Install
Launched June 1, 2026, depthfirst's Dependency Firewall vets every open-source package before install — approving safe ones, quarantining the suspicious, and blocking the malicious.

Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.

Microsoft Open-Sources RAMPART and Clarity — A Safety-First Toolkit for AI Agent Development
Microsoft released RAMPART and Clarity as open-source tools on May 20, 2026 — operationalizing AI agent safety by turning red-team findings into repeatable tests and documenting design assumptions in agent workflows.

Microsoft Open-Sources the Agent Governance Toolkit: Runtime Security for Every AI Agent You Deploy
Microsoft's Agent Governance Toolkit is open-source runtime security for AI agents — covering all 10 OWASP agentic AI risks at sub-millisecond enforcement.

Cisco Releases DefenseClaw: Open-Source Framework for Securing AI Agents
Cisco unveils DefenseClaw at RSAC 2026, an open-source framework that scans AI agents for vulnerabilities across MCP tools and can quarantine threats in 2 seconds.

NVIDIA Open-Sources NemoClaw — A Security-First Stack for Deploying Autonomous AI Agents on Any Hardware
Built on the OpenClaw platform, NemoClaw bundles Nemotron models with sandboxed execution and privacy controls, enabling secure AI agent deployment from RTX laptops to DGX clusters.

OpenAI's Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Vulnerabilities in Open-Source Projects
The AI-powered security agent discovers critical bugs in OpenSSH, Chromium, PHP, and GnuTLS during its research preview, with false positive rates dropping 50% over 30 days.
