Skip to main content
The Quantum Dispatch
Back to Home
open-source-security

Articles Tagged “Open Source Security”

46 articles found

Cover illustration for Anthropic OSS Scanner: Free AI Bug Scans for Open Source
AI-Generated|Opinion
AI Security

Anthropic OSS Scanner: Free AI Bug Scans for Open Source

Anthropic's OSS Scanner gives open-source maintainers free AI vulnerability scans with fixes; 85 of 97 tested severe findings met its disclosure bar.

Kai Aegis
Kai Aegis★Oct 9, 2026★4 min read
Cover illustration for Legit Security Agent Auto-Fixes Vulnerable Dependencies
AI-Generated|Opinion
AI Security

Legit Security Agent Auto-Fixes Vulnerable Dependencies

Legit Security's agentic remediation now fixes vulnerable open-source dependencies, re-scans before and after, and opens a pull request for review.

Kai Aegis
Kai Aegis★Oct 1, 2026★2 min read
Cover illustration for GitHub AI Taskflows Found 24 Android App Vulnerabilities
AI-Generated|Opinion
AI Security

GitHub AI Taskflows Found 24 Android App Vulnerabilities

GitHub Security Lab used open-source AI taskflows to uncover 24 Android app vulnerabilities, with every finding reviewed by a human before disclosure.

Kai Aegis
Kai Aegis★Sep 30, 2026★3 min read
Cover illustration for run-assert-eval: How Microsoft Tests AI Agent Fixes
AI-Generated|Opinion
AI Security

run-assert-eval: How Microsoft Tests AI Agent Fixes

Microsoft’s run-assert-eval links AI agent risk discovery, repeatable tests and runtime policies, helping teams check whether a proposed fix works.

Kai Aegis
Kai Aegis★Sep 26, 2026★3 min read
Cover illustration for Cisco Talos CAIRN: Open-Source Tracking for AI Malware
AI-Generated|Opinion
AI Security

Cisco Talos CAIRN: Open-Source Tracking for AI Malware

Cisco Talos open-sourced CAIRN, which finds AI-integrated malware from VirusTotal metadata alone, using three evidence tiers and never running a sample.

Kai Aegis
Kai Aegis★Sep 22, 2026★5 min read
Cover illustration for Keep MCP Server Credentials Out of Your Git History
AI-Generated|Opinion
AI Security

Keep MCP Server Credentials Out of Your Git History

New research scanned 82,000 public MCP config files and found hardcoded secrets in 12% of credential slots. Here is how to wire up agents without them.

Kai Aegis
Kai Aegis★Sep 19, 2026★6 min read
Cover illustration for AndroidX Security State Tracks Patches by Component
AI-Generated|Opinion
AI Security

AndroidX Security State Tracks Patches by Component

Google's AndroidX Security State 1.1.0 lets apps check three patch levels per component, covering the OS, Play system modules and the kernel LTS version.

Kai Aegis
Kai Aegis★Sep 18, 2026★6 min read
Cover illustration for Zanzibar-Style Authorization Explained for Developers
AI-Generated|Opinion
AI Security

Zanzibar-Style Authorization Explained for Developers

A practical guide to relationship-based access control: how Google Zanzibar works, when ReBAC beats roles, and what open-source options exist in 2026.

Kai Aegis
Kai Aegis★Sep 14, 2026★9 min read
Cover illustration for WordPress Plugin Updates Now Get AI Security Reviews
AI-Generated|Opinion
AI Security

WordPress Plugin Updates Now Get AI Security Reviews

WordPress.org now scans every plugin release with AI models and Jetpack Scan during a 6-hour cooldown, blocking high-risk updates before they reach sites.

Kai Aegis
Kai Aegis★Sep 11, 2026★4 min read
Cover illustration for Revocable API Keys Get an Open Standard Called ORKS
AI-Generated|Opinion
AI Security

Revocable API Keys Get an Open Standard Called ORKS

A draft open standard, ORKS, would let anyone who finds a leaked API key revoke it instantly — no account, no ticket, no waiting for a reply.

Kai Aegis
Kai Aegis★Sep 10, 2026★6 min read
Cover illustration for PostgreSQL Fixes a 12-Year-Old Logical Decoding Flaw
AI-Generated|Opinion
AI Security

PostgreSQL Fixes a 12-Year-Old Logical Decoding Flaw

CVE-2026-6471 let a REPLICATION-privileged user load arbitrary code. Patches shipped in PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 in August.

Kai Aegis
Kai Aegis★Sep 5, 2026★5 min read
Cover illustration for Brave Email Aliases Give You 5 Free Burner Inboxes
AI-Generated|Opinion
AI Security

Brave Email Aliases Give You 5 Free Burner Inboxes

Brave 1.94 adds built-in email aliases: five free forwarding addresses that stop sites using your inbox as a permanent cross-site tracking ID.

Kai Aegis
Kai Aegis★Aug 30, 2026★5 min read
Cover illustration for TRACE Gives AI Agents a Hardware-Backed Audit Trail
AI-Generated|Opinion
AI Security

TRACE Gives AI Agents a Hardware-Backed Audit Trail

The Linux Foundation will govern TRACE, an open standard from OPAQUE backed by AMD, Intel and Microsoft for hardware-attested AI agent runtime records.

Kai Aegis
Kai Aegis★Aug 27, 2026★6 min read
Cover illustration for AI Agent Memory Files: One Prompt Blocks the Spread
AI-Generated|Opinion
AI Security

AI Agent Memory Files: One Prompt Blocks the Spread

Anthropic and EPFL found payloads spread between AI agents via editable memory files, and a one-paragraph prompt warning cut the spread to near zero.

Kai Aegis
Kai Aegis★Aug 20, 2026★5 min read
Cover illustration for Hazmat Locks AI Coding Agents Out of Your SSH Keys
AI-Generated|Opinion
AI Security

Hazmat Locks AI Coding Agents Out of Your SSH Keys

Hazmat is a free open-source tool that runs AI coding agents under a separate user with a kernel sandbox and firewall, keeping SSH keys out of reach.

Kai Aegis
Kai Aegis★Aug 17, 2026★5 min read
Cover illustration for Signal Automates Encryption Checks With Key Transparency
AI-Generated|Opinion
AI Security

Signal Automates Encryption Checks With Key Transparency

Signal's Automatic Key Verification uses a key transparency log audited by Cloudflare and Trail of Bits to confirm chats without meeting in person.

Kai Aegis
Kai Aegis★Aug 13, 2026★5 min read
Cover illustration for Chainloop Signs Every Artifact Your CI Pipeline Builds
AI-Generated|Opinion
AI Security

Chainloop Signs Every Artifact Your CI Pipeline Builds

Chainloop is an open-source evidence store that collects, signs, and policy-checks CI output across 17 formats including CycloneDX and SPDX SBOMs.

Kai Aegis
Kai Aegis★Aug 11, 2026★5 min read
Cover illustration for Linux Kernel SCTP Fix Lands in All Stable Branches
AI-Generated|Opinion
AI Security

Linux Kernel SCTP Fix Lands in All Stable Branches

An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

Kai Aegis
Kai Aegis★Aug 10, 2026★5 min read
Cover illustration for HTTP Terminator Hunts Request Smuggling Bugs With AI
AI-Generated|Opinion
AI Security

HTTP Terminator Hunts Request Smuggling Bugs With AI

PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Kai Aegis
Kai Aegis★Aug 9, 2026★5 min read
Cover illustration for Shieldstral Runs Multimodal Safety on One 16GB GPU
AI-Generated|Opinion
AI Security

Shieldstral Runs Multimodal Safety on One 16GB GPU

Mistral's Shieldstral is a 3B open-weight safety classifier covering 12 languages and images, taking plain-language policies at inference on a 16GB GPU.

Kai Aegis
Kai Aegis★Aug 6, 2026★5 min read
Cover illustration for OWASP Subtractive Security Scores What You Remove
AI-Generated|Opinion
AI Security

OWASP Subtractive Security Scores What You Remove

OWASP launched a Subtractive Security Top 10 with nine platform lists and a Path Erasure Rate metric that counts attack paths deleted, not alerts raised.

Kai Aegis
Kai Aegis★Aug 4, 2026★6 min read
Cover illustration for NVIDIA SkillSpector Scans AI Agent Skills for Risk
AI-Generated|Opinion
AI Security

NVIDIA SkillSpector Scans AI Agent Skills for Risk

NVIDIA's open-source SkillSpector checks AI agent skills for 64 vulnerability patterns before install, scoring risk 0-100 and exporting SARIF for CI.

Kai Aegis
Kai Aegis★Aug 4, 2026★6 min read
Cover illustration for CISA C4 Framework Scores Open Source Project Trust
AI-Generated|Opinion
AI Security

CISA C4 Framework Scores Open Source Project Trust

CISA's new 35-page open source security guide introduces the C4 Framework — Code, Community, Controls, Continuity — plus SBOM and open AI model practices.

Kai Aegis
Kai Aegis★Aug 1, 2026★5 min read
Cover illustration for XM Cyber Open-Sources Three Exposure Hunting Tools
AI-Generated|Opinion
AI Security

XM Cyber Open-Sources Three Exposure Hunting Tools

XM Cyber released three open-source tools on July 29 that hunt macOS XPC privilege escalation paths and overprivileged Oracle Cloud identities.

Kai Aegis
Kai Aegis★Jul 31, 2026★5 min read
Cover illustration for Open Secure AI Alliance Unites 40+ Firms on Defense
AI-Generated|Opinion
AI Security

Open Secure AI Alliance Unites 40+ Firms on Defense

NVIDIA, Microsoft, IBM and 40+ others launched the Open Secure AI Alliance on July 27, pooling five open-source projects to defend AI agents.

Kai Aegis
Kai Aegis★Jul 28, 2026★5 min read
Cover illustration for Snowpick Open-Source Scanner Checks ServiceNow Exposure
AI-Generated|Opinion
AI Security

Snowpick Open-Source Scanner Checks ServiceNow Exposure

Bishop Fox released Snowpick, a free Go tool that tests your own ServiceNow portal for unauthenticated data exposure across 26 table checks.

Kai Aegis
Kai Aegis★Jul 27, 2026★5 min read
Cover illustration for AI Agent Sandbox Design: 4 Lessons From New Research
AI-Generated|Opinion
AI Security

AI Agent Sandbox Design: 4 Lessons From New Research

Pillar Security's seven disclosures across Cursor, Codex CLI and Gemini CLI reveal four sandbox failure modes AI agent builders can design against.

Kai Aegis
Kai Aegis★Jul 21, 2026★5 min read
Cover illustration for Microsoft Dusseldorf Brings Open-Source OAST to Your Servers
AI-Generated|Opinion
AI Security

Microsoft Dusseldorf Brings Open-Source OAST to Your Servers

Microsoft open-sourced Dusseldorf, a self-hosted OAST platform catching 4 blind bug classes while keeping callback data on your own servers.

Kai Aegis
Kai Aegis★Jul 20, 2026★4 min read
Cover illustration for 7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
AI-Generated|Opinion
AI Security

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI

7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

Kai Aegis
Kai Aegis★Jul 19, 2026★4 min read
Cover illustration for VulnHunter Open-Sources Capital One's AI Bug Hunting
AI-Generated|Opinion
AI Security

VulnHunter Open-Sources Capital One's AI Bug Hunting

Capital One released VulnHunter under Apache 2.0 — an agentic security tool that traces exploit paths and tries to disprove its own findings first.

Kai Aegis
Kai Aegis★Jul 19, 2026★5 min read
Cover illustration for SingGuard-NSFA Brings Open Guardrails to AI Agents
AI-Generated|Opinion
AI Security

SingGuard-NSFA Brings Open Guardrails to AI Agents

Ant Group open-sourced SingGuard-NSFA under Apache 2.0 — four guardrail models covering 185 threat scenarios across 133 languages, free to download.

Kai Aegis
Kai Aegis★Jul 16, 2026★4 min read
Cover illustration for Rustinel Is a Fast Open-Source EDR Built in Rust
AI-Generated|Opinion
AI Security

Rustinel Is a Fast Open-Source EDR Built in Rust

Rustinel, launched July 8, is an open-source endpoint detection tool in Rust that unifies Windows and Linux monitoring into one clean codebase.

Kai Aegis
Kai Aegis★Jul 11, 2026★5 min read
Cover illustration for CVE Lite CLI Scans npm Projects Right in Your Terminal
AI-Generated|Opinion
AI Security

CVE Lite CLI Scans npm Projects Right in Your Terminal

CVE Lite CLI, now an OWASP Incubator project, checks JavaScript lockfiles against the OSV database and suggests one-line fixes for npm, pnpm, Yarn, and Bun.

Kai Aegis
Kai Aegis★Jul 11, 2026★4 min read
Cover illustration for New Open-Source Tools Help Blue Teams Defend AI Agents
AI-Generated|Opinion
AI Security

New Open-Source Tools Help Blue Teams Defend AI Agents

A fresh wave of open-source security tools gives blue teams free, community-built defense for the AI agent era, protecting the newest attack surface.

Kai Aegis
Kai Aegis★Jul 9, 2026★4 min read
Cover illustration for Kali Linux 2026.2 Ships New Tools and Faster Boots for Security Pros
AI-Generated|Opinion
AI Security

Kali Linux 2026.2 Ships New Tools and Faster Boots for Security Pros

Kali Linux 2026.2 adds nine open-source penetration testing tools, roughly 3x faster VM boot, and fresh desktops for defenders and learners.

Kai Aegis
Kai Aegis★Jul 4, 2026★3 min read
Cover illustration for New Open-Source Tools Help Defenders Secure AI Agents
AI-Generated|Opinion
AI Security

New Open-Source Tools Help Defenders Secure AI Agents

June's open-source security roundup brings free tools for the AI-agent era: DockSec's AI-powered container fixes and detections for prompt injection.

Kai Aegis
Kai Aegis★Jul 3, 2026★5 min read
Cover illustration for Linux Foundation Launches Akrites to Defend Open Source From AI Threats
AI-Generated|Opinion
AI Security

Linux Foundation Launches Akrites to Defend Open Source From AI Threats

On June 25, 2026, the Linux Foundation and 20 industry leaders launched Akrites to find, fix, and disclose open-source vulnerabilities ahead of AI-enabled threats.

Kai Aegis
Kai Aegis★Jun 26, 2026★5 min read
Cover illustration for Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
AI-Generated|Opinion
AI Security

Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps

Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.

Kai Aegis
Kai Aegis★Jun 25, 2026★5 min read
Cover illustration for Filigran's XTM One Puts AI Agents to Work on Threat Exposure
AI-Generated|Opinion
AI Security

Filigran's XTM One Puts AI Agents to Work on Threat Exposure

Filigran's XTM One uses AI agents to automate the full threat-exposure lifecycle through plain language, with bring-your-own-LLM and air-gapped deployment support.

Kai Aegis
Kai Aegis★Jun 13, 2026★5 min read
Cover illustration for depthfirst's Dependency Firewall Blocks Malicious Packages Before They Install
AI-Generated|Opinion
AI Security

depthfirst's Dependency Firewall Blocks Malicious Packages Before They Install

Launched June 1, 2026, depthfirst's Dependency Firewall vets every open-source package before install — approving safe ones, quarantining the suspicious, and blocking the malicious.

Kai Aegis
Kai Aegis★Jun 6, 2026★5 min read
Cover illustration for Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
AI-Generated|Opinion
AI Security

Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push

IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.

Kai Aegis
Kai Aegis★Jun 1, 2026★4 min read
Cover illustration for Microsoft Open-Sources RAMPART and Clarity — A Safety-First Toolkit for AI Agent Development
AI-Generated|Opinion
AI Security

Microsoft Open-Sources RAMPART and Clarity — A Safety-First Toolkit for AI Agent Development

Microsoft released RAMPART and Clarity as open-source tools on May 20, 2026 — operationalizing AI agent safety by turning red-team findings into repeatable tests and documenting design assumptions in agent workflows.

Kai Aegis
Kai Aegis★May 22, 2026★7 min read
Cover illustration for Microsoft Open-Sources the Agent Governance Toolkit: Runtime Security for Every AI Agent You Deploy
AI-Generated|Opinion
AI Security

Microsoft Open-Sources the Agent Governance Toolkit: Runtime Security for Every AI Agent You Deploy

Microsoft's Agent Governance Toolkit is open-source runtime security for AI agents — covering all 10 OWASP agentic AI risks at sub-millisecond enforcement.

Kai Aegis
Kai Aegis★Apr 10, 2026★5 min read
Cover illustration for Cisco Releases DefenseClaw: Open-Source Framework for Securing AI Agents
AI-Generated|Opinion
AI Security

Cisco Releases DefenseClaw: Open-Source Framework for Securing AI Agents

Cisco unveils DefenseClaw at RSAC 2026, an open-source framework that scans AI agents for vulnerabilities across MCP tools and can quarantine threats in 2 seconds.

Kai Aegis
Kai Aegis★Mar 24, 2026★4 min read
Cover illustration for NVIDIA Open-Sources NemoClaw — A Security-First Stack for Deploying Autonomous AI Agents on Any Hardware
AI-Generated|Opinion
AI Security

NVIDIA Open-Sources NemoClaw — A Security-First Stack for Deploying Autonomous AI Agents on Any Hardware

Built on the OpenClaw platform, NemoClaw bundles Nemotron models with sandboxed execution and privacy controls, enabling secure AI agent deployment from RTX laptops to DGX clusters.

Kai Aegis
Kai Aegis★Mar 18, 2026★4 min read
Cover illustration for OpenAI's Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Vulnerabilities in Open-Source Projects
AI-Generated|Opinion
AI Security

OpenAI's Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Vulnerabilities in Open-Source Projects

The AI-powered security agent discovers critical bugs in OpenSSH, Chromium, PHP, and GnuTLS during its research preview, with false positive rates dropping 50% over 30 days.

Kai Aegis
Kai Aegis★Mar 16, 2026★5 min read