Hottest cybersecurity open-source tools of the month: November 2025Help Net Security·Nov 27, 00:00 UTC · Nov 27, 2025Exploit / PoC57
White House releases report on securing openCyberScoop·Jan 30, 21:09 UTC · Jan 30, 2024Exploit / PoC in the wild60
Securing open-source code supply chains may help prevent the next big cyberattackHelp Net Security·Nov 24, 00:00 UTC · Nov 24, 2021Exploit / PoC57
Open-source software holds the key to solving Log4Shell-like problemsHelp Net Security·Dec 22, 00:00 UTC · Dec 22, 2021Exploit / PoC in the wild60
20 cybersecurity projects on GitHub you should check outHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2023Exploit / PoC45
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60
Sandyaa: Open-source autonomous security bug hunterHelp Net Security·May 13, 00:00 UTC · May 13, 2026Exploit / PoC45
APTRS: Open-source automated penetration testing reporting systemHelp Net Security·Apr 9, 00:00 UTC · Apr 9, 2025Exploit / PoC145
Open-source security spat leads companies to join forces for new toolCyberScoop·Jan 27, 15:29 UTC · Jan 27, 2025Exploit / PoC in the wild60
Fleet: Open-source platform for IT and security teamsHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2025Exploit / PoC45
Evilginx: Open-source man-in-the-middle attack frameworkHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2024Exploit / PoC60
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious PurposesPalo Alto Unit 42·Jun 6, 01:14 UTC · Jun 6, 2024Exploit / PoCCVE-2017-9506CVE-2017-12629CVE-2019-2767+23 CVEs60
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Lyrie: Open-source autonomous pentesting agentHelp Net Security·May 18, 00:00 UTC · May 18, 2026Exploit / PoC45
Commix: Open-source OS command injection exploitation toolHelp Net Security·Apr 2, 08:47 UTC · Apr 2, 2025Exploit / PoC45
New hacker group uses open-source tools to spy on entities in AsiaThe Record·Jul 18, 12:25 UTC · Jul 18, 2024Exploit / PoC60
Secator: Open-source pentesting Swiss army knifeHelp Net Security·Jul 3, 00:00 UTC · Jul 3, 2024Exploit / PoC57
CVEMap: Open-source tool to query, browse and search CVEsHelp Net Security·Mar 25, 17:03 UTC · Mar 25, 2024Exploit / PoC in the wild60
CI Fuzz CLI: Open-source tool to test Java apps for unexpected behaviorsHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2022Exploit / PoC60
PentAGI: Open-source autonomous AI penetration testing systemHelp Net Security·Apr 22, 00:00 UTC · Apr 22, 2026Exploit / PoC60
BlacksmithAI: Open-source AI-powered penetration testing frameworkHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2026Exploit / PoC145
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
Zen-AI-Pentest: Open-source AI-powered penetration testing frameworkHelp Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Exploit / PoC45
Senate Intel chair urges national cyber director to safeguard against openCyberScoop·Dec 18, 18:35 UTC · Dec 18, 2025Exploit / PoC in the wild60
Strix: Open-source AI agents for penetration testingHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Exploit / PoC45
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
AWS Kill Switch: Open-source incident response toolHelp Net Security·Apr 19, 15:21 UTC · Apr 19, 2024Exploit / PoC45
Six-year old bug will likely live forever in Lenovo, Intel productsCyberScoop·Apr 11, 21:36 UTC · Apr 11, 2024Exploit / PoC60
AuthLogParser: Open-source tool for analyzing Linux authentication logsHelp Net Security·Apr 9, 17:29 UTC · Apr 9, 2024Exploit / PoC45
Drozer: Open-source Android security assessment frameworkHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2024Exploit / PoC45
White House hosts open-source software security summit in light of expansive Log4j flawCyberScoop·Jan 13, 14:08 UTC · Jan 13, 2022Exploit / PoC in the wild60
Microsoft pushes open-source software kit to election agencies, votingCyberScoop·May 7, 01:14 UTC · May 7, 2019Exploit / PoC in the wild60
Open-source software’s archenemy TeamPCP goes back further than anyone thoughtCyberScoop·Aug 5, 13:00 UTC · Aug 5, 2026Exploit / PoC in the wild60
CISA issues recommendations to federal agencies on openCyberScoop·Jul 30, 18:24 UTC · Jul 30, 2026Exploit / PoC in the wild60
Microsoft, tech companies throw weight behind spread of openCyberScoop·Jul 24, 15:22 UTC · Jul 24, 2026Exploit / PoC in the wild60
Hackers turn open-source AI framework into global cryptojacking operationCyberScoop·Nov 19, 15:29 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2023-48022160
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
Using an agent for the Mythic framework: pros and cons in pentestingKaspersky Securelist·May 13, 10:00 UTC · May 13, 2025Exploit / PoC60