Vet: Open-source software supply chain security toolHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2025Vulnerability42
Defense Unicorns raises $35 million to enhance national security through open-source softwareHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2024Industry55
EU Offering Bug Bounties on Critical Open-Source SoftwareSchneier on Security·Jan 27, 14:38 UTC · Jan 27, 2020Malware55
Following Log4j: Supporting the developer community to secure ITHelp Net Security·Nov 1, 00:00 UTC · Nov 1, 2022Vulnerability30
Securing software repositories leads to better OSS securityHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2024Vulnerability55
Lineaje OSM improves software supply chain securityHelp Net Security·May 2, 00:00 UTC · May 2, 2024Vulnerability55
Six-year old bug will likely live forever in Lenovo, Intel productsCyberScoop·Apr 11, 21:36 UTC · Apr 11, 2024Exploit / PoC60
Open-source supply chain attacks expand to the banking sectorThe Record·Jul 21, 19:49 UTC · Jul 21, 2023Vulnerability55
Researchers uncover rare, difficult-toCyberScoop·Jul 3, 00:04 UTC · Jul 3, 2024Exploit / PoCCVE-2024-638760
Senate Intel chair urges national cyber director to safeguard against openCyberScoop·Dec 18, 18:35 UTC · Dec 18, 2025Exploit / PoC in the wild60
New Hampshire set to pilot voting machines that use software everyone can seeThe Record·Dec 22, 00:00 UTC · Dec 22, 2022Policy & legal30
Enhancing open source security: Insights from the OpenSSF on addressing key challengesHelp Net Security·May 18, 00:00 UTC · May 18, 2023Policy & legal55
White House details ‘Gold Eagle’ clearinghouse for AI cyber threatsCyberScoop·Jul 14, 23:22 UTC · Jul 14, 2026Exploit / PoC in the wild60
How software development's speed obsession enabled TeamPCP’s chaos crusadeCyberScoop·Jun 18, 23:03 UTC · Jun 18, 2026Ransomware57
The hidden risks inside open-source codeHelp Net Security·Sep 30, 00:00 UTC · Sep 30, 2025Vulnerability55
CISA issues recommendations to federal agencies on openCyberScoop·Jul 30, 18:24 UTC · Jul 30, 2026Exploit / PoC in the wild60
Week in review: CISA releases RedEye, Apache Commons Text flaw, Medibank data breachHelp Net Security·Apr 12, 11:03 UTC · Apr 12, 2024Data breachCVE-2022-4288960
When transparency is also obscurity: The conundrum that is open-source securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2022Vulnerability55
LIVE Webinar: Key Lessons Learned from Major Cyberattacks in 2021 and What to Expect in 2022The Hacker News·Mar 2, 10:29 UTC · Mar 2, 2022Ransomware60
CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber ThreatsThe Hacker News·Dec 18, 15:14 UTC · Dec 18, 2023VulnerabilityCVE-2018-1337960
White House to study open source software in critical infrastructureCyberScoop·Aug 9, 20:50 UTC · Aug 9, 2024Exploit / PoC in the wild60
Tanium Software Bill of Materials identifies software supply-chain vulnerabilitiesHelp Net Security·Nov 3, 00:00 UTC · Nov 3, 2022Vulnerability42
CISA and OpenSSF Release Framework for Package Repository SecurityThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability55
CISA's new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bugCyberScoop·Feb 8, 18:22 UTC · Feb 8, 2022Exploit / PoC in the wild60
Week in review: New Black Basta's social engineering campaign, passing the CISSP exam in 6 weeksHelp Net Security·May 19, 00:00 UTC · May 19, 2024Threat actor in the wildCVE-2024-32002CVE-2024-4947CVE-2024-30051+3 CVEs160
CISA advisory committee approves four draft reports on critical infrastructure resilienceCyberScoop·Oct 11, 21:38 UTC · Oct 11, 2024Advisory in the wild60
White House, CISA call for help with security of open source softwareThe Record·Aug 11, 14:54 UTC · Aug 11, 2023Vulnerability55
Iranian hackers use Log4Shell to mine crypto on federal computer systemCyberScoop·Nov 16, 23:37 UTC · Nov 16, 2022Ransomware in the wild60
40 Open-Source Tools Redefining How Security Teams Secure The StackHelp Net Security·Dec 11, 00:00 UTC · Dec 11, 2025Vulnerability42
What closed-source software developers can learn from their open-source counterpartsHelp Net Security·Jun 1, 12:28 UTC · Jun 1, 2023Malware30
Zarf: Open-source continuous software delivery on disconnected networksHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2024Policy & legal30
In studying tech supply chain, feds cite open source products, device firmwareCyberScoop·Feb 25, 15:08 UTC · Feb 25, 2022Ransomware in the wild60
Cybersecurity in the Age of Instant SoftwareSchneier on Security·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability55
Hopper Security emerges from stealth to fix open-source security problemsHelp Net Security·Apr 29, 00:00 UTC · Apr 29, 2025Vulnerability30
How GitHub untangled itself from the ‘Octopus’ malware that infected 26 software projectsCyberScoop·May 29, 19:51 UTC · May 29, 2020Malware in the wild160
20 Free Cybersecurity Tools You Might Have MissedHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2024Ransomware60
Out-of-bounds read vulnerability in NVIDIA driver; Open-source flashcard software contains multiple security issuesCisco Talos·Jul 31, 18:09 UTC · Jul 31, 2024VulnerabilityCVE-2024-0107CVE-2024-32152CVE-2024-29073+2 CVEs135
A little-known npm package was North Korea’s warmCyberScoop·Jul 29, 21:09 UTC · Jul 29, 2026Exploit / PoC in the wild60
Biden administration pledges $11 million to open source security initiativeThe Record·Aug 13, 17:39 UTC · Aug 13, 2024Vulnerability55
Invicti SCA enables users to track and secure open-source componentsHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2022Vulnerability30