OpenSSF announces 15 new members to tackle supply chain security challengesHelp Net Security·May 11, 00:00 UTC · May 11, 2022Vulnerability55
Enhancing open source security: Insights from the OpenSSF on addressing key challengesHelp Net Security·May 18, 00:00 UTC · May 18, 2023Policy & legal55
OpenSSF adds new members from around the globe to improve OSS securityHelp Net Security·Apr 17, 12:42 UTC · Apr 17, 2026Vulnerability55
OpenSSF announces Alpha-Omega Project to improve global OSS supply chain securityHelp Net Security·Jan 19, 11:47 UTC · Jan 19, 2023Vulnerability55
Establishing a security baseline for open source projectsHelp Net Security·May 13, 00:00 UTC · May 13, 2024Vulnerability55
New 'Siren' mailing list aims to share threat intelligence for open source projectsThe Record·May 20, 14:20 UTC · May 20, 2024Exploit / PoC60
CISA and OpenSSF Release Framework for Package Repository SecurityThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability55
Google to create security team for open source projectsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability55
New Open Source Security Foundation wants to improve open source software securityHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2020Advisory55
Securing software repositories leads to better OSS securityHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2024Vulnerability55
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
Washington summit grapples with securing open source softwareCyberScoop·Sep 13, 13:30 UTC · Sep 13, 2023Exploit / PoC in the wild60
A 10-point plan to improve the security of open source softwareHelp Net Security·Jan 19, 11:46 UTC · Jan 19, 2023Vulnerability55
Big tech companies step in to support the open source security ecosystemHelp Net Security·Mar 18, 00:00 UTC · Mar 18, 2026Vulnerability55
Paid open-source maintainers spend more time on securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2024Vulnerability55
One-third of dev professionals unfamiliar with secure coding practicesHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2024Vulnerability55
Researchers stop ‘credible takeover attempt’ similar to XZ Utils backdoor incidentThe Record·Apr 15, 19:44 UTC · Apr 15, 2024Malware55
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Tech Giants Reveal RecordInfosecurity Magazine·Oct 11, 09:30 UTC · Oct 11, 2023Exploit / PoCCVE-2023-4448760
Week in review: KeePass vulnerability, Apple fixes exploited WebKit 0-daysHelp Net Security·May 21, 00:00 UTC · May 21, 2023Vulnerability in the wildCVE-2023-28204CVE-2023-32373CVE-2023-32409+1 CVEs60
Google offers $1 million sponsorship to secure open source softwareThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Vulnerability55
Google Pledges $1m to Secure Open Source ProjectInfosecurity Magazine·Oct 5, 09:48 UTC · Oct 5, 2021Vulnerability55
Critical open-source projects get a new security frameworkHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Vulnerability155
Cybersecurity Skills Framework connects the dots between IT job roles and the practical skills neededHelp Net Security·May 16, 00:00 UTC · May 16, 2025Vulnerability55
OpenJS Foundation Targeted in Potential JavaScript Project Takeover AttemptThe Hacker News·Apr 17, 05:00 UTC · Apr 17, 2024Vulnerability55
New open-source project takeover attacks spotted, stymiedHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2024Vulnerability55
CISA, NSA and npm Release Software Supply Chain GuidanceInfosecurity Magazine·Sep 2, 10:30 UTC · Sep 2, 2022Vulnerability55
Open Source Community Hands White House 10Infosecurity Magazine·May 13, 09:30 UTC · May 13, 2022Vulnerability55
Tech Giants to Team-Up on Open Source Security After White House MeetInfosecurity Magazine·Jan 14, 09:04 UTC · Jan 14, 2022Vulnerability55
Google underwrites two full-time maintainers for Linux kernel security developmentHelp Net Security·Feb 25, 00:00 UTC · Feb 25, 2021Vulnerability55
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC releasedHelp Net Security·Aug 2, 00:00 UTC · Aug 2, 2026Data breachCVE-2026-54121CVE-2026-63077CVE-2026-20316+1 CVEs60
NSA and CISA Urge Adoption of Memory Safe Languages for SafetyInfosecurity Magazine·Jun 25, 16:00 UTC · Jun 25, 2025Vulnerability55
What open source means for cybersecurityHelp Net Security·Apr 15, 11:46 UTC · Apr 15, 2025Vulnerability55
NCSC Urges Users to Patch Next.js Flaw ImmediatelyInfosecurity Magazine·Mar 31, 10:15 UTC · Mar 31, 2025VulnerabilityCVE-2025-2992760
Week in review: Botnet hits M365 accounts, PoC for Ivanti Endpoint Manager vulnerabilities releasedHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2025Exploit / PoCCVE-2024-13159CVE-2025-2336360
Security Risks Persist in Open Source EcosystemInfosecurity Magazine·Dec 4, 14:00 UTC · Dec 4, 2024Vulnerability55
Open source maintainers: Key to software health and securityHelp Net Security·Oct 21, 09:35 UTC · Oct 21, 2024Industry55
The number of Android memory safety vulnerabilities has tumbled, and here's whyHelp Net Security·Sep 26, 00:00 UTC · Sep 26, 2024Vulnerability55
DARPA awards $14 million to semifinal winners of AI code review competitionThe Record·Aug 14, 01:43 UTC · Aug 14, 2024Vulnerability55