Week in review: 0-days exploited in Palo Alto Networks firewalls, two unknown Linux backdoors identifiedHelp Net Security·Nov 24, 00:00 UTC · Nov 24, 2024Malware in the wildCVE-2024-0012CVE-2024-9474CVE-2024-44309+2 CVEs60
Big tech companies step in to support the open source security ecosystemHelp Net Security·Mar 18, 00:00 UTC · Mar 18, 2026Vulnerability55
GitHub CISO on security strategy and collaborating with the open-source communityHelp Net Security·Jan 13, 00:00 UTC · Jan 13, 2025Vulnerability55
HackerOne updates Internet Bug Bounty program to improve the security of open source softwareHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2021Vulnerability55
EU unveils tech sovereignty package to cut reliance on US, Chinese suppliersThe Record·Jun 5, 13:43 UTC · Jun 5, 2026Vulnerability55
Open source security platform Snyk raises $7 million in Series A funding roundCyberScoop·Mar 6, 15:36 UTC · Mar 6, 2018Exploit / PoC in the wild60
iTerm2 macOS Terminal App is affected by a critical RCE since 2012Security Affairs·Oct 10, 06:56 UTC · Oct 10, 2019VulnerabilityCVE-2019-953560
Week in review: ScreenConnect servers open to attack, exploited Microsoft SharePoint flawHelp Net Security·Mar 22, 00:00 UTC · Mar 22, 2026Ransomware in the wildCVE-2026-20963CVE-2026-3564CVE-2026-2013160
Washington summit grapples with securing open source softwareCyberScoop·Sep 13, 13:30 UTC · Sep 13, 2023Exploit / PoC in the wild60
The US NSA is using Anthropic's Claude Mythos despite supply chain riskSecurity Affairs·Apr 21, 10:27 UTC · Apr 21, 2026Vulnerability55
Project Glasswing powered by Claude Mythos: defending software before hackers doSecurity Affairs·Apr 8, 11:18 UTC · Apr 8, 2026Vulnerability55
Paid open-source maintainers spend more time on securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2024Vulnerability55
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
ARMO raises $30 million to offer a complete open source security solution for the Kubernetes communityHelp Net Security·Jan 10, 13:59 UTC · Jan 10, 2024Vulnerability55
Bill proposes new DHS centers for testing security of critical government techThe Record·Apr 25, 19:45 UTC · Apr 25, 2023Policy & legal55
How businesses can bolster their cybersecurity defenses with open sourceHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability55
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60
Critical open-source projects get a new security frameworkHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Vulnerability155
7-Year-Old Critical RCE Flaw Found in Popular iTerm2 macOS Terminal AppThe Hacker News·Oct 9, 18:38 UTC · Oct 9, 2019VulnerabilityCVE-2019-953560
Snyk gets $22 million for platform that tracks security flaws in open source projectsCyberScoop·Sep 25, 15:27 UTC · Sep 25, 2018Data breach in the wild60
#SOOCon23: UK Government Urges Industry Input on Software Security PolicyInfosecurity Magazine·Feb 8, 14:00 UTC · Feb 8, 2023Vulnerability55
Defense Unicorns raises $35 million to enhance national security through open-source softwareHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2024Industry55
Finding Vulnerabilities in Open Source ProjectsSchneier on Security·Feb 2, 16:01 UTC · Feb 2, 2022Vulnerability55
New open-source project takeover attacks spotted, stymiedHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2024Vulnerability55
Critical RCE vulnerabilities found in git (CVE-2022-41903, CVE-2022-23251)Help Net Security·Jan 19, 00:00 UTC · Jan 19, 2023VulnerabilityCVE-2022-41903CVE-2022-23251CVE-2022-4195360
Establishing a security baseline for open source projectsHelp Net Security·May 13, 00:00 UTC · May 13, 2024Vulnerability55
ForAllSecure raises $21 million to secure open source projects used by businesses around the worldHelp Net Security·Mar 22, 00:00 UTC · Mar 22, 2022Vulnerability55
Critical command execution vulnerability in iTerm2 patched, upgrade ASAP!Help Net Security·Oct 10, 00:00 UTC · Oct 10, 2019VulnerabilityCVE-2019-953560
Google to create security team for open source projectsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability55
Cape Privacy launches open source platform and raises $5M in seed fundingHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2020Policy & legal55
Week in review: Kali Linux evolution, ransomware getting more fearsomeHelp Net Security·Mar 8, 00:00 UTC · Mar 8, 2020Ransomware60
Backdoor in XZ Utils That Almost HappenedSchneier on Security·Apr 15, 00:00 UTC · Apr 15, 2024Malware155
Kali Linux evolution: What's next for the open source pentesting Linux distro?Help Net Security·Mar 2, 00:00 UTC · Mar 2, 2020Policy & legal55
Open-source security is posing challenges governments can't easily solveCyberScoop·Jun 24, 13:45 UTC · Jun 24, 2026Vulnerability55
VeraCrypt Audit Reveals Critical Security Flaws — Update NowThe Hacker News·Oct 18, 12:01 UTC · Oct 18, 2016Vulnerability55
OpenAI wants AI to fix vulnerabilities, not just find themHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2026Vulnerability55
DHS Cyber Safety Review Board found no evidence China knew of Log4j before disclosureCyberScoop·Jul 14, 14:30 UTC · Jul 14, 2022Exploit / PoC in the wild60
Seal Security raises $7.4 million to secure open source with GenAIHelp Net Security·Feb 14, 00:00 UTC · Feb 14, 2024Vulnerability55
DHS Releases Report into Log4j Vulnerabilities and ResponseInfosecurity Magazine·Jul 15, 17:19 UTC · Jul 15, 2022Vulnerability55
A 10-point plan to improve the security of open source softwareHelp Net Security·Jan 19, 11:46 UTC · Jan 19, 2023Vulnerability55