Open-source security is posing challenges governments can't easily solveCyberScoop·Jun 24, 13:45 UTC · Jun 24, 2026Vulnerability55
White House releases report on securing openCyberScoop·Jan 30, 21:09 UTC · Jan 30, 2024Exploit / PoC in the wild60
Establishing a security baseline for open source projectsHelp Net Security·May 13, 00:00 UTC · May 13, 2024Vulnerability55
Open-source software holds the key to solving Log4Shell-like problemsHelp Net Security·Dec 22, 00:00 UTC · Dec 22, 2021Exploit / PoC in the wild60
New security concerns for the open-source software supply chainHelp Net Security·Oct 17, 00:00 UTC · Oct 17, 2022Vulnerability55
White House hosts open-source software security summit in light of expansive Log4j flawCyberScoop·Jan 13, 14:08 UTC · Jan 13, 2022Exploit / PoC in the wild60
Senate panel approves open-source software bill, though future unclearThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Policy & legal55
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60
Rocket Support for Zowe enables developers to modernize and accelerate mainframe app developmentHelp Net Security·Sep 15, 00:00 UTC · Sep 15, 2022Vulnerability55
Supply Chain Attacks or Vulnerabilities Experienced by 80% of Orgs, BlackBerry FindsInfosecurity Magazine·Oct 26, 13:02 UTC · Oct 26, 2022Vulnerability55
Open-source software’s archenemy TeamPCP goes back further than anyone thoughtCyberScoop·Aug 5, 13:00 UTC · Aug 5, 2026Exploit / PoC in the wild60
Hackers target AI and crypto as software supply chain risks growHelp Net Security·Dec 3, 14:29 UTC · Dec 3, 2025Vulnerability in the wild60
Protect AI introduces three open-source software tools designed to secure AI/ML environmentsHelp Net Security·Oct 5, 00:00 UTC · Oct 5, 2023Vulnerability55
Microsoft pushes open-source software kit to election agencies, votingCyberScoop·May 7, 01:14 UTC · May 7, 2019Exploit / PoC in the wild60
Trends and dangers in open-source software dependenciesHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2024Vulnerability155
How businesses can bolster their cybersecurity defenses with open sourceHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability55
Developer Sabotages Open-Source Software PackageSchneier on Security·Mar 22, 17:04 UTC · Mar 22, 2022Vulnerability55
Debunking myths about open-source securityHelp Net Security·Nov 20, 00:00 UTC · Nov 20, 2024Vulnerability55
Ubuntu Pro: Comprehensive subscription for open-source software securityHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability55
Defense Unicorns raises $35 million to enhance national security through open-source softwareHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2024Industry55
EU Offering Bug Bounties on Critical Open-Source SoftwareSchneier on Security·Jan 27, 14:38 UTC · Jan 27, 2020Malware55
Securing software repositories leads to better OSS securityHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2024Vulnerability55
Lineaje OSM improves software supply chain securityHelp Net Security·May 2, 00:00 UTC · May 2, 2024Vulnerability55
Six-year old bug will likely live forever in Lenovo, Intel productsCyberScoop·Apr 11, 21:36 UTC · Apr 11, 2024Exploit / PoC60
Open-source supply chain attacks expand to the banking sectorThe Record·Jul 21, 19:49 UTC · Jul 21, 2023Vulnerability55
Researchers uncover rare, difficult-toCyberScoop·Jul 3, 00:04 UTC · Jul 3, 2024Exploit / PoCCVE-2024-638760
Senate Intel chair urges national cyber director to safeguard against openCyberScoop·Dec 18, 18:35 UTC · Dec 18, 2025Exploit / PoC in the wild60
Enhancing open source security: Insights from the OpenSSF on addressing key challengesHelp Net Security·May 18, 00:00 UTC · May 18, 2023Policy & legal55
White House details ‘Gold Eagle’ clearinghouse for AI cyber threatsCyberScoop·Jul 14, 23:22 UTC · Jul 14, 2026Exploit / PoC in the wild60
The hidden risks inside open-source codeHelp Net Security·Sep 30, 00:00 UTC · Sep 30, 2025Vulnerability55
CISA issues recommendations to federal agencies on openCyberScoop·Jul 30, 18:24 UTC · Jul 30, 2026Exploit / PoC in the wild60
Week in review: CISA releases RedEye, Apache Commons Text flaw, Medibank data breachHelp Net Security·Apr 12, 11:03 UTC · Apr 12, 2024Data breachCVE-2022-4288960
When transparency is also obscurity: The conundrum that is open-source securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2022Vulnerability55
LIVE Webinar: Key Lessons Learned from Major Cyberattacks in 2021 and What to Expect in 2022The Hacker News·Mar 2, 10:29 UTC · Mar 2, 2022Ransomware60
CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber ThreatsThe Hacker News·Dec 18, 15:14 UTC · Dec 18, 2023VulnerabilityCVE-2018-1337960
White House to study open source software in critical infrastructureCyberScoop·Aug 9, 20:50 UTC · Aug 9, 2024Exploit / PoC in the wild60
CISA and OpenSSF Release Framework for Package Repository SecurityThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability55
CISA's new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bugCyberScoop·Feb 8, 18:22 UTC · Feb 8, 2022Exploit / PoC in the wild60
Week in review: New Black Basta's social engineering campaign, passing the CISSP exam in 6 weeksHelp Net Security·May 19, 00:00 UTC · May 19, 2024Threat actor in the wildCVE-2024-32002CVE-2024-4947CVE-2024-30051+3 CVEs160