OpenSSF announces 15 new members to tackle supply chain security challengesHelp Net Security·May 11, 00:00 UTC · May 11, 2022Vulnerability55
Enhancing open source security: Insights from the OpenSSF on addressing key challengesHelp Net Security·May 18, 00:00 UTC · May 18, 2023Policy & legal55
OpenSSF adds new members from around the globe to improve OSS securityHelp Net Security·Apr 17, 12:42 UTC · Apr 17, 2026Vulnerability55
OpenSSF announces Alpha-Omega Project to improve global OSS supply chain securityHelp Net Security·Jan 19, 11:47 UTC · Jan 19, 2023Vulnerability55
Establishing a security baseline for open source projectsHelp Net Security·May 13, 00:00 UTC · May 13, 2024Vulnerability55
US Government and OpenSSF Partner on New SBOM Management ToolInfosecurity Magazine·Apr 17, 15:36 UTC · Apr 17, 2024Vulnerability42
OpenSSF Publishes Security Framework for Open Source SoftwareInfosecurity Magazine·Feb 27, 11:00 UTC · Feb 27, 2025Vulnerability42
New 'Siren' mailing list aims to share threat intelligence for open source projectsThe Record·May 20, 14:20 UTC · May 20, 2024Exploit / PoC60
CISA and OpenSSF Release Framework for Package Repository SecurityThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability55
Two-Thirds of Open Source Community Unaware of Cyber Resilience ActInfosecurity Magazine·Jun 8, 09:00 UTC · Jun 8, 2026Vulnerability42
Google to create security team for open source projectsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability55
New Open Source Security Foundation wants to improve open source software securityHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2020Advisory55
Securing software repositories leads to better OSS securityHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2024Vulnerability55
Package Analysis dynamic analyzes packages in open-source repositoriesSecurity Affairs·May 3, 06:08 UTC · May 3, 2022Tools30
Linux Foundation secures $12.5 million to strengthen open source security and support maintainersHelp Net Security·Mar 17, 00:00 UTC · Mar 17, 2026Vulnerability30
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
OSPS Baseline: Practical security best practices for open source software projectsHelp Net Security·Feb 28, 00:00 UTC · Feb 28, 2025Vulnerability30
Washington summit grapples with securing open source softwareCyberScoop·Sep 13, 13:30 UTC · Sep 13, 2023Exploit / PoC in the wild60
A 10-point plan to improve the security of open source softwareHelp Net Security·Jan 19, 11:46 UTC · Jan 19, 2023Vulnerability55
Google touts new tool that scans for malicious packages in popular openThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Tools142
GitHub Dependabot malware alerts now cover eight ecosystemsHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2026Malware30
Social engineering attacks on open source developers are escalatingHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2026Phishing & fraud30
Big tech companies step in to support the open source security ecosystemHelp Net Security·Mar 18, 00:00 UTC · Mar 18, 2026Vulnerability55
How Intel is making open source accessible to all developersHelp Net Security·Nov 14, 00:00 UTC · Nov 14, 2024Vulnerability30
Paid open-source maintainers spend more time on securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2024Vulnerability55
One-third of dev professionals unfamiliar with secure coding practicesHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2024Vulnerability55
Researchers stop ‘credible takeover attempt’ similar to XZ Utils backdoor incidentThe Record·Apr 15, 19:44 UTC · Apr 15, 2024Malware55
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Tech Giants Reveal RecordInfosecurity Magazine·Oct 11, 09:30 UTC · Oct 11, 2023Exploit / PoCCVE-2023-4448760
Week in review: KeePass vulnerability, Apple fixes exploited WebKit 0-daysHelp Net Security·May 21, 00:00 UTC · May 21, 2023Vulnerability in the wildCVE-2023-28204CVE-2023-32373CVE-2023-32409+1 CVEs60
Google offers $1 million sponsorship to secure open source softwareThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Vulnerability55
Here's a New Tool That Scans Open-Source Repositories for Malicious PackagesThe Hacker News·May 3, 03:59 UTC · May 3, 2022Malware42
Google Pledges $1m to Secure Open Source ProjectInfosecurity Magazine·Oct 5, 09:48 UTC · Oct 5, 2021Vulnerability55
Critical open-source projects get a new security frameworkHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Vulnerability155
Cybersecurity Skills Framework connects the dots between IT job roles and the practical skills neededHelp Net Security·May 16, 00:00 UTC · May 16, 2025Vulnerability55
Experts warn of DDoS attacks using linux printing vulnerabilityThe Record·Oct 2, 21:08 UTC · Oct 2, 2024VulnerabilityCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs35
OpenJS Foundation Targeted in Potential JavaScript Project Takeover AttemptThe Hacker News·Apr 17, 05:00 UTC · Apr 17, 2024Vulnerability55
New open-source project takeover attacks spotted, stymiedHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2024Vulnerability55
Google Unveils Open Source Project to Improve Software Supply Chain SecurityInfosecurity Magazine·Oct 21, 17:00 UTC · Oct 21, 2022Exploit / PoC57