Vulnerabilities Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. Mike LennonJuly 20, 2026
Application Security Linux Foundation Unveils New Open Source Security Project Akrites It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. Ionut ArghireJune 26, 2026
Application Security Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive. Ionut ArghireJune 16, 2026
Vulnerabilities IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. SecurityWeek NewsMay 28, 2026
Artificial Intelligence Cisco Releases Open Source Tool for AI Model Provenance The new kit aims to address risks related to poisoned models, regulatory issues, supply chain integrity, and incident response. Eduard KovacsMay 1, 2026
Malware & Threats Telnyx Targeted in Growing TeamPCP Supply Chain Attack Two malicious versions of the popular SDK were uploaded to the PyPI registry, targeting Windows, macOS, and Linux. Ionut ArghireMarch 30, 2026
Supply Chain Security Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack Hackers published a malicious scanner release and replaced tags to point to information-stealer malware. Ionut ArghireMarch 23, 2026
Cybersecurity Funding Tech Giants Invest $12.5 Million in Open Source Security Anthropic, AWS, Google, Microsoft, and OpenAI fund the Linux Foundation’s long-term security initiatives focused on open source software. Ionut ArghireMarch 17, 2026
Artificial Intelligence OpenAI Rolls Out Codex Security Vulnerability Scanner Codex Security, formerly Aardvark, has found hundreds of critical vulnerabilities in tested software in the past month. Eduard KovacsMarch 10, 2026
Threat Intelligence RSAC Releases Quantickle Open Source Threat Intelligence Visualization Tool Quantickle is a browser-based tool designed for creating visual representations of threat research. Eduard KovacsFebruary 10, 2026
Supply Chain Security From Open Source to OpenAI: The Evolution of Third-Party Risk From open source libraries to AI-powered coding assistants, speed-driven development is introducing new third-party risks that threat actors are increasingly exploiting. Nadir IzraelDecember 16, 2025
Cloud Security $320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits Participants earned rewards at the hacking competition for Grafana, Linux Kernel, Redis, MariaDB, and PostgreSQL vulnerabilities. Eduard KovacsDecember 12, 2025
Cybersecurity Funding Chainguard Raises $280 Million in Growth Funding Chainguard has raised $636 million in the past six months alone for its software supply chain security solutions. Eduard KovacsOctober 27, 2025
Phishing PyPI Warns Users of Fresh Phishing Campaign Threat actors impersonating PyPI ask users to verify their email for security purposes, directing them to fake websites. Ionut ArghireSeptember 25, 2025
Application Security Seal Security Raises $13 Million to Secure Software Supply Chain The open source security firm will use the investment to enhance go-to-market efforts and accelerate platform expansion. Ionut ArghireJuly 29, 2025
Application Security HeroDevs Raises $125 Million to Secure Deprecated OSS HeroDevs has received a $125 million strategic growth investment from PSG to secure enterprise security stacks. Ionut ArghireJuly 24, 2025
Vulnerabilities Vulnerability Exposed All Open VSX Repositories to Takeover A vulnerability in the extension publishing mechanism of Open VSX could have allowed attackers to tamper with any repository. Ionut ArghireJune 27, 2025
Malware & Threats Ongoing Campaign Uses 60 NPM Packages to Steal Data Security firm Socket warns flags a campaign targeting NPM users with tens of malicious packages that can hijack system information. Ionut ArghireMay 27, 2025
Application Security Open Source Security Firm Hopper Emerges From Stealth With $7.6M in Funding Hopper has emerged from stealth mode with a solution designed to help organizations manage open source software risk. Eduard KovacsApril 22, 2025
Application Security Google Releases Major Update for Open Source Vulnerability Scanner Google has integrated OSV-SCALIBR features into OSV-Scanner, its free vulnerability scanner for open source developers. Ionut ArghireMarch 18, 2025