Security News

Google's AI-Powered OSS-Fuzz Tool Finds 26 Vulnerabilities in Open-Source Projects
2024-11-21 07:13

Google has revealed that its AI-powered fuzzing tool, OSS-Fuzz, has been used to help identify 26 vulnerabilities in various open-source code repositories, including a medium-severity flaw in the...

AxoSyslog: Open-source scalable security data processor
2024-11-21 06:30

AxoSyslog is a syslog-ng fork, created and maintained by the original creator of syslog-ng, Balazs Scheidler, and his team. “We first started by making syslog-ng more cloud-ready: we packaged...

GitHub Secure Open Source Fund: Project maintainers, apply now!
2024-11-20 13:38

GitHub is calling on maintainers of open source projects to apply for the newly opened Secure Open Source Fund, to get funding and knowledge to improve the security and sustainability of their...

Debunking myths about open-source security
2024-11-20 05:30

In this Help Net Security interview, Stephanie Domas, CISO at Canonical, discusses common misconceptions about open-source security and how the community can work to dispel them. She explains how...

Open-source and free Android password managers that prioritize your privacy
2024-11-19 04:30

We’re often told to use strong, unique passwords, especially for important accounts like email, banking, and social media. However, managing different passwords for numerous accounts can be...

ScubaGear: Open-source tool to assess Microsoft 365 configurations for security gaps
2024-11-18 04:30

ScubaGear is an open-source tool the Cybersecurity and Infrastructure Security Agency (CISA) created to automatically evaluate Microsoft 365 (M365) configurations for potential security gaps....

How Intel is making open source accessible to all developers
2024-11-14 05:30

In this Help Net Security interview, Arun Gupta, Vice President and General Manager for Open Ecosystem, Intel, discusses the company’s commitment to fostering an open ecosystem as a cornerstone of...

Powerpipe: Open-source dashboards for DevOps
2024-11-12 05:00

Powerpipe is an open-source solution designed to streamline DevOps management with powerful visualization and compliance tools, making it simple to track, assess, and act on key data for smarter...

AI Industry is Trying to Subvert the Definition of “Open Source AI”
2024-11-08 12:03

The Open Source Initiative has published (news article here) its definition of “open source AI,” and it’s terrible. It allows for secret training data and mechanisms. It allows for development to...

Am I Isolated: Open-source container security benchmark
2024-11-08 05:30

Am I Isolated is an open-source container security benchmark that probes users’ runtime environments and tests for container isolation. The Rust-based container runtime scanner runs as a...