Security News

Finders Keypers: Open-source AWS KMS key usage finder
2025-03-24 05:30

Finders Keypers is an open-source tool for analyzing the current usage of AWS KMS keys. It supports both AWS customer managed KMS keys and AWS Managed KMS keys. Use cases include: Identifying the...

UAT-5918 Targets Taiwan's Critical Infrastructure Using Web Shells and Open-Source Tools
2025-03-21 13:54

Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities in Taiwan since at least 2023. "UAT-5918, a threat actor believed to be...

Dependency-Check: Open-source Software Composition Analysis (SCA) tool
2025-03-19 05:30

Dependency-Check is an open-source Software Composition Analysis (SCA) tool to identify publicly disclosed vulnerabilities within a project’s dependencies. The tool analyzes dependencies for...

IntelMQ: Open-source tool for collecting and processing security feeds
2025-03-17 05:00

IntelMQ is an open-source solution designed to help IT security teams (including CERTs, CSIRTs, SOCs, and abuse departments) streamline the collection and processing of security feeds using a...

NetBird: Open-source network security
2025-03-12 06:00

NetBird is an open-source solution that integrates a configuration-free peer-to-peer private network with centralized access control, providing a single platform to build secure private networks...

Hetty: Open-source HTTP toolkit for security research
2025-03-10 06:00

Hetty is an open-source HTTP toolkit designed for security research, offering a free alternative to commercial tools like Burp Suite Pro. Built with the needs of penetration testers, security...

Open-source tool 'Rayhunter' helps users detect Stingray attacks
2025-03-05 20:36

The Electronic Frontier Foundation (EFF) has released a free, open-source tool named Rayhunter that is designed to detect cell-site simulators (CSS), also known as IMSI catchers or Stingrays. [...]

Fix Inventory: Open-source cloud asset inventory tool
2025-03-05 06:00

Fix Inventory is an open-source tool for detecting compliance and security risks in cloud infrastructure accounts. It was built from the ground up for cloud-native environments and provides broad...

Commix: Open-source OS command injection exploitation tool
2025-03-03 06:00

Commix is an open-source penetration testing tool designed to automate the detection and exploitation of command injection vulnerabilities, streamlining security assessments for researchers and...

OSPS Baseline: Practical security best practices for open source software projects
2025-02-28 12:35

The Open Source Security Foundation (OpenSSF), a cross-industry initiative by the Linux Foundation, has announced the initial release of the Open Source Project Security Baseline (OSPS Baseline),...