We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
📦 Installing a single package can introduce dozens of dependencies.
Attackers exploit this through typosquatting, malicious packages, and compromised maintainers.
ENISA’s advisory highlights why dependency visibility is becoming critical.
#CyberSecurity #SoftwareSupplyChain #OpenSourceSecurity
This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module
A man with glasses and a white patterned shirt is smiling with his hand near his chin. He has a bald head and light skin.
Marcin Wyszynski warns that open source isn’t the feel‑good story many think. It’s a survival strategy.
Read why teams betting on “free” tools need to rethink risk now:
spr.ly/63329h4jPX
#FoundryExpert #OpenSourceSecurity #SoftwareSupplyChain
I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work
Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age
I learned a ton from this disucssion
⚠️ El desarrollo con IA lleva el riesgo del código abierto al límite
La IA acelera el desarrollo, pero multiplica los riesgos de seguridad
devops.com/ai-fueled-development-pu...
#OpenSourceSecurity #BlackDuckOSSRA #VulnerabilityManagement #RoxsRoss
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=FazSzP_Kty4
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=FazSzP_Kty4
Full breakdown in this week's Securing the Backbone. Link below. 👇
www.linkedin.com/pulse/securi...
#DevSecOps #SoftwareSupplyChain #OpenSourceSecurity #CyberSecurity
This week on #OpenSourceSecurity I chat with Brad Axen about Goose and the Agentic AI Foundation
I'm often skeptical about AI claims, but I do approve the foundation model and seeing Goose donated to it
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=-Unu5gZ8Cxc
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=-Unu5gZ8Cxc
Love that GitHub's investing in open source security for AI tools. Keeping those foundational projects safe means fewer Log4Shell nightmares down the line. 🛡️ #OpenSourceSecurity #AI
The software supply chain is already broken. SBOMs help you see where.
Learn how to make software visibility your first step.
jeffbailey.us/blog/2026/02...
#Software #SBOM #SoftwareSupplyChain #AppSec #OpenSourceSecurity #DevSecOps #OSS #SRE #PlatformEngineering
Legal, security, and devs walk into a bar. The OSPO keeps it from burning down.
Learn how OSPOs coordinate teams that could easily talk past each other.
jeffbailey.us/blog/2026/02...
#OpenSource #OSPO #SoftwareGovernance #SoftwareSupplyChain #RiskManagement #OpenSourceSecurity
🔥 Tachan de "incendio" de seguridad a OpenClaw, pero hay una forma de protegerse
Un análisis de Snyk revela graves fallos en ClawHub. Te contamos cómo mitigarlos.
https://thenewstack.io/deno-sandbox-security-secrets/
#OpenSourceSecurity #SupplyChain #Snyk #RoxsRoss
Read more:
www.technadu.com/15-openclaw-...
Do you think AI agent frameworks are being deployed too quickly in production environments? Comment your opinion below.
#CyberSecurity #AIAgents #DevSecOps #OpenSourceSecurity #AccessControl
15 security flaws found in OpenClaw, including a critical auth bypass (CVSS 9.4).
AI agents with file, API & command access expand enterprise attack surfaces.
All patched - but adoption is accelerating fast.
#CyberSecurity #AIAgents #OpenSourceSecurity
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
Researchers disclosed critical n8n vulnerabilities (CVE-2026-25049) enabling sandbox escape and server-level control by authenticated users.
Patches are available, and no confirmed exploitation has been reported.
#CyberSecurity #n8n #CVE #OpenSourceSecurity #TechNadu
Researchers found 341 malicious ClawHub repos spreading malware — open-source trust is being actively abused at scale. Clone carefully. 🧩⚠️ #OpenSourceSecurity #SupplyChainRisk
This episode of #OpenSourceSecurity I have a chat with David Bernstein about crisis response
I love this topic because responding to a crisis is pretty common in security work, but doesn't have to be a gong show
This is one of those topics that can go deep. David did a nice job covering basics
Notepad Plus Plus Update Spreads Malware
Read More: buff.ly/OVafqqU
#NotepadPlusPlus #SupplyChainAttack #SoftwareUpdateAbuse #StateSponsoredHack #MalwareDistribution #CyberThreat #InfosecAlert #OpenSourceSecurity
OpenSSL Fixes 12 Flaws Including RCE
Read More: buff.ly/F70rTJm
#OpenSSL #OpenSourceSecurity #RemoteCodeExecution #CriticalVulnerability #PatchTuesday #CryptoSecurity #AppSec #CVE
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=rKOnBryIYww
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=rKOnBryIYww
Grist Core Flaw Enables Remote Code Execution
Read More: buff.ly/Vm8WYov
#CVE202624002 #RemoteCodeExecution #GristCore #OpenSourceSecurity #Pyodide #AppSec #VulnerabilityDisclosure #ZeroDay
This episode of #OpenSourceSecurity I discuss @suricata.io with Victor Julian
Victor tells us all about the past, present, and future of #Suricata
I learned a ton
opensourcesecurity.io/2026/2026-01...