security
SBOM 1.0: A specification for sandwich supply chain transparency.
On January 14, 2026, global telnet traffic observed by GreyNoise sensors fell off a cliff. A 59% sustained reduction, eighteen ASNs going completely silent, five countries vanishing from our data entirely. Six days later, CVE-2026-24061 dropped. Coincidence is one explanation.
A security-focused library OS supporting kernel- and user-mode execution - microsoft/litebox
OS-enforced capability sandbox for running untrusted AI agents. No escape hatch. Works with Claude, GPT, and any AI agent.
Lightweight, container-free sandbox for running commands with network and filesystem restrictions - Use-Tusk/fence
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL - dev-sec/ansible-collection-hardening
: Fluent Bit has 15B+ deployments … and 5 newly assigned CVEs
HelixGuard provides open-source research on supply chain malware and vulnerability intelligence. Advanced threat detection tools and datasets for the security community.
Worldwide enumeration of accounts was possible due to a —now closed— privacy vulnerability
Microsoft said today that the Aisuru botnet hit its Azure network with a 15.72 terabits per second (Tbps) DDoS attack, launched from over 500,000 IP addresses.
The Ubuntu 25.10 transition to using some Rust system utilities continues proving quite rocky
A lively discussion about open source, security, and who pays the bills has erupted on Twitter.
Google announced its intent to acquire cloud security company Wiz in March and the deal is now on track to close in early 2026.
Log4Shell proved that open source security isn't guaranteed and isn’t just a code problem.
The Louvre heist was an instant joke online — a joke that gets even funnier when you learn the museum's video surveillance password.
Scan MCP Servers for vulnerabilities. Contribute to cisco-ai-defense/mcp-scanner development by creating an account on GitHub.
Learn how to use AI code assistants securely with OpenSSF’s new free course, Secure AI/ML-Driven Software Development (LFEL1012) by David A. Wheeler. Build safer software with practical AI security guidance.