OpenMandriva Linux says it faced an attempted internal sabotage tied to a contributor dispute, a reminder that repository access can become a security issue long before malware enters the picture.
A cluster of malicious packages in npm and PyPI shows how public registries can be turned into a delivery channel for software-supply-chain abuse.
A new EU action plan pushes cybersecurity and artificial intelligence beyond rulemaking, putting model evaluation, vulnerability handling, open source, and skills at the center of practical defense.
PolinRider shows how a software supply-chain operation can turn legitimate open source assets into a route for backdoors and credential theft, putting developer workstations at the center of the blast radius.
An open source kei truck aimed at low-speed use is not a breach story, but it does show how transparency changes the way builders think about parts, documentation, and trust.
A jailed Anonymous-linked Canadian hacker, open source zero-days, and an ATM jackpotting sentence all point to the same pressure point: when technical trust breaks, legal and operational fallout follows fast.
The game engine’s updated contribution rules show how open-source projects are responding when AI raises patch volume faster than humans can safely review it.
A cluster of fixed flaws in Fluentd shows how a logging hub can become a pivot point for code execution, internal probing, disruption, and sensitive-data leakage.
Akrites is being introduced as a security project meant to help the open source world report, patch, and disclose vulnerabilities with less friction and more discipline.
A ministry-built collaboration platform shows how public-sector digital independence can work in practice, while also revealing the staffing, storage, and governance burden that comes with running your own cloud.
The EU is treating key technologies as a control problem, where supply chains, data boundaries, and infrastructure resilience all sit in the same policy stack.
Curl has landed a security update that fixes a long-standing vulnerability described as 25 years old, plus 18 more medium- and low-severity issues that remind defenders how durable software debt can be.
A reported flaw pattern in build automation shows how a single CI/CD weakness can put repository control and software supply-chain trust at risk.
A new upstream security effort uses OpenAI models and Trail of Bits review to hunt flaws in widely used open-source code, but the real test is whether speed can be paired with restraint.
ACN CSIRT Italia has flagged one critical and two high-severity vulnerabilities in libssh2, a client-side open-source SSH library that many applications may embed or link against.
SUSE’s pitch shows how enterprise AI is increasingly judged by who controls the cloud, the OS, Kubernetes, and the exit path when a vendor no longer fits.
Fresh critical and high-severity NGINX fixes show how a few rewrite and proxy directives can turn an internet-facing layer into a crash point, and in narrower conditions, a path toward code execution.
A new EU sovereignty push ties chips, cloud, AI, open source, and energy digitalization into one resilience agenda, shifting security thinking from products to dependencies.
The fight over cheaper model access is less about a single token bill than about who owns routing, policy, and dependency control across AI deployments.
A security roundup describing Microsoft Azure repositories being disabled alongside a suspected package compromise is a reminder that modern malware often targets trust infrastructure before it targets users.