Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
PentestGPT
PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then …

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because …

Chainloop
Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what …

ShieldFont
ShieldFont fights AI scraping by handing crawlers the wrong words

Isaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a …

Cloudflare OS
Cloudflare OS goes open source with a record of everything its agents read

Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record …

Future AGI
Future AGI: Open-source platform for shipping self-improving AI agents

Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register …

GitHub
AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) …

Nuget
Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for …

erase
OWASP’s subtractive security project measures the attack paths you erased

An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to …

SkillSpector
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills

SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a …

GitHub
GitHub delays version updates so malware gets caught first

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. …

GitHub
GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools