Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, …
GitHub adds AI to catch passwords before a code push
GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories. …
AI Agent Gateway: Open-source tool keeps credentials out of agent configs
Tuskira’s AI Agent Gateway is an open-source solution that sits between AI agents and everything they call: the MCP tool servers that connect them to services like …
GitHub’s ReviewBench puts AI code reviewers to the test
GitHub’s ReviewBench measures how well AI code review tools detect problems before software is released. Available in research preview through its website, the benchmark lets …
RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models
A developer has released RemoveMacAI, a free command-line tool that turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded AI models. It requires a Mac …
Keyorix: Open-source secrets management for teams that can’t use SaaS
Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application fetches the database …
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs. …
OWASP Noir: Open-source static analysis tool
OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, …
GitHub’s AI agent found 24 Android app vulnerabilities
GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to …
Hottest cybersecurity open-source tools of the month: September 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across …
NVIDIA wants AI agent safety enforced in silicon, not left to the agent
NVIDIA has introduced an open software platform and a hardware-based reference design intended to keep AI agents within the limits set by the organizations that use them. The …
Authorizer: Open-source authentication and authorization for your apps
Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they …
Featured news
Resources
Don't miss
- FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
- What the BPFDoor backdoor tells us about attacks on the network edge
- Thousands of wind and solar park systems sit exposed on the internet across Europe
- YouTubers targeted with fake sponsorships and “channel verification” phishing
- Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers