Ray: Open-Source Distributed Computing Framework
Ray is a Python-native distributed computing framework for scaling AI and ML workloads. It is affected by CVE-2025-62593, a critical RCE vulnerability…
Ray is a Python-native distributed computing framework for scaling AI and ML workloads. It is affected by CVE-2025-62593, a critical RCE vulnerability…
Trivy, an open-source security scanner, was compromised in March 2026. Credentials stolen from Trivy were used to compromise Checkmarx KICS actions.
Open source software is undergoing a forced maturation, driven by a convergence of threats and regulatory pressures. The article argues that while…
EmeritOSS is a concept introduced in the article as a 'retirement home' for open source projects whose maintainers are no longer able…
HTTP Terminator is an open-source AI-assisted research system built by James Kettle at PortSwigger. It generated 30,000 candidate attack vectors from RFC…
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
TeamPCP is a cybercrime group alleged to have compromised open-source projects like Trivy, Checkmarx KICS, and LiteLLM in March 2026. The group…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
Diffusers is a Python library for state-of-the-art pretrained diffusion models used to generate videos, images, and audio. It is widely downloaded and…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…