#opensourcesecurity

2025-12-11

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=vQTvAPCvr2c

2025-12-11

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=vQTvAPCvr2c

2025-12-10

Governance: because even code needs structure and curfews. #LicenseClearance #OpenSourceSecurity #Governance

Flat style illustration showing a parent teaching a child beside a checklist, used as a metaphor for open source governance. The visual supports the message that clear boundaries, guidance, and routine check-ins lead to reliable software releases. Includes icons like a lightbulb and checkmark to represent good practices in software compliance and SCA.
2025-12-09

Authorities in Russia report that they dismantled a group using NFCGate-based malware distributed through messaging apps to collect card data and perform unauthorized ATM withdrawals.

Reported losses exceed 200M rubles, and researchers continue to track increasingly advanced NFCGate variants used in financial fraud across multiple regions.

What detection or policy mechanisms do you think can most effectively limit the misuse of open-source NFC tooling?

Source: therecord.media/russian-police

Follow us for steady, unbiased threat-research coverage.

#InfoSec #Cybersecurity #ThreatResearch #FinancialFraud #MobileSecurity #Malware #NFC #OpenSourceSecurity #FraudAnalysis #CyberAwareness #SecurityCommunity

Russian police bust bank-account hacking gang that used NFCGate-based malware
2025-12-08

This week on #OpenSourceSecurity I chat with Jamie Tanna about updating open source dependencies. It's usually not as simple as "just update" and Jamie has a ton of real world experience in this working on Renovate

opensourcesecurity.io/2025/202

2025-12-04

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=imLWFmYfVbQ

2025-12-04

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=imLWFmYfVbQ

Whonix Anonymous OSwhonix@fosstodon.org
2025-12-04

Secure by Design. Privacy by Default.
Whonix is built on Kicksecure-hardened Debian and runs inside VMs โ€” so your IP, identity & data stay protected.

#Whonix #CyberSecurity #Kicksecure #PrivacyMatters #SecureByDesign #PrivacyByDefault #Anonymity #TorNetwork #VMsecurity #DataProtection #CyberDefense #SecurityHardened #OpenSourceSecurity #DigitalPrivacy

ActiveStateactivestate
2025-12-04

With 97% of developers now using AI coding tools at work, the question isnโ€™t if AI is in your codebase. Itโ€™s where.

We take a closer look at how AI-generated code can alter your software supply chain, sometimes in ways you wonโ€™t notice until it's too late.

๐Ÿ‘‰ See our thoughts on managing AI-driven risk with confidence.

๐Ÿ”— bit.ly/3Xyi5bH

2025-12-01

This episode of #OpenSourceSecurity I chat with Alex Zenla from Edera about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one. Alex fills us in on how it was found, what the coordination looked like, and some things to think about as we manage these incredibly complex supply chains

opensourcesecurity.io/2025/202

ActiveStateactivestate
2025-11-26

Enhancing the software supply chain starts long before code reaches a scanner. It begins with the quality of the open-source components you bring into your ecosystem.

In our latest post, we break down why upstream integrity matters now and how a curated, source-built catalog is becoming a quiet advantage for more resilient software supply chains.

Link to post: activestate.com/resources/quic

ActiveStateactivestate
2025-11-24

๐Ÿšจ Another npm supply-chain attack hit this week โ€” the Shai-Hulud worm resurfaced, embedding credential-harvesting code into legitimate packages and executing through install scripts.

Once triggered, it collected environment variables and secrets, then propagated by publishing compromised packages under names that looked trustworthy.

Hereโ€™s a resource that can help your team stay ahead of attacks like this:

๐Ÿ‘‰ activestate.com/blog/protect-y

2025-11-24

#OpenSourceSecurity has a chat with @sethmlarson about @ThePSF security

Seth has a new whitepaper, there's a CFP open (which you should submit a paper to), and some discussion about the PSF grant situation

It's always fun to chat with Seth, I learn a ton every time!

opensourcesecurity.io/2025/202

N-gated Hacker Newsngate
2025-11-24

๐Ÿ› Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! ๐ŸŽ‰ struts in with their clipboard and magnifying glass, ready to save the dayโ€”right after the damage is done. ๐Ÿ”๐Ÿ“
helixguard.ai/blog/malicious-s

2025-11-20

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=REMLniQyhkE

2025-11-20

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=REMLniQyhkE

ActiveStateactivestate
2025-11-19

The EU Cyber Resilience Act (CRA) is about to fundamentally change how software teams build and ship products in the EU.

We break down how teams can prepare without slowing innovation.

Link to the full guide: activestate.com/blog/eu-cyber-

2025-11-17

On this episode of #OpenSourceSecurity I chat with @hughsie about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

If you have gear that doesn't work with LVFS, make sure you ask the vendor why not (and support the hardware folks who do support LVFS)

opensourcesecurity.io/2025/202

2025-11-13

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=9a2smJppw0Y

2025-11-13

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=9a2smJppw0Y

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst