Skip to content
Open Source Beat
Open Source Projects Developer Tools Programming Languages DevOps & Infrastructure
AI & Machine Learning Security & Privacy Community & Governance Cloud & Databases
🔒

Security & Privacy

James Bottomley presenting TPM interposer defenses at SCALE 23x conference
Security & Privacy

Linux Kernel's New Shield Against TPM Interposer Sneak Attacks

TPM chips were supposed to be the unbreakable guardians of your PC's secrets. Turns out, they're vulnerable to interposer attacks — and Linux just patched the hole.

4 min read 3 days, 19 hours ago
OpenSSH 10.3 release notes with security patch highlights
Security & Privacy

OpenSSH 10.3 Finally Plugs a Username Metacharacter Hole

What if your SSH login name was secretly executing code? OpenSSH 10.3 just fixed that nightmare — plus more housekeeping that old servers won't like.

4 min read 3 days, 19 hours ago
Project Glasswing consortium logo with AI shielding open source code from vulnerabilities
Security & Privacy

Project Glasswing: Big Tech's $100M Bet to AI-Arm Open Source Defenders

Open source maintainers are drowning in bugs — now Big Tech's dropping $100M in AI firepower to save them. Project Glasswing promises patches at scale, but skeptics wonder if it'll deliver.

3 min read 3 days, 19 hours ago
GitLab CI/CD pipeline dashboard highlighting container scanning vulnerabilities with Trivy report
Security & Privacy

GitLab's Container Scanning Arsenal: Five Tools to Lock Down Your Images Before Disaster Strikes

Containers ship vulns faster than you can say 'supply chain attack.' GitLab's scanning suite — from CI jobs to vulnerability dashboards — aims to fix that, but does it scale for real-world chaos?

3 min read 3 days, 20 hours ago
GitLab vulnerability report showing AI confidence badges and false positive filters
Security & Privacy

GitLab 18.10's AI Triage: Cutting Noise or Just Kicking the Can?

Your SAST scan just dumped 47 alerts. Forty are junk. GitLab 18.10's AI says it'll sort the mess—and even patch it for you. Really?

4 min read 3 days, 20 hours ago
Diagram of GitLab's 18-domain Control Framework with security icons
Security & Privacy

GitLab Ditches NIST's 1,000+ Controls for a Bespoke Security Fortress

Over 1,000 NIST controls? GitLab said no thanks. They forged the GitLab Control Framework (GCF) from their own fiery needs, proving custom beats cookie-cutter in the security arena.

4 min read 3 days, 20 hours ago
Linux kernel patch detecting malicious USB device like O.MG cable injecting keystrokes
Security & Privacy

Linux's New hid-omg-detect Driver Spots Malicious USB Keyloggers Before They Strike

Linux insiders expected USB devices to stay a blind spot for kernel-level defenses. This hid-omg-detect driver flips the script, passively scoring shady plugs without blocking legit ones.

3 min read 3 days, 20 hours ago
Timeline graphic of March 2026 supply chain attacks on Trivy, KICS, LiteLLM, and axios
Security & Privacy

76 Poisoned Tags in 12 Days: Pipeline Nightmares from March 2026

Imagine running your trusted vulnerability scanner—only for it to steal your cloud keys. That's what hit four open-source tools in March 2026, all via pipelines.

3 min read 3 days, 20 hours ago
GitLab vulnerability dashboard with auto-dismissed findings filtered and policy-linked
Security & Privacy

GitLab's Auto-Dismiss Policies Quiet the Vulnerability Storm

Security pros, picture this: no more endless manual dismissals of test-file vulns across 100 repos. GitLab's auto-dismiss policies automate the drudgery, freeing you for real threats.

3 min read 3 days, 20 hours ago
Illustration of a secure Kubernetes debugging gateway pod shielding production cluster
Security & Privacy

Kubernetes Debugging's Dirty Secret: From Quick Fixes to Breach Backdoors

Picture this: 3 a.m. outage, prod's on fire, and your go-to fix is cluster-admin access. It works — until the breach report lands in your lap.

4 min read 3 days, 20 hours ago
Grafana dashboard displaying critical security alert for RCE vulnerability
Security & Privacy

Grafana's SQL Nightmare: Critical RCE Patch Drops, But Who's Really Exposed?

A clever SQL feature in Grafana turned into a remote code execution nightmare. Patches are out, but the real question is how many exposed instances are still ticking.

4 min read 3 days, 20 hours ago
GitHub Actions 2026 security roadmap timeline with lockfiles and policy icons
Security & Privacy

GitHub Actions 2026 Roadmap: Lockfiles Lock Down Supply Chain Risks

Supply chain attacks hit CI/CD hard last year—tj-actions, Nx, trivy-action compromised. GitHub's firing back with lockfiles and centralized policies in its 2026 Actions roadmap.

4 min read 3 days, 20 hours ago
← Newer Page 6 of 9 Older →
Open Source Beat

Community-driven. Code-first.

Categories

  • Open Source Projects
  • Developer Tools
  • Programming Languages
  • DevOps & Infrastructure
  • AI & Machine Learning
  • Security & Privacy
  • Community & Governance
  • Cloud & Databases

More

  • RSS Feed
  • Sitemap
  • About
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Fintech Dose Crypto & DeFi

© 2026 Open Source Beat. All rights reserved.

📬

Stay in the loop

The week's most important stories from Open Source Beat, delivered once a week.

No spam. Unsubscribe any time.

You clearly love Open Source news — get it in your inbox

🏠 Home 🔍 Search 🔖 Saved 📂 Categories