Skip to content
Open Source Beat
Open Source Projects Developer Tools Programming Languages DevOps & Infrastructure
AI & Machine Learning Security & Privacy Community & Governance Cloud & Databases
🔒

Security & Privacy

VS Code editor showing EnvGuard detecting a JWT token leak with a red underline warning in the environment file
Security & Privacy

One Developer's VS Code Extension Just Made Committing Secrets a Lot Harder to Mess Up

A developer built a free VS Code extension after nearly pushing a live Stripe key to GitHub. EnvGuard now catches 30+ types of secrets before they escape into the wild.

5 min read 1 week, 1 day ago
Screenshot of Docker Hub with a warning banner showing compromised Trivy image versions alongside a timeline of the attack from March 19-23, 2026.
Security & Privacy

The Trivy Supply Chain Ambush: How a Vulnerability Scanner Became the Attack Vector

Between March 19 and 23, 2026, threat actors compromised Aqua Security's CI/CD pipeline and poisoned Trivy images with malware. If you pulled the wrong version, your secrets are at risk.

4 min read 1 week, 1 day ago
Diagram showing passkey authentication flow: browser signs challenge with private key, server verifies with public key, no shared secrets transmitted
Security & Privacy

Why Passkeys Are Finally Killing Passwords — And Why Your App Isn't Ready Yet

Over 80% of web application breaches still trace back to stolen passwords. Passkeys aren't the future anymore—they're here. So why are most apps still asking users to type secrets into a box?

7 min read 1 week, 1 day ago
GitHub secret detector dashboard showing detection metrics and MCP agent integration status
Security & Privacy

GitHub's Secret Scanner Just Got 37 Times Smarter—and It's Watching Your AI Agents

GitHub's March 2026 update isn't just another incremental feature drop. It's a signal that secret detection is finally catching up to how developers actually build—with AI.

5 min read 1 week, 1 day ago
Terminal showing regex pattern matching for PII detection with response times under 400ms
Security & Privacy

I Built a PII Detection API Without Touching AI—And It's Faster Than Every Enterprise Tool

Most PII detection tools bleed money because they run your data through an LLM. One developer just proved you don't need AI to catch credit cards, emails, and SSNs—pure regex patterns work fine, faster, and cheaper.

4 min read 1 week, 1 day ago
A terminal window showing git commit history with sensitive database files highlighted in red, symbolizing accidental credential exposure.
Security & Privacy

How I Accidentally Committed My Entire 2FA Database to Git—And Why Your .gitignore Isn't Protecting You

A homelab operator built something beautiful for two years. Then a single `git add .` command destroyed it. Here's what went wrong—and how you're probably vulnerable too.

5 min read 1 week, 1 day ago
Diagram showing secure access token lifecycle with proper storage, validation, expiration, and revocation mechanisms in web applications
Security & Privacy

Your Access Tokens Are Probably Broken (And Nobody's Telling You)

Your authentication system is probably leaking tokens right now—you just don't know it yet. Here's what security audits keep finding, and why your team's token strategy is likely incomplete.

6 min read 1 week, 1 day ago
Abstract visualization of red attack vectors staying beneath blue SRE alert thresholds in cloud infrastructure
Security & Privacy

The Error Budget Trap: Why Your Reliability Monitoring Is Blind to Attacks

Your SRE monitoring is built to catch failures—not attacks. Attackers know this. They're weaponizing error budgets as the perfect hiding place, staying just beneath the thresholds your alerts ignore.

5 min read 1 week, 1 day ago
Code repository visualization with warning symbols highlighting npm package vulnerabilities
Security & Privacy

npm's Security Crisis Is Real—And GitHub Isn't Fixing It Fast Enough

The maintainer of ESLint just laid bare what developers won't say publicly: npm—the backbone of JavaScript—is held together with duct tape and good intentions. And GitHub's recent security push? Not nearly enough.

5 min read 1 week, 1 day ago
Abstract representation of Kubernetes security layers and AI agent integration architecture
Security & Privacy

Kubescape 4.0 Brings Enterprise Stability—and Now Your AI Can Debug Your Kubernetes

Kubescape 4.0 is out, and it's solving a problem nobody saw coming: your AI agents need to understand your Kubernetes security posture. But there's a catch.

5 min read 1 week, 1 day ago
Network diagram showing malware propagation through npm package registry with blockchain nodes for command and control
Security & Privacy

How TeamPCP's Self-Propagating Worm Turned Open Source Into a Backdoor Factory

TeamPCP just demonstrated something terrifying: a worm that doesn't need human help to spread through open source ecosystems. It compromised npm tokens, poisoned packages, and used blockchain to stay untouchable.

4 min read 1 week, 1 day ago
Abstract visualization of hidden code layered beneath visible legitimate source code, with Unicode characters highlighted
Security & Privacy

Invisible Code Is Now Flooding GitHub. Your Code Review Won't Catch It.

A new supply-chain attack is hiding malicious code in plain sight using invisible Unicode characters. Traditional defenses? Completely useless.

5 min read 1 week, 1 day ago
← Newer Page 9 of 10 Older →
Open Source Beat

Community-driven. Code-first.

Categories

  • Open Source Projects
  • Developer Tools
  • Programming Languages
  • DevOps & Infrastructure
  • AI & Machine Learning
  • Security & Privacy
  • Community & Governance
  • Cloud & Databases

More

  • RSS Feed
  • Sitemap
  • About
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Fintech Dose Crypto & DeFi

© 2026 Open Source Beat. All rights reserved.

📬

Stay in the loop

The week's most important stories from Open Source Beat, delivered once a week.

No spam. Unsubscribe any time.

You clearly love Open Source news — get it in your inbox

🏠 Home 🔍 Search 🔖 Saved 📂 Categories