







Open Source Security Advisory Update: Wednesday, April 1, 2026 Boston, MA 10:00 AM ET Over the past week, we have nearly finalized our investigation and are now in the final stages of documentation and review. There continues to be no indication that Aqua’s commercial products have been affected. As part of this process, we identified …
Mitigating High Severity RunC Vulnerability (CVE-2019-5736)
A high severity (CVSS score 7.2) vulnerability (CVE-2019-5763) was found in runc, allowing attackers to compromise the container host. Patches are already available from most providers. Aqua customers can prevent this vulnerability from being exploited by applying the appropriate runtime policies.

Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond

Attorney General Marshall Launches Investigation Into OpenAI and Sam Altman for Massive Artificial Intelligence Data Breach - Alabama Attorney General's Office
For Immediate Release:August 24, 2026
Bitwarden scrubs 'Always free' and 'Inclusion' values from its website as longtime execs step down - Fast Company
What is going on with the beloved open-source password manager?

Meta’s Bacterial Mystery Could Poison the Data Center Well
Water pollution in Wyoming has big implications for the future of data center development.

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure. This attack was very sophisticated, and the resulting document doubles as a crash-course …
Attacking & Auditing Docker Containers Using Open Source tools
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
Security Update: Suspected Supply Chain Incident | liteLLM
As of 2:00 PM ET on March 24, 2026

Microsoft's open source tools were hacked to steal passwords of AI developers | TechCrunch
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.

Updated: Data Breaches Caused by Leaks in 2024
We’re tracking data breaches that are most likely caused by leaked secrets and keeping this page up-to-date.

Glassworm Returns: Invisible Unicode Malware Found in 150+ GitHub Repositories
The Glassworm supply chain attack is back. Researchers uncovered malware hidden in invisible Unicode characters across 150+ GitHub repositories, plus npm packages and VS Code extensions.

OpenAI Trained Its Models For Months While Those Models Were Coordinating Exploits Via Message Boards
How does the situation keep turning out to be worse than we know?

Microsoft, Meta, Nvidia, OpenAI, and Palantir have a message for Washington - AOL
For his first-ever post on X, Nvidia CEO Jensen Huang shared an open letter to DC calling for the protection of open source AI.

OpenAI’s Hacking Debacle Comes Down to Human Error
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
