Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows
Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

Trust3 AI Launches MCP Security: A Hardened Control Plane or Just Another Promise?
Trust3 AI has announced MCP Security to protect enterprise agentic workloads, focusing on connection verification, isolated tokens, an…

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension
GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

AI-Powered Honeypots: Cisco Talos Flips the Script on Automated Threats
On April 29, Cisco Talos Intelligence researchers released a proof-of-concept aimed at neutralizing offensive asymmetry in cyberspace.…

GitHub Investigates Alleged Exfiltration of 4,000 Internal Repositories by TeamPCP
GitHub is investigating claims from the threat group TeamPCP, which alleges to have exfiltrated nearly 4,000 internal repositories and…

Grafana Refuses Ransom Following GitHub Token Theft and Codebase Breach
Grafana Labs has confirmed that a stolen GitHub access token allowed attackers to exfiltrate its source code. Despite extortion attemp…

NGINX Rift: Critical CVE-2026-42945 Exploitation Detected In-the-Wild
The NGINX Rift vulnerability (CVE-2026-42945) has seen active exploitation since May 16, leveraging a long-dormant heap buffer overflo…

DirtyDecrypt: Linux Local Privilege Escalation Exploit Surfaces for Unpatched Systems
A proof-of-concept for 'DirtyDecrypt'—a local privilege escalation flaw in the Linux kernel's RXGK module—is now public. Organizations…

Grafana Labs Hit by GitHub Breach: Source Code Stolen, Ransom Demands Rejected
Grafana Labs has confirmed a breach of its GitHub environment via a 'Pwn Request' vulnerability. While attackers exfiltrated proprieta…

CVE-2026-7482: Technical Analysis of Ollama’s Memory Leak Vulnerability via GGUF
Technical breakdown of CVE-2026-7482 in Ollama. Discovered by Cyera, the vulnerability enables unauthenticated remote attackers to exf…

Fragnesia Flaw Enables Local Root via Linux Page Cache Corruption
CVE-2026-46300 allows local root escalation on Linux by corrupting read-only files in memory. With a public PoC available and patches…

Exim 'Dead.Letter' Vulnerability: Critical RCE Risk for GnuTLS-Based Builds
CVE-2026-45185 is a use-after-free vulnerability in the Exim SMTP BDAT parser that allows unauthenticated RCE on GnuTLS-compiled serve…