A critical security flaw has been discovered in Appsmith, the popular open-source platform used by organizations worldwide...
Open Source Security
A critical security flaw has been uncovered in Open5GS, a popular open-source implementation of 5G core network...
A new vulnerability has been discovered in libheif, a widely used open-source library for decoding modern image...
A potentially dangerous vulnerability has been uncovered in GNU libtasn1, a foundational software library used by countless...
Apache Solr administrators are being urged to update their instances immediately following the disclosure of two moderate-severity...
A critical security vulnerability has been found in Cal.com, the popular open-source scheduling platform used by individuals...
A critical vulnerability has been discovered in Appsmith, the popular open-source platform used by organizations to build...
A critical vulnerability has been discovered in zlib, the lossless data-compression engine used on “virtually any computer...
GNU Wget2, the modern successor to the ubiquitous command-line download tool, has been hit with a double...
The Apache Software Foundation has released a critical fix for StreamPipes, its self-service Industrial IoT toolbox designed...
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the...
A critical vulnerability has been unearthed in Apache bRPC, an industrial-grade RPC framework widely used to power...
The ReversingLabs research team has uncovered yet another software supply chain attack targeting the cryptocurrency ecosystem, this...
Hunted Labs has uncovered that a widely used open source library—easyjson—is maintained and controlled by developers associated...
CVE-2025-32444 (CVSS 10): Critical RCE Flaw in vLLM’s Mooncake Integration Exposes AI Infrastructure
CVE-2025-32444 (CVSS 10): Critical RCE Flaw in vLLM’s Mooncake Integration Exposes AI Infrastructure
A critical security vulnerability has been disclosed in vLLM, a popular open-source library used for high-performance inference...
The Socket Threat Research Team has exposed three malicious open-source packages masquerading as developer tools — designed...
As cyber threats grow more sophisticated, so do the tools defenders use to counter them. In 2025,...
vLLM, a popular library for Large Language Model (LLM) inference and serving, has recently addressed a critical...
Synopsys recently released the Black Duck Report on 2018 Open Source Security and Risk Analysis, which provides an in-depth...