Tag
GNOME developer Michael Catanzaro argues that AI vulnerability scanning is now essential for maintaining secure, high-quality open-source software, noting that AI-generated vulnerability reports have improved dramatically in 2026 despite still causing issues like verbose or occasionally fabricated reports.
Vex8s is an experimental tool that generates VEX documents by analyzing Kubernetes security contexts and vulnerability data with an embedded ML model to determine which CVEs are actually exploitable in a cluster.
Greg Brockman describes how OpenAI used the Astra model to identify and fix critical vulnerabilities in their systems, highlighting a continuous AI-driven security loop and declaring the AGI era.
The tweet demonstrates how Cline Desktop, an open-source app for open-weight models, automatically scanned and fixed intentional vulnerabilities in a codebase using a scheduled agent, showcasing AI coding agents as autonomous teammates.
The author experimented with a de-aligned AI agent from Abliteration AI to hack their own home network, uncovering vulnerabilities and exploring implications for AI-driven cybersecurity threats and defenses.
Z.ai has released GLM 5.3, a powerful open-weight AI model for coding and cybersecurity tasks, comparable to leading models from Anthropic and OpenAI, with potential applications in defensive security and concerns about misuse.
Echo and NanoClaw collaborated to eliminate 1,400 CVEs in NanoClaw's container images through scanning, patching, and backporting fixes. The article details their agentic hardening process, including safe version bumps and manual patch research.
Deep Eye is an AI-driven penetration testing tool that can integrate with multiple model services, automatically generate test plans, cover over 45 vulnerability detection types, and support compliance report generation.
A filtering engine and database that scans public kernel commits to identify security patches that have not yet been propagated to stable branches, helping developers track potential vulnerabilities.
T3MP3ST is an open-source harness that turns AI coding agents like Claude Code and Codex into autonomous red team tools, achieving high pass rates on security benchmarks and real CVE detection.
Cognition introduces Devin Security Swarm, a new tool for finding security vulnerabilities using an Agentic MapReduce architecture, achieving higher accuracy and lower cost than alternatives.
Charlie Marsh announces uv audit, a native vulnerability scanning feature for project dependencies in the uv package manager.
AI can now complete OWASP security audits in 30 seconds instead of three days, using a single prompt to identify vulnerabilities like SQL injection, XSS, and broken authentication.
The article discusses the rise of LLM-powered automated vulnerability scanning for open source code, leading to a significant increase in security reports, and coins this trend as the 'strip mining era of open source security'. It highlights the shift in both volume and quality of reports observed by Metabase and others starting in early 2026.
Daniel Stenberg reports that Anthropic's Mythos AI model identified a vulnerability in curl, highlighting the growing role of advanced AI in security auditing while noting initial access hurdles via the Linux Foundation.
A practical guide to securing Python supply chains through layered defenses including linting with Ruff, dependency pinning with hashes, vulnerability scanning with pip-audit, SBOM generation, and Trusted Publishing with OIDC attestations.
Trivy is a comprehensive, open-source security scanner by Aqua Security that detects vulnerabilities, misconfigurations, secrets, and license issues across containers, filesystems, git repos, and Kubernetes.