LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
ai

Hottest cybersecurity open-source tools of the month: August 2026

Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a

zeroday.news ·

A selection of new open-source cybersecurity tools has been highlighted for their potential to improve security across various environments. These tools include solutions for AI agent security, software supply chain integrity, and automated penetration testing.

NVIDIA has released SkillSpector, an open-source security scanner designed to evaluate AI agent skills. Users can point SkillSpector at a directory, a zip file, a single SKILL.md file, or a Git URL. The tool then provides a list of findings, a risk score, and recommendations regarding the skill's safety for installation.

Another tool, Future AGI, offers an open-source platform for managing self-improving AI agents. Licensed under Apache 2.0, this self-hostable platform supports tracing, evaluating, simulating, and guardrailing Large Language Model (LLM) agents. Upon its initial boot, a self-hosted instance of Future AGI registers with the main Future AGI service, transmitting an instance ID, a version string, a deployment type, and the email addresses and domains of active administrative users.

For software supply chain security, Chainloop functions as an open-source evidence store and policy engine. This tool operates as a command-line interface within various CI/CD pipelines, including GitHub Actions, GitLab, Jenkins, or Dagger. It collects build artifacts, uploads them to content-addressable storage, and then references each artifact in a signed in-toto attestation. The in-toto specification is used to record the execution steps of a build process, enabling subsequent verification.

PentestGPT is an open-source agentic framework for automated penetration testing. This tool directs a large language model at a target system. In its default mode, it progresses through reconnaissance, exploitation, and walkthrough stages, with each stage informing the next. When switched to "pentest mode," the stages become asset discovery, vulnerability identification, and report generation, operating without human intervention.

Finally, Hazmat provides open-source containment for AI agents. This tool runs AI coding agents within a separate account on the user's machine. It supports various existing harnesses, such as Claude Code, Codex, OpenCode, and Cursor Agent, as well as custom scripts.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

phishing

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]

breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.