Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

More than two dozen technology companies, including Microsoft, Meta, Palantir, and IBM, have issued an open letter to policymakers advocating for the widespread adoption and support of open-source artificial intelligence (AI) systems and code. The letter, posted on Friday, argues that an open-source approach is inherently safer and more beneficial for societal innovation than restricting access or relying solely on a limited number of proprietary, closed models.
The signatories contend that the current debate around AI mirrors the software industry's landscape in the 1980s, when concerns about open-source software's impact on business proved unfounded. That era ultimately led to a robust open-source ecosystem that now forms the backbone of the internet, government IT, and commercial software, fostering a shared knowledge base for future innovation. The companies assert that U.S. leadership in AI will be defined by its ability to build a strong, open ecosystem that permeates all sectors, rather than by the success of a single frontier AI model.
While acknowledging the security risks associated with expanding access to open-source AI, the letter posits that the benefits for cybersecurity defenders outweigh the potential for misuse by attackers. Cybersecurity experts have warned that broadly available AI tools could empower less technically skilled criminals. Once an AI model is "open weight," meaning its internal parameters are accessible, anyone can download, customize, and remove built-in safeguards for their own purposes, potentially leading to an increase in malicious deepfakes and other AI-generated content.
However, the letter argues that open-source AI models are crucial for startups, universities, research labs, and other smaller organizations, enabling them to innovate and refine the technology for broader societal utility. The companies state that open weights allow organizations to select the most appropriate model for specific tasks at an optimal cost, reserving high-capacity frontier models for complex problems and deploying efficient, specialized models for everyday applications. This disciplined approach, they claim, is essential for making AI economically sustainable as its use expands.
From a cybersecurity perspective, the letter emphasizes that open-source AI will empower defenders to outpace attackers. It argues that in an environment where attackers leverage advanced AI, defenders require access to comparable models to effectively detect, simulate, and respond to emerging threats. Open models, the signatories contend, enhance defensive capabilities, increase transparency, and facilitate the discovery and remediation of vulnerabilities across multiple teams.
Other notable signatories include Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, and Dell Technologies. The letter emerges as U.S. policymakers continue to navigate the complex balance between fostering domestic AI innovation and implementing oversight and regulation to mitigate potential harms.
The Trump administration has explored various frameworks, shifting from a laissez-faire stance to an executive order establishing a voluntary industry testing regime. More recently, the administration imposed export controls on Anthropic's Fable model and reportedly urged OpenAI to delay model releases due to cybersecurity concerns. There have also been reports that the administration is considering an executive order to restrict American access to Chinese-made open-source AI models.
The White House, while recognizing the overall advantages of an open-source approach, is also cautious about actions that could inadvertently benefit rival nations. Earlier this month, the White House announced the creation of the Gold Eagle AI cybersecurity clearinghouse, an initiative aimed at coordinating efforts among government, the private sector, and civil society to identify and address AI-discovered vulnerabilities. A senior White House official confirmed that supporting providers and maintainers of open-source AI tools is a significant component of this initiative.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed