The current state of trusted open source

Chainguard, the go-to source for open source, has a unique perspective on how modern organizations are actually using open source software and where they face risks and operational burdens. With a growing customer base and an extensive catalog of over 1,800 container image projects, 148,000 versions, 290,000 images, 100,000 language libraries, and nearly 500 million […]

Cisco patches ISE security vulnerability after releasing public PoC exploit

January 8, 2026Ravi LakshmananNetwork security/vulnerabilities Cisco has released updates that address medium-severity security flaws in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) using public proof-of-concept (PoC) exploits. This vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), exists in the licensing feature and could allow an authenticated, remote attacker with administrator privileges to access […]

Researchers discover NodeCordRAT hidden in npm Bitcoin-themed packages

January 8, 2026Rabi LakshmananMalware/Cloud Security Cybersecurity researchers discovered three malicious npm packages designed to deliver previously undocumented malware called NodeCordRAT. Below are the names of all removed packages as of November 2025. These were uploaded by a user named ‘wenmoonx’. “The bitcoin-main-lib and bitcoin-lib-js packages run a postinstall.cjs script during installation, which installs bip40, a […]

Coolify discloses 11 critical flaws that allow full server compromise on self-hosted instances

January 8, 2026Rabi LakshmananVulnerabilities / Container Security Cybersecurity researchers have detailed multiple-severity security flaws affecting Coolify, an open-source self-hosting platform. This could lead to authentication bypass or remote code execution. Here is the list of vulnerabilities: CVE-2025-66209 (CVSS Score: 10.0) – Command injection vulnerability in the database backup feature allows an authenticated user with database […]

OpenAI launches ChatGPT Health with isolated and encrypted health data controls

January 8, 2026Ravi LakshmananPrivacy / Artificial Intelligence Artificial intelligence (AI) company OpenAI on Wednesday announced the launch of ChatGPT Health, a dedicated space where users can have conversations with chatbots about their health. That’s why the Sandbox experience gives users the option to securely connect their medical records and wellness apps like Apple Health, Function, […]

CISA reports bugs in Microsoft Office and HPE OneView as being actively exploited

January 8, 2026Rabi LakshmananVulnerabilities / KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws affecting Microsoft Office and Hewlett Packard Enterprise’s (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2009-0556 (CVSS Score: 8.8) – Code injection […]

Ford is developing AI assistant and new hands-free BlueCruise technology

Ford announced Wednesday at the 2026 Consumer Electronics Show that it is developing an AI assistant that will debut in its smartphone app before expanding to its vehicles in 2027. The company is also previewing the next generation of its BlueCruise advanced driver assistance system, which will be cheaper to manufacture and more capable, ultimately […]

Discord and Mercor investor Niko Bonatsos leaves General Catalyst and plans new VC firm

After many years leading General Catalyst’s seed strategy, Niko Bonatsos has left the company. Bonatsos, known for backing IPO-hopped Discord and $10 billion startup Mercor, told TechCrunch he plans to start a new early-stage VC firm with “friends.” Mr. Bonatsos is the latest investor to leave General Catalyst, which recently expanded beyond the traditional venture […]

Yes, LinkedIn banned AI agent startup Artisan, but now it’s back

Over the past few days, several posts on LinkedIn and Twitter/X have gone viral after Artisan AI, one of San Francisco’s most talked-about AI companies, suddenly disappeared from LinkedIn. The company’s LinkedIn page, each employee’s profile, and posts from executives all displayed the message “This post cannot be viewed.” Artisan CEO Jaspar Carmichael-Jack confirmed to […]