Artificial Intelligence
Top cyber official wants US open-source AI adopted worldwide
National Cyber Director Sean Cairncross’s remarks come as the White House has excluded open-weight models from voluntary security testing and as new hacking incidents underscored risks posed by autonomous AI.
Cybersecurity
Amazon uncovers broad North Korean hacking campaign against open-source software
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.
Artificial Intelligence
Anthropic calls for threading the needle on open-source AI
Anthropic CEO Dario Amodei cited China as the primary threat to such a paradigm and cast doubt over the narrative of open-source as a cybersecurity asset.
Artificial Intelligence
Over 30 companies form open-source AI alliance
Helmed by NVIDIA, the Open Secure AI Alliance looks to shore up industry support for continued access to and work with open-source artificial intelligence models.
Cybersecurity
North Korea-linked hackers suspected in Axios open-source hijack, Google analysts say
“The full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will have far reaching impacts,” a chief Google analyst said.
Cybersecurity
Sen. Cotton urges top White House cyber official to protect open-source software
A letter from the chairman of the Senate Intelligence Committee cites previous Nextgov/FCW reporting about a potential Russian backdoor into a Defense Department software suite.
Defense
Industry groups push to keep open-source measures in annual intelligence bill
They’re backing provisions in the House version of the Intelligence Authorization Act. But multiple intelligence community elements are hesitant about the measures, people familiar say.
Exclusive
Cybersecurity
Report: Russia-based Yandex employee oversees open-source software approved for DOD use
The package is listed inside Platform One’s Iron Bank, a vetted Defense Department software repository, people familiar say.
Cybersecurity
DARPA unveils winners of AI challenge to boost critical infrastructure cybersecurity
The AI Cyber Challenge aims to accelerate the distribution of open-source AI models to help patch the code that powers major infrastructure like water treatment plans and power grids. Four of the open-source models have already been made available for use.
Cybersecurity
Foreign adversaries are trying to weaponize open-source software, report finds
Hacking units affiliated with nation-state adversaries are subtly contributing to open-source software tools and working to insert backdoors into publicly available code used by millions worldwide, new research says.
Artificial Intelligence
National AI Action plan should expand open-source offerings, respondents say
During the open comment period, a multitude of entities — from private sector to academic research bodies — touted the benefits of a robust open-source AI ecosystem.
Ideas
Strengthening open source: A roadmap to enhanced cybersecurity
COMMENTARY | Open-source software is a cornerstone of American innovation, underpinning critical infrastructure and driving economic growth.
Cybersecurity
Half of critical open source projects contain memory-unsafe code, U.S. cyber agency says
The findings come after recent hijacking attempts into major open-source tools.
Cybersecurity
New mailing list aims to share hacking attempts on open-source projects
The Siren email list allows members to share active exploitations of open-source projects, fueled by recent attempts to sabotage free-to-use software tooling
Artificial Intelligence
Feds beware: New studies demonstrate key AI shortcomings
Recent studies have started to show that there are serious downsides when it comes to such programs’ ability to produce secure code.
Cybersecurity
Hackers tried to breach, disable widely used open-source Java tools, groups warn
The alert comes just after a possible nation state entity attempted to hijack an open-source Linux tool last month.
Cybersecurity
Linux backdoor was a long con, possibly with nation-state support, experts say
If the XZ Utils vulnerability hadn’t been caught in time, hackers would have had a “skeleton key to the world,” one analyst told Nextgov/FCW.
Artificial Intelligence
NTIA explores the benefits and risks of open-weight AI models
A new request for information issued by the National Telecommunications and Information Administration will inform regulatory policy on open-weight models.
Ideas
Taking open source risks seriously
COMMENTARY | Software bills of materials don't address what tech leaders should actually do to make sure open source components are safe to use.
Cybersecurity