WhisperX tag archive

#open-source security

This page collects WhisperX intelligence signals tagged #open-source security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-03-30 04:27:03 · GitHub Issues

1. AxonOps go-audit Library Lacks Critical Security Policy, Exposing Regulated Environments to Unreported Vulnerabilities

The AxonOps go-audit library, a security-critical tool designed for regulated environments, currently operates without a formal vulnerability disclosure policy. This significant gap leaves security researchers with no documented, responsible channel to report potential security flaws, creating a blind spot for users wh...

The Lab · 2026-03-31 11:27:18 · GitHub Issues

2. Axios NPM Package Compromised: Malicious Versions Deploy Remote Access Trojan in Supply-Chain Attack

A critical supply-chain attack has compromised the widely used Axios HTTP client library on the NPM registry, with malicious versions deploying a remote access trojan (RAT). This incident represents a direct infiltration of a foundational JavaScript package, posing an immediate and severe risk to countless applications...

The Lab · 2026-04-01 01:56:57 · Hacker News

3. AI Recruiting Startup Mercor Hit by Cyberattack, Hackers Claim Data Theft via Compromised LiteLLM

AI recruiting startup Mercor has confirmed a security breach after an extortion-focused hacking group claimed responsibility for stealing data from the company's internal systems. The incident is directly tied to the compromise of the open-source LiteLLM project, a widely used library for unifying large language model ...

The Lab · 2026-05-10 21:31:45 · r/netsec

4. 21-Year-Old FreeBSD Vulnerability Enables Remote Code Execution, CVE-2026-42511 Revealed

Security researchers have disclosed a critical remote code execution vulnerability in FreeBSD that remained unpatched for 21 years before disclosure. The flaw, tracked as CVE-2026-42511, affects multiple versions of the open-source operating system and could allow unauthenticated attackers to execute arbitrary code rem...

The Lab · 2026-05-12 16:18:29 · Techmeme Echo RSS

5. Microsoft Probes Compromised Mistral AI PyPI Package Tied to Mini Shai-Hulud Supply Chain Attack

Microsoft has initiated an investigation into a compromised Python package uploaded to the Python Package Index (PyPI) under the Mistral AI branding. Security researchers have confirmed the malicious package, identified as version 2.4.6, is connected to the broader Mini Shai-Hulud supply chain campaign, highlighting th...