The Open Source Question Coming Due in SeptemberEU CRA disclosure obligations start in about two months. Most finance and security leaders have not rehearsed the answer.In roughly two months, the EU Cyber Resilience Act's first disclosure obligations take effect. Any organization with a product in scope will need to report actively exploited vulnerabilities within 24 hours, for products already on the market, not just new ones. Most finance and security leaders have not rehearsed what that report would actually say if they had to produce it today.That is not a compliance detail. It is a rehearsal problem, and rehearsal problems are the ones that get discovered at the worst possible moment, in front of the worst possible audience.Here is the exercise I would run before September, not after. Pick one dependency in your environment, any one, and try to answer three questions in writing: who decided this was acceptable to run, what would you show a regulator who asked you to document that decision, and what would it cost you if the answer turned out to be nobody and nothing.Most executives who attempt this exercise get as far as "we have a scanner" and stop, because that is the only artifact anyone thought to produce. A scanner report is not a decision record. It documents what a particular tool found on a given day. It does not document who evaluated the risk of running that dependency in the first place, what alternative was considered and rejected, or why the answer was yes. A regulator asking for a defensible decision is not going to accept a tool's output as a substitute for a decision nobody made.Socket recently tied a campaign called PolinRider, linked to North Korean state actors, to 162 malicious release artifacts across 108 packages and repositories spanning five different software ecosystems. I want to be precise about what that number represents. It is not one bad actor exploiting one bad dependency. It is a patient, well-resourced campaign working the intake layer of the software supply chain across five ecosystems at once. If a vendor showed up in 108 different places in your environment without anyone in procurement noticing, that would be a control failure worth a board briefing on its own. Open source gets a pass on that scrutiny for one reason: it never came with an invoice, so nobody in the organization was ever assigned to watch for it the way they would watch a vendor.The AI acceleration piece is not theoretical. Researchers are describing an open weight model, GLM-5.2, as capable of advanced coding and cybersecurity work at a level close to models kept under much tighter control, and it can be downloaded and run locally, with no vendor standing between the model and whoever is using it. That means the volume of AI generated dependencies entering your environment, and the sophistication available to whoever wants to find a way in, are both accelerating at the same time, on a timeline that has nothing to do with your audit calendar.It is worth noting what preparedness actually looks like right now, because it is not hypothetical. IBM and Red Hat recently expanded a service called Project Lightwell specifically to give regulated industries, starting with financial institutions, a way to share vulnerability data and coordinate patching confidentially, with SBOMs and compliance data attached to every package by default. That is not a product pitch. It is a signal of where the bar is moving. The organizations building toward that bar will have an answer ready in September. Most will not, and the gap between those two groups is not a technology gap. It is a documentation gap that started accumulating long before anyone thought to check.In the current regulatory environment, a security failure is no longer only a company problem. The SEC's cybersecurity disclosure rules and the EU CRA both point the same direction: at some point soon, someone is going to ask an executive to produce the record of a decision, and "we had a scanner" is not going to be the record anyone is looking for. A scanner tells you what it found. It does not tell you who decided the underlying policy was acceptable, or when, or why.This is not, in the end, a security team's homework assignment. The decision about what a company allows into its own software is a business decision with the same weight as any vendor contract the finance team already reviews, and it should be owned with the same rigor. Handing the entire question to security and expecting a scanner to stand in for governance is how organizations end up with a technical answer to a question a regulator is going to ask in business terms.Most organizations can answer what their scanner found last quarter. Almost none can answer who decided, in writing, what their AI tools and their open source dependencies are allowed to bring into production, and whether that decision would survive being read aloud in front of a regulator. September is not far away. The organizations that treat the next ten weeks as a documentation exercise will have an answer. The ones that treat it as a technology problem will still be looking for a scanner report that was never going to be the right document in the first place.
Nguồn: https://securityboulevard.com/2026/07/the-open-source-question-coming-due-in-september. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
Đọc tin ở đây, luyện code, học theo lộ trình và luyện IELTS trên các sản phẩm anh em — tất cả kết nối với nhau trong hệ sinh thái 8 Sync Dev.
Cổng chính của hệ sinh thái: giới thiệu sản phẩm, blog và bảng giá trọn bộ.
Khám pháHọc theo lộ trình rõ từng chặng: video, quiz chấm tự động, certificate và mentor đang làm nghề.
Xem lộ trìnhHơn 600 bài FREE, đề tiếng Việt, chấm tự động 7 ngôn ngữ — chạy ngay trên trình duyệt.
Redential là công cụ đọc lịch sử git trên máy cá nhân, tạo hồ sơ kỹ thuật dựa trên những gì nhà phát triển thực sự xây dựng mà không tiết lộ code. Người dùng có thể kiểm soát dữ liệu chia sẻ và bảo vệ trực tiếp trước nhà tuyển dụng thông qua các buổi phỏng vấn live, cung cấp bằng chứng đáng tin cậy hơn CV truyền thống.
Là một lập trình viên cần tìm kiếm cơ hội công việc hoặc chứng minh năng lực thực tế của mình, Redential là giải pháp giúp bạn chứng minh thành tích thực sự qua lịch sử code cá nhân mà không cần phụ thuộc vào CV dễ bị giả mạo.

Harness, công ty nền tảng cung cấp phần mềm AI, vừa mở rộng nền tảng của mình để bao phủ toàn bộ vòng đời phát triển AI Agent.
Lập trình viên phát triển AI nên đọc bài này vì nó giới thiệu Harness Agent DLC – công cụ tự động hóa và mở rộng quy trình phát triển các AI Agent, giúp tiết kiệm thời gian, giảm lỗi và tối ưu hóa hiệu suất từ giai đoạn thiết kế đến triển khai, đặc biệt quan trọng khi phát triển các hệ thống thông minh phức tạp.
Các mô hình ngôn ngữ lớn (LLM) hiện nay có tỷ lệ dương tính giả cao và không xem xét ngữ cảnh của các lần quét, khiến công việc của các chuyên gia bảo mật ứng dụng (AppSec) trở nên phức tạp hơn.
Lập trình viên nên đọc bài này để hiểu cách các mô hình ngôn ngữ lớn (LLM) hiện nay thường gây ra nhiều sai sót khi phát hiện và xếp hạng lỗ hổng, từ đó giúp họ nhận thức về những rủi ro thực tế khi tự tin sử dụng công cụ tự động mà không kiểm tra kỹ lưỡng.

Hầu hết dự án phát hiện xâm nhập bằng machine learning dừng lại ở mô hình, huấn luyện trên dữ liệu, in ra điểm validation rồi dừng lại.
Là người phát triển hệ thống an ninh mạng thực thời, bạn cần hiểu cách chuyển đổi mô hình ML thành một dashboard phản hồi nhanh, tích hợp với các giao thức mạng và cơ sở dữ liệu để bảo vệ hệ thống hiệu quả.
Canonical vừa công bố ba lỗ hổng bảo mật mới trong snapd, bao gồm CVE-2026-8933 (nâng quyền cục bộ, ảnh hưởng Ubuntu 22.04+), CVE-2026-15226 (thoát khỏi Snap confinement) và CVE-2024-5300 (lỗ hổng cũ nhất, từ Ubuntu 16.04, cho phép truy cập mật khẩu băm).
Lập trình viên cần đọc bài này để cập nhật kiến thức về các lỗ hổng bảo mật trong hệ thống phân phối Ubuntu, đặc biệt là về Snap, để có thể cải thiện an toàn cho các ứng dụng hoặc hệ thống chạy trên nền tảng này, tránh rủi ro từ các exploit mới.
Ngày càng nhiều dự án mã nguồn mở rời khỏi GitHub do lo ngại về thời gian downtime thường xuyên, quyền sở hữu của Microsoft, việc đào tạo AI trên mã nguồn, và định hướng chính trị. Các lựa chọn thay thế như Codeberg (dựa trên Forgejo), Sourcehut, Gitea và các nền tảng self-hosted đang thu hút sự quan tâm.
Những lập trình viên quan tâm đến tự do và bảo mật của mã nguồn nên đọc để biết cách chuyển sang các nền tảng tự chủ như Codeberg, tránh rủi ro về quyền sở hữu, AI hóa và kiểm soát chính trị từ GitHub.
Node.js là môi trường runtime JavaScript miễn phí, mã nguồn mở, đa nền tảng, cho phép lập trình viên xây dựng server, ứng dụng web, công cụ dòng lệnh và scripts.
Lập trình viên nên đọc bài này để cập nhật về các bản vá an toàn cho Node.js 2026, giúp bảo vệ ứng dụng hiện tại khỏi các lỗ hổng mới có thể dẫn đến tấn công xâm nhập hoặc gián điệp.