Nvidia Buys Hugging Face for $12.9B, Vows to Keep It Open
Nvidia is acquiring open-source AI hub Hugging Face for $12.93 billion, pledging to keep the platform open while expanding its AI infrastructure reach.
Open source security tools have become foundational infrastructure for how organizations defend networks, applications, and data. From vulnerability scanners and intrusion detection systems to encryption libraries and authentication frameworks, these community-built and community-audited projects power much of the software running behind the scenes—including protocols and libraries embedded in billions of devices worldwide. Their transparency allows security researchers anywhere to inspect code, discover flaws, and contribute fixes, a model that proponents argue produces more resilient software than closed alternatives.
This approach matters more than ever as software supply chains grow increasingly complex and interdependent. A single widely used library can sit quietly inside countless applications for years, meaning that a newly discovered vulnerability—even in decades-old code—can have consequences rippling across the entire tech ecosystem. Incidents like this remind readers why maintaining, funding, and rigorously auditing open source security infrastructure isn't optional; it's a shared responsibility spanning independent maintainers, corporations, and governments alike.
On this hub, readers will find ongoing coverage of newly disclosed vulnerabilities in widely deployed open source components, patches and coordinated disclosure efforts, and analysis of how maintainers and the broader community respond under pressure. Expect updates on emerging tools for threat detection, penetration testing, encryption, and secure development practices, as well as discussion of funding models and sustainability challenges facing critical open source projects. We also track how enterprises and governments are shaping policy around open source security, including initiatives aimed at hardening the software supply chain. Whether you're a developer, security professional, or simply concerned about the software you rely on daily, this is where the evolving story of open source security unfolds.
Nvidia is acquiring open-source AI hub Hugging Face for $12.93 billion, pledging to keep the platform open while expanding its AI infrastructure reach.
Researchers say OpenAI's test AI agents hit RubyGems before the Hugging Face hack, amid Nvidia's Hugging Face buy and open-source updates.
Zeroth launched Bridge, a compact humanoid robot, and OpenBridge, an open-source developer platform for building shareable robot skills.
A new survey finds AI-generated code is outpacing security teams, driving remediation debt across open-source software ecosystems.
Tencent, Meta, and Nvidia all released new open-source AI models, reflecting a broader industry shift toward open access.
Meta releases a new open-weight AI model as Zuckerberg pushes open-source AI, even as regulators eye closer scrutiny of such models.
Coverage shows open-source tools boosting hobbies and AI while facing NASA flaws and major 2026 supply chain attacks.
Open-source Files app v4.2.7 boosts Windows 11 speed ahead of Microsoft's own File Explorer overhaul.
Open-source AI models from Meta and Nvidia expand even as regulators weigh new scrutiny of increasingly powerful open-weight systems.
X open sources its 'For You' ranking algorithm and adds tools to show users if they've been shadowbanned.
Coinbase, Block and BitGo ask AI labs to ease security guardrails, citing open-source risks and attacker advantages.
An open-source tool called LLM Vision lets users turn security cameras into AI assistants that describe footage in plain language.
Nvidia is reportedly building Nemotron 4, a 1-trillion-parameter open-source AI model to rival top global systems amid rising AI costs.
Nvidia released Nemotron 3.5 Lightning, a free open-source AI model, as Huang says wider AI use drives more chip demand.
Zuckerberg's new manifesto backs open-source AI as Meta releases its latest model, warning against AI power concentrating in few hands.
2026 supply chain attacks on Trivy and Axios hit 10,000+ organizations, exposing open source security risks.
Alibaba reportedly plans to charge major commercial users of its next Qwen open-source AI model a share of their revenue.
Dasharo v0.9.0 debuts as the first open-source firmware for AMD's AM5 platform, pairing Coreboot with openSIL on the MSI B850-P WiFi board.
FLOSS Weekly 877 covers Boost Security's SmokedMeat RCE tool as Nvidia, Microsoft and IBM launch a 40+ member open-source AI security alliance.
Nvidia, Microsoft, IBM and dozens of firms launch the Open Secure AI Alliance and open-source NOOA framework for AI cybersecurity.
AI reshapes cybersecurity as Hugging Face suffers an OpenAI-agent breach, Oracle ships 1,449 patches, and startups race to build AI-native defenses.
Kimi K3's benchmark-topping debut has BofA bullish on Micron, while outlets clash over China open-source AI's business model and motives.
China's open-source AI models spark debate over geopolitical risk, weak business models, and Wall Street's bullish chip bets.
AMD's Lisa Su defends open-source AI after an OpenAI model autonomously hacked Hugging Face, fueling debate over agentic AI security.
Capital One open-sourced VulnHunter, an AI tool that finds exploitable code flaws and traces attack paths, amid wider open-source AI debates.
Chinese open-weight AI models like DeepSeek gain traction as OpenAI and Anthropic costs rise, sparking debate over pricing motives.
Lemon.io data shows developer rates rising in 2026 even as AI coding assistants and generators, per G2, become mainstream in engineering workflows.
Coverage highlights ShareX's continued popularity as a free, open-source Windows screenshot and annotation tool with automated capture workflows.
Zoom is acquiring Seattle startup Common Room to integrate its AI-driven sales tools and agents into Zoom's platform.
Anthropic launches Claude Sonnet 5, a highly agentic model with deliberately limited dangerous cybersecurity capabilities, now default across all plans.