
Cloudflare is offering its Vulnerability Discovery Harness as an open source skill to add security to agent systems.
Microsoft AI Red Team has open sourced several tools and harnesses. PyRIT – Python Risk Identification toolkit enables AI red teamers to run automated red teaming, with built in memory, supporting common targets, as well as custom endpoints.
RAMPART turns red-team findings and real-world incidents into repeatable tests that run as software changes. Clarity helps teams question design assumptions and identify potential failures before code is written.
Microsoft has also open sourced Assert , which converts natural language requirements and expected AI safety and security behaviors into executable evaluations.
Atlas is Wiz’s autonomous vulnerability research engine that orchestrates specialized AI agents to discover and validate security flaws across code and open source packages.
Visa has also joined the Open Secure AI Alliance, contributing its open sourced Visa Vulnerability Agentic Harness to help teams identify issues, support remediation and validation, quickly and safely.
Not every security or safety task calls for a general-purpose model. Specialized security and safety models are purpose-built for defense: trained to understand code, locate vulnerabilities and reason about threats at scale. They can work to support agentic workflows as systems of models, with both open and closed models working together to get the job done efficiently.
Cisco DefenseClaw is an open source agentic governance layer that sits on top of NVIDIA OpenShell to provide robust, automated security at the runtime level when scaling agentic workforces. Cisco has also released two of its Antares security small language models to help pinpoint where known vulnerabilities exist within a codebase; and Project CodeGuard to embed secure-by-default practices directly into AI coding workflows.
CrowdStrike is fine-tuning the NVIDIA Nemotron Nano model for cyber defense. Internal testing achieved 96% accuracy in generating investigation queries within Falcon LogScale, delivering a natural-language interface that boosts agent investigative efficiency. CrowdStrike has also published research demonstrating how a specialized NVIDIA Nemotron Nano reasoning model outperforms much larger models on Security Operations Center detection triage while introducing calibrated logit-based confidence to enable measurable, tunable, and auditable autonomous security decisions.
Mistral today released its new Shieldstral multimodal safety classifier model as open weights under Apache 2.0.
Seeing what an agent did is only part of the picture. Defenders also need to understand why it acted, whether the system behaves safely and how attacks are evolving in the real world.
Akamai brings insights from its State of the Internet reports and Security Intelligence Group research , drawing on real-world data to illuminate AI-era threats and explain how emerging exploits work so defenders can learn, adapt and respond. Cognition has released a trustworthiness evaluation , which measures alignment and security risks of open source-derived models. The evaluation demonstrates these risks can be mitigated via post-training.
Numbat is Perplexity’s open source agent security suite for client endpoints. It detects, investigates, and prevents agent activity across macOS, Linux and Windows — giving defenders a structured record of what agents actually did.
Uber open sourced key components of ADR (Agentic AI Detection and Response) , a production system that reconstructs the full causal chain of AI agent activity -– from prompt to reasoning, tool calls, and outcomes -– to help security teams detect threats. Today, ADR supports more than 200,000 agent sessions per day across 30,000 endpoints, using a two-tier analysis approach that combines efficient detection with deeper investigation for high-confidence threats.
Agent systems must remain dependable under disruption, contain failures and recover safely without losing critical state or exposing the broader environment.
LangChain is adding resilience capabilities to its open source frameworks — Deep Agents, LangGraph and LangChain — enabling agents to retry interrupted work, follow a safe recovery path, resume from a saved state instead of starting over and automatically fall back to alternative models when the primary model fails.
Veeam helps organizations keep the data and infrastructure behind AI resilient and recoverable with technologies such as Kanister , its open source framework for data protection on Kubernetes. It helps teams protect and recover AI workloads, vector databases, and data to a verified known-good state.
More contributions are coming. When members publish reusable mitigations, defenders across the ecosystem can inspect, adapt and improve them, helping security practices evolve as AI advances.
Join members of the Open Secure AI Alliance at Black Hat today, Tuesday, Aug. 4, at 5:15pm PT, for a group photo outside the Main Stage, Business Hall at the Mandalay Bay Convention Center.
Learn more or share interest in joining the Open Secure AI Alliance.
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://blogs.nvidia.com/blog/open-secure-ai-alliance-contributions/#primary
- https://blogs.nvidia.com/blog/author/justin-boitano/
- https://blogs.nvidia.com/blog/open-secure-ai-alliance-contributions/#disqus_thread
- Asus ProArt PA32UCDMR 32-inch 4K professional OLED monitor review: Precision, speed, and flexibility
- Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security
- Lenovo LOQ Essentials 15 Gen 11 Review: A good display meets a low-power RTX 5060
- Ten years later, the iconic GTX 1080 Ti still holds up in 1080p gaming, but not without showing its age — Redux testing highlights the wonders of 11GB VRAM & th
- Grab 32GB of Corsair DDR5 for an effective $230 right now in this 9950X3D combo deal —Newegg RAM bundle ships with 16-core AMD X3D chip alongside an MSI X870E b
Informational only. No financial advice. Do your own research.