Rss.Slashdot Cal.com Transitions to Closed Source Due to AI-Driven Security Risks
Article Content
- •Cal.com is moving to a closed source model to enhance security against AI-driven attacks.
- •AI tools can now scan open source codebases for vulnerabilities much faster than human efforts.
- •Cal.diy will remain an open source option for hobbyists despite the main product's transition.
Cal.com has announced its shift from open source to a closed source model for its scheduling software, citing the increased risk of AI-driven attacks that can easily exploit vulnerabilities in public codebases. Co-founder Peer Richelsen stated that the reliance on human effort for open source security is no longer viable, as AI tools can now rapidly identify and exploit weaknesses. The company emphasized the need to protect customer data, particularly booking information, which is sensitive and critical to their operations. While the main product will no longer be open source, Cal.diy will remain available for hobbyists under the MIT license. The decision reflects a broader trend in the software industry where open source projects may face heightened risks due to advancements in AI security tools. CEO Bailey Pumfleet noted that the transition is not a rejection of open source principles but a necessary step to mitigate risks in the current threat landscape. The company hopes to return to open source in the future as security conditions improve.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Cal.com in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…