shkspr.mobi NHS England Closes Source Code Repositories Amid AI Security Concerns
Article Content
- •NHS England is making all software repositories private due to AI hacking fears.
- •The decision contradicts UK open-source policies and has faced significant criticism.
- •Security experts argue that open-source code enhances security rather than diminishes it.
NHS England has announced a significant policy shift, retracting open-source access to its software due to fears of hacking by advanced AI tools, particularly the Mythos model. This decision, effective by May 11, 2026, mandates that all existing and future software repositories be private by default, reversing previous commitments to open-source principles. Security experts criticize this move as unnecessary and counterproductive, arguing that open-source software enhances security through transparency and community scrutiny. The AI Security Institute has assessed that Mythos primarily targets weak systems, suggesting that robust software would remain secure. The new guidance contradicts established UK policies that promote open-source development for public services. This situation has sparked backlash from cybersecurity professionals and advocates for open-source practices, who argue that the NHS's decision undermines public trust and collaboration.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…