Opens in a new tab

Hottest open-source cybersecurity tools, September 2026

  • Home
  • Blog
  • Hottest open-source cybersecurity tools, September 2026
Open hardshell case of open-source cybersecurity tools glowing in blue light

September 2026 open-source cybersecurity releases worth knowing

Several open-source cybersecurity projects drew attention this month for solving real problems across cloud, identity, and AI agent control. The tools below cover secrets scanning, containerized AI infrastructure, access control, Windows driver research, password management, and runtime policy enforcement for AI coding agents, all released as free, source-available software that security teams can self-host and audit.

What is Sift and where does it search for secrets?

Sift is a free, open-source command-line tool that hunts for credentials and other sensitive data across the systems a company already uses. It scans local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams channel files, Slack messages, and Jira and Confluence. That breadth matters because secrets rarely stay in one place, and a credential pasted into a Slack thread or a Jira ticket is just as dangerous as one sitting on a developer laptop. A penetration testing consultancy built Sift for its own engagements and released it for free.

ToolHive: a containerized runtime for Model Context Protocol servers

ToolHive is an open-source platform that runs Model Context Protocol (MCP) servers inside containers. An MCP server is the connector that lets an AI client such as Cursor or Claude Code reach an outside tool. ToolHive ships under Apache 2.0, and the runtime, the Kubernetes operator, and the registry are all free to self-host, which removes a major friction point for teams that want to use MCP without giving up control over where the code runs.

How does AI-Infra-Guard scan AI systems for known vulnerabilities?

AI-Infra-Guard is an open-source security scanner for AI systems, built by Tencent’s Zhuque Lab. It fingerprints running services such as Ollama, vLLM, and ComfyUI, then checks them against more than 1,600 known CVEs. The tool also inspects MCP servers and agent skills across 14 categories of risk and runs jailbreak evaluations against a target model, giving security teams a single instrument for both component-level and prompt-level exposure.

Permify: open-source authorization as a service

Permify is an open-source authorization service that answers access questions at run time, for example whether a given user can view a specific document, or which posts members of a team are allowed to edit. It keeps those rules in one place, apart from the application code that would otherwise carry them, so policy changes do not require redeploys and audits do not require reading every service.

What does DeepZero do with vulnerable Windows drivers?

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. Point it at a folder of binaries and it parses them, strips them down, scans them, discards the uninteresting ones, and asks a language model whether what survives looks attackable. Pipelines are written in YAML, the code runs on Python 3.11 and up, and the tool fits cleanly into a research workflow without forcing a custom framework.

Gopass: a team-oriented command-line password manager

Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager, which keeps the learning curve low for engineers already comfortable with that workflow and gives teams a familiar way to share secrets across a small group.

Prismor: runtime policy enforcement for AI coding agents

Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and checks each tool call against a policy before the call runs. Every call receives one of three verdicts: allow, warn, or block, which gives engineering teams a way to approve high-risk actions, flag suspicious ones, and stop dangerous ones without disabling the agent entirely.

Authorizer: open-source authentication and authorization for apps

Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they choose. Its maintainers have built a permissions engine and an interface for AI agents into the same Go program that logs users in, so a chatbot can ask whether a user may see a document before it fetches that document.

FAQ

What are the top new open-source cybersecurity tools in September 2026?

Notable releases this month include Sift for secrets scanning, ToolHive for running MCP servers in containers, AI-Infra-Guard for scanning AI systems against known CVEs, Permify for authorization as a service, DeepZero for vulnerable Windows driver research, Gopass as a command-line password manager, Prismor for runtime control of AI coding agents, and Authorizer for app authentication.

Are these cybersecurity tools free to use?

Yes. Each project listed is open-source and free to self-host. ToolHive in particular ships under the Apache 2.0 license, which permits broad use without licensing fees.

Which tool handles AI agent access control?

Prismor sits between an AI coding agent and the actions it wants to take, returning allow, warn, or block for every tool call based on a configurable policy. Authorizer also exposes a permissions interface that AI agents can query before accessing a document.


This article summarizes reporting from helpnetsecurity.com.

← All Articles