#opensourceSecurity
🚨 Breaking: The OpenSSF welcomes Honda Motor Co., Ltd. and Guidewire Software, Inc. as new members!

From Delhi, we’re celebrating #SOSSCommunityDay India, advancing collaboration and innovation to secure open source software.

openssf.org/press-releas...

#OpenSSF #OpenSourceSecurity
December 10, 2024 at 4:12 AM
Malicious MemTensor packages deliver sckit credential-stealer via npm & PyPI—update and rotate secrets now. #SupplyChain #Malware #OpenSourceSecurity #CredentialTheft #CI/CD #MemTensor thedailytechfeed.com/memtensor-su...
September 23, 2026 at 2:13 PM
September 1, 2025 at 11:00 PM
Interested in working on #opensourcesecurity, my group is hiring
https://jobs.careers.microsoft.com/global/en/job/1575779/Senior-Security-Program-Manager
July 2, 2023 at 1:44 AM
Breaking threat alert from DigitalOcean and Microsoft Azure! Mass exploitation campaign detected by actor codenamed Goofy Khaki Flamecrest. Find out about the 4 key events that characterized the campaign 👇

#cybersecurity #cohortattack #threaintel #opensourcesecurity
April 25, 2025 at 10:48 AM
Alpha‑Omega teams up with OpenSSF to boost open‑source security against AI‑driven attacks. New funding means faster vulnerability detection for maintainers. Curious how Google DeepMind fits in? Dive in! #OpenSourceSecurity #AIThreats #OpenSSF

🔗 aidailypost.com/news/alpha-o...
March 17, 2026 at 4:42 PM
🚨 OpenSSF community is heading to Denver for #OpenSSFCommunity Day NA 2025 on June 26!
AI security, SBOM tooling, real-world TTX, and more — all in one day.
🌄 Co-located with #OSSummit
🛡️ Agenda is live — register now!
🔗 openssf.org/blog/2025/04...
#CyberSecurity #OpenSourceSecurity
April 9, 2025 at 7:47 PM
🎧 CRob and Michael Winser discuss #AlphaOmega’s work improving open source security on he latest What’s in the SOSS? Podcast. From building trust to tackling vulnerabilities, this episode is packed with insights.

Listen now openssf.org/podcast/2024...

#OpenSourceSecurity
December 10, 2024 at 2:38 PM
This episode of #OpenSourceSecurity I chat with @alex.zenla.io from @edera.dev about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one
TARmageddon with Alex Zenla
Josh discusses the TARmageddon vulnerability with Alex Zenla, CTO of Edera. In this episode, we explore the discovery of the TARmageddon vulnerability. It’s especially interesting because it’s Rust, b...
opensourcesecurity.io
December 1, 2025 at 7:04 PM
Our Director of Programs Erik Möller spoke to @josh.bressers.name on the #OpenSourceSecurity Podcast about how we work, where we invest, and the importance of supporting #opensource maintainers in times of AI.

🎧 Take a listen: opensourcesecurity.io/2026/2026-08...
September 2, 2026 at 10:20 AM
#OpenSourceSecurity has a chat with @sethmlarson.dev about @python.org security

Seth has a new whitepaper, there's a CFP open (which you should submit a paper to), and some discussion about the PSF grant situation

It's always fun to chat with Seth, I learn a ton every time!
Python Security with Seth Larson
In this episode Seth Larson gives us a cornucopia of topics relating to Python security. Seth discusses the Python Software Foundation’s decision to reject a significant grant NSF. Diversity is a big ...
opensourcesecurity.io
November 24, 2025 at 3:58 PM
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=5jT7yhBi5CM
June 25, 2026 at 7:00 PM
Here are the new malicious packages you should watch for:
• jsonupon
• jsonucap
• jsoncap
• jsonauto
• jstoauto
• jsonpino
(... more in next reply)
#OpenSourceSecurity #JavaScript #DevSecOps 🧵3/6
November 12, 2025 at 10:08 PM
📢 New 7ASecurity public #SecurityAudit report
🔐 Bayanat audited by 7ASecurity: 43 findings & recommendations, all resolved & verified. ✅
🔗 7asecurity.com/blog/2026/09...
💬 Feedback welcome

#CyberSecurity #OpenSourceSecurity #AppSec #InfoSec #Bayanat
Bayanat audit by 7ASecurity - 7ASecurity Blog
7ASecurity audited Bayanat across web, API/auth, evidence workflows, deployment, fuzzing, supply chain, and threat modeling. Read the public report.
7asecurity.com
September 22, 2026 at 12:24 PM
We explore the intricacies of the #OpenSource Project Security Baseline, its significance in the current technological landscape, and how it could revolutionise the #opensourcesecurity approach.

www.frameworktraining.co.uk/news-insight...

#opensourcesecurity
Understanding the Open Source Project Security Baseline: A Comprehensive Guide
We explore the intricacies of the Open Source Project Security Baseline, its significance in the current technological landscape, and how it could revolutionise the open source security approach.
www.frameworktraining.co.uk
April 11, 2025 at 10:28 AM
🚨 62% of open source stewards lack dedicated personnel for incident response—a key CRA requirement.

Learn more in our full report: www.linuxfoundation.org/research/cra...

#CRA #EUcompliance #OpenSourceSecurity #LinuxFoundationEurope
April 11, 2025 at 1:31 PM
💎 #ApacheGeode alert: CSRF in the management API (CVE-2025-47410, CVSSv3 8.8). Attackers can trick authenticated admins into running gfsh commands remotely. Fix: upgrade to 1.15.2+.
#AppSec #OpenSourceSecurity #CyberSecurity #CVE 🧵6/7
October 28, 2025 at 2:42 PM
Thank you Open Source Security for sponsoring EuroRust in Paris as a Partner 🦀💜

It is great to have you on board!

Learn more about OpenSourceSecurity Inc here ➡️ opensrcsec.com

#rustlang #EuroRust25
March 26, 2025 at 10:45 AM
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund

Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve

#OpenSourceSecurity #rust #RustFoundation
Rust Foundation Maintainers Fund with Lori and Niko
Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It’s a great discussion w...
opensourcesecurity.io
July 6, 2026 at 2:35 PM
I spoke with Lars Wirzenius on #OpenSourceSecurity about two really cool projects he's working on

Ambient is a distributed CI/CD system written in Rust

Radicle is a distributed Git Forge

It's a really fun chat and I learned a lot

opensourcesecurity.io/2025/2025-03...
Distributed CI and Git with Lars Wirzenius
I got to chat with Lars about a new CI/CD system he’s been working on called Ambient. It sounds really cool and does some very clever things today, with even more things planned in the future. We also...
opensourcesecurity.io
March 31, 2025 at 1:31 PM
Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

Free registration: luma.com/5mwalp6p?tk=...

#Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI
Trusted Publishing — Eliminating Credentials from Your Release Workflow · Luma
6:00-6:30 Network - Pizza provided 6:30-7:30 Talk and Q&A 7:30-8:00 Network In February 2024, about 10% of PyPI uploads used Trusted Publishers. By October…
luma.com
August 24, 2026 at 8:49 PM
This week #OpenSourceSecurity chats with @andrewnez.bsky.social about Ecosyste.ms

Ecosyste.ms is a massive collection of data about open source

It's an amazingly useful collection of data. If you're doing anything that needs information about open source you should check it out
Ecosyste.ms with Andrew Nesbitt
I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is...
opensourcesecurity.io
June 2, 2025 at 5:58 PM
🚀 Looking to break into #Cybersecurity or gain hands-on experience in #OpenSourceSecurity? The OpenSSF BEAR WG is teaming up with LFX Mentorship for the Summer 2025 program — and applications are now open!

Projects include #RSTUF and #gittuf, with a stipend for mentees!
May 8, 2025 at 8:15 PM
It was fantastic to be a part of this program - we learned so much and continue to implement our backlog of tasks to secure Mautic's ecosystem.

If you're considering applying, we wholeheartedly recommend doing so!

#OpenSource #Security #GitHub #OpenSourceSecurity #SecureOpenSource
🚀 GitHub is on a mission to supercharge open-source security! We've partnered with 71 key open-source projects, giving them tools, funding, and playbooks to boost security. 🔐
Want your project to be part of this effort? Now’s the time to get involved! 💪
🔗 Find out more: github.blog/open-source/...
Securing the supply chain at scale: Starting with 71 important open source projects
Learn how the GitHub Secure Open Source Fund helped 71 open source projects significantly improve their security posture.
github.blog
August 11, 2025 at 5:51 PM
This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety
Rustls with Dirkjan and Joe
Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...
opensourcesecurity.io
December 29, 2025 at 2:49 PM