#securitycon
Heading to #KubeCon + #CloudNativeCon + Open Source #SecurityCon? Let’s connect at ZarfFest! 🎉

Join OpenSSF and Defense Unicorns for an evening of drinks, light bites, and great conversations with fellow builders, maintainers, and open source friends.

defenseunicorns.com/events/zarff...
ZarfFest: A Defense Unicorns x OpenSSF Happy Hour
ZarfFest: A KubeCon Happy Hour Presented by Defense Unicorns and OpenSSF Join Defense Unicorns and OpenSSF for ZarfFest, a happy hour bringing together the open source, cloud native, and software sec...
defenseunicorns.com
September 25, 2026 at 7:01 PM
We published this on Monday, in case you missed it: OpenSSF Welcomes New Members as SLSA, Gemara, and AI Security Efforts Mature - FOSS Force buff.ly/3stijbd
OpenSSF Welcomes New Members as SLSA, Gemara, and AI Security Efforts Mature - FOSS Force
At Amsterdam's SecurityCon Europe, the Linux Foundation's OpenSSF adds new members and showcases progress on SLSA, Gemara, and AI security.
buff.ly
March 25, 2026 at 7:30 PM
At Amsterdam’s SecurityCon Europe, the Linux Foundation’s OpenSSF adds new members and showcases progress on SLSA, Gemara, and AI security. fossforce.com/2026/03/open...
OpenSSF Welcomes New Members as SLSA, Gemara, and AI Security Efforts Mature - FOSS Force
At Amsterdam's SecurityCon Europe, the Linux Foundation's OpenSSF adds new members and showcases progress on SLSA, Gemara, and AI security.
fossforce.com
March 23, 2026 at 5:29 PM
Big news @ #securitycon #KubeCon EU — Canonical, publishers of Ubuntu, have joined the Rust Foundation as a Gold Member! Canonical's investment supports the long-term health of #rustlang and highlights its growing role in resilient systems. rustfoundation.org/media/canoni... 🦀
March 23, 2026 at 9:01 AM
At Open Source #SecurityCon Europe, we welcome Helvethink, Spectro Cloud, and Quantrexion as General Members, introduce Kusari Inspector, and launch the OpenSSF Ambassador Program.

Read the Announcement: openssf.org/press-releas...
March 23, 2026 at 8:27 AM
🚨 Today at Open Source SecurityCon: Don't miss the "It's Not If, It's When" panel. Anchore's Josh Bressers joins a quality panel of guests to talk about practical software supply chain attack prep.

📍 Hall 8 | Room D | 11:50 CET
https://sched.co/2DY3p

#KubeConEU
March 23, 2026 at 7:30 AM
OpenSSF Celebrates New Members, No-Cost Tooling, and Project Milestones
_Foundation welcomes Helvethink, Spectro Cloud, Quantrexion as members, offers Kusari Inspector for free to projects, and celebrates increased investment in AI security_ **AMSTERDAM – Open Source SecurityCon Europe – March 23, 2026 –** The Open Source Security Foundation (OpenSSF), a cross-industry initiative of the Linux Foundation that focuses on sustainably securing open source software (OSS), today announced new members and key project momentum during Open Source SecurityCon Europe. New OpenSSF members include Helvethink, Spectro Cloud, and Quantrexion, who join the Foundation as General Members. As members, these companies will engage with working groups, contribute to technical initiatives, and help guide the strategic direction of the OpenSSF. Together, members support open, transparent, and community-driven security innovation, and the long-term sustainability of the Foundation. “Open source security continues to evolve significantly in the face of new, automated threats,” said Steve Fernandez, General Manager of OpenSSF. “Our member organizations are seeding a more secure future, built with longevity in mind, by working with the OpenSSF. This network of projects, maintainers, and thousands of contributors is key to reinforcing reliable, sustainable open source software for all.” **Foundation Updates and Milestones** In the past quarter, OpenSSF has furthered its mission to secure open source software with the following achievements: * A new partnership with Kusari to offer Kusari Inspector at no cost to OpenSSF projects – this offering provides maintainers with deeper visibility into their software supply chains and enables proactive security checks at the pull request level. * The SLSA (Supply-chain Levels for Software Artifacts) project achieved Graduated status – this recognition advances SLSA’s stability, maturity, and broad adoption as a critical framework for supply chain integrity. * The release of the Gemara Project’s inaugural white paper – the findings outline a new framework for integrating security-as-code principles directly into the software development lifecycle. * The launch of new Special Interest Groups focused on Model Lifecycle Provenance and GPU-Based Model Integrity – these groups, under the AI/ML Security Working Group, expand the Foundation’s focus on securing the rapidly evolving field of AI/ML software security. * OpenSSF is approved as a CEN / CENELEC Liaison Organization for cybersecurity – this designation, through the Linux Foundation Europe, strengthens OpenSSF’s position in global standards development and policy influence. * The official launch of the OpenSSF Ambassador Program – applications are now open for the initial cohort. * Over 7,300 learners enrolled in OpenSSF’s free course, “Understanding the EU Cyber Resilience Act (LFEL1001)” – the Foundation has had over 75,000 enrollments in OpenSSF training programs to date. OpenSSF growth follows the announcement of $12.5 million in grant funding awarded to OpenSSF and Alpha-Omega from leading AI providers. Funding from these leaders underscores broad industry support for more sustainable AI security assistance that empowers maintainers. Learn more about how OpenSSF and Alpha-Omega are using this grant to build long-term, sustainable security solutions, here. **Supporting Quotes** “At Helvethink, we work at the intersection of cloud architecture, platform engineering, and DevSecOps. Open source components are foundational to modern infrastructure from Kubernetes and IaC tooling to CI/CD pipelines and security automation. Strengthening this ecosystem requires measurable standards, robust software supply chain security practices, and active collaboration across the community. By joining OpenSSF, we are actively participating in several working groups to contribute to initiatives focused on supply chain integrity, secure-by-design principles, and the continuous improvement of cloud-native security practices.” **– Jose Goncalves, co-founder, Helvethink** “Quantrexion is proud to join OpenSSF and support its mission to strengthen the security, resilience, and trustworthiness of open source software. As a company focused on governance and human risk management, we see secure open ecosystems as a critical part of long-term digital resilience.” **– Dionysis Karamitopoulos, CEO, Quantrexion** “Open source is the foundation of modern infrastructure — and its security is a shared responsibility. By joining the OpenSSF, Spectro Cloud is investing directly in the community work that raises the bar for everyone. Just as importantly, it strengthens the standards and practices behind the software we ship, so our customers can deploy Kubernetes with confidence in the integrity of every component. We’re proud to support the OpenSSF mission and to keep translating that momentum into real product capabilities that make secure software a default, not a bolt-on.” **– Saad Malik, CTO and co-founder, Spectro Cloud** **Events and Gatherings** OpenSSF members are gathering this week in Amsterdam at Open Source SecurityCon Europe. To get involved with the OpenSSF community, join us at the following upcoming events: * Open Source Summit North America (Minneapolis; May 18-20, 2026) * OpenSSF Community Day North America (Minneapolis; May 21, 2026) * OpenSSF Community Day Europe (Prague; October 6) * Open Source Summit Europe (Prague; October 7-9) **Additional Resources** * View the complete list of OpenSSF members * Contribute efforts to one or more of the active OpenSSF working groups and projects * Sign up for the OpenSSF newsletter to receive updates on upcoming events, resources, and community news. **About the OpenSSF** The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all. For more information, please visit us at openssf.org. **Media Contact** Grace Lucier The Linux Foundation pr@linuxfoundation.org
openssf.org
March 23, 2026 at 1:36 PM
Fact: Security teams are drastically outnumbered by developers.

When the next zero-day hits, will your team be ready? Join Josh Bressers & a great lineup at Open Source SecurityCon on March 23 to talk tactical prep rather than panic. https://sched.co/2DY3p

#DevSecOps #KubeCon
March 18, 2026 at 5:54 PM
🔍 What to expect at Open Source #SecurityCon Europe 2026?

From eBPF-based algorithms to the latest on the EU Cyber Resilience Act, we’re covering the tech and policy that keeps our ecosystem safe.

🔗 Read: openssf.org/blog/2026/03...
March 16, 2026 at 8:20 PM
It's not IF, it's WHEN🛡️

Catch Anchore's VP of Security, Josh Bressers alongside a stellar panel at Open Source SecurityCon (co-located at #KubeConEU). They're getting practical about software supply chain attacks & zero-day prep.

📅 Mar 23 | 11:50 CET
https://sched.co/2DY3p
March 12, 2026 at 3:21 PM
March 23rd is when things really start to get rolling. No more rest! First, co-lo day! We're sponsoring Platform Engineering Day and we'll also be at Open Source SecurityCon. But that's just during the day...
#PlatEngDay
March 10, 2026 at 2:34 PM
Alright, @cncf.io KubeCon EU (and all the other fun) is two weeks away. Let's talk about what we've got tee'd up for you...
🧵
edera.link/kceu26
March 10, 2026 at 2:34 PM
OpenSSF Newsletter – February 2026
### TL;DR: Open Source SecurityCon Europe → Agenda live and registration open Securing Agentic AI in Practice → March 17 Tech Talk on AI/ML security in action Compiler Annotations Guide → Practical C/C++ hardening without rewrites Security Slam 2026 → 30-day challenge to level up project security CRA in Practice @ FOSDEM → Turning regulation into actionable steps Package Repository Security Forum → Cross-ecosystem collaboration in action What’s in the SOSS? → CFP tips and a 4-part AIxCC deep dive 6 min read ## Join Us at Open Source SecurityCon Europe 2026 in Amsterdam Planning to attend KubeCon + Cloud Native Con Europe in March? Don’t miss OpenSSF’s co-located 1-day event! This gathering will bring together a diverse community, including software developers, security engineers, public sector experts, CISOs, CIOs, and tech pioneers, to explore challenges and opportunities in modern security. Collaborate with peers and discover the essential tools, knowledge, and strategies needed to ensure a safer, more secure future. The agenda is live! Read the blog to learn what not to miss in Amsterdam and to see highlights from SecurityCon North America. Read the blog | Register now | View the agenda ## Mark Your Calendar For the Upcoming Tech Talk: Securing Agentic AI in Practice: From OpenSSF Guidance to Real-World Implementation Join us for the first OpenSSF Tech Talk of the year, focusing on agentic artificial intelligence (AI) security. In this session, we will explore how the OpenSSF AI/ML Security Working Group is developing open guidance and frameworks to help secure AI and machine learning systems, and how that work translates into real-world practice. Using SAFE MCP and other solutions from OpenSSF member companies as examples, we will highlight community-driven efforts to improve the security of agentic AI systems, the problems they address, the design tradeoffs involved, and the lessons learned so far. We will also feature OpenSSF’s free course, Secure AI/ML Driven Software Development (LFEL1012), which gives attendees a clear path to build practical skills and contribute to this rapidly evolving field. Register and mark your calendar for March 17 at 1:00 p.m. ET. Additional speaker information will be shared soon. ## Fill Out All The Margins : OpenSSF Releases Compiler Annotations Guide for C and C++ OpenSSF has released a new Compiler Annotations Guide for C and C++ to help developers improve memory safety, diagnostics, and overall software security by using compiler-supported annotations. The guide explains how annotations in GCC and Clang/LLVM can make code intent explicit, strengthen static analysis, reduce false positives, and enable more effective compile-time and run-time protections. As memory-safety issues continue to drive a significant share of vulnerabilities in C and C++ systems, the guide offers practical, real-world guidance for applying low-friction hardening techniques that improve security without requiring large-scale rewrites of existing codebases. Read the blog ## Security Slam 2026 Security Slam 2026 is a 30-day security hygiene challenge running from February 20 to March 20, culminating in an awards ceremony at KubeCon + CloudNativeCon Europe. Hosted by OpenSSF in partnership with CNCF TAG Security & Compliance and Sonatype, the event encourages projects to use practical security tools, including OpenSSF resources, to strengthen their security posture based on their maturity level. Participants can earn recognition, badges, and plaques for completing milestones, reinforcing a community-driven effort to improve open source software security at scale. Read the blog to learn more | Register now to receive reminders and instructions ## EU Cyber Resilience Act (CRA) in Practice @ FOSDEM 2026: From Awareness to Action At FOSDEM 2026, the CRA in Practice DevRoom brought together open source and industry leaders to turn the EU Cyber Resilience Act from policy discussion into practical action. Through case studies and panels, speakers shared concrete approaches to vulnerability management, SBOMs, VEX, risk assessment, and the steward role. Read the blog ## Advancing Package Repository Security Through Collaboration On February 2, OpenSSF convened the Package Manager Security Forum, bringing together maintainers and registry operators from major ecosystems to address shared challenges in package repository security. Discussions highlighted common concerns around identity and account security, governance and abuse handling, transparency, and long-term sustainability. The session reinforced that package ecosystem risks are interconnected and that improving security requires cross-ecosystem coordination, shared frameworks, and continued collaboration through OpenSSF’s neutral convening role. Read the recap ## Getting an OpenSSF Baseline Badge with the Best Practices Badge System Is your open source project meeting the “minimum definition” of security? The OpenSSF has officially integrated the Open Source Project Security Baseline (OSPS Baseline) into its Best Practices Badge Program. In our latest blog, David A. Wheeler explains how you can quickly identify and meet essential security requirements to earn a Baseline Badge. ## What’s in the SOSS? An OpenSSF Podcast: #50 – S3E2 Demystifying the CFP Process with KubeCon North America Keynote Speakers Stacey Potter and Adolfo “Puerco” García Veytia share practical, behind-the-scenes advice on submitting conference talks, fresh off their KubeCon keynote. They break down how CFP review committees work, what makes an abstract stand out, common mistakes to avoid, and why authenticity matters more than polish. The episode also tackles imposter syndrome and encourages new and diverse voices to shape the future of open source through speaking. #51 – S3E3 AIxCC Part 1: From Skepticism to Success with Andrew Carney Andrew Carney from DARPA explains the vision and results behind the two-year AI Cyber Challenge (AIxCC), which tasked teams with building AI systems that can automatically find and patch vulnerabilities in open source software. Despite early skepticism, competitors identified more than 80% of seeded vulnerabilities and generated effective patches at surprisingly low compute costs. The episode looks at what comes next as these cyber reasoning systems move from competition to real-world adoption. #52 – S3E4 AIxCC Part 2: How Team Atlanta Won by Blending Traditional Security and LLMs Professor Taesoo Kim of Georgia Tech describes how Team Atlanta combined fuzzing, symbolic execution, and large language models to win AIxCC. Initially skeptical of AI, the team shifted its strategy mid-competition and discovered that hybrid approaches produced the strongest results. The conversation also covers commercialization efforts, integration with OSS-Fuzz, and how the experience reshaped academic security research. #53 – S3E5 AIxCC Part 3: Trail of Bits’ Hybrid Approach with Buttercup Michael Brown of Trail of Bits discusses Buttercup, the second-place AIxCC system that pairs large language models with conventional software analysis tools. The team focused on using AI for well-scoped tasks like patch generation while relying on fuzzers for proof-of-vulnerability. Now fully open source and able to run on a laptop, Buttercup is actively maintained and positioned for broader enterprise and community use. #54 – S3E6 AIxCC Part 4: Cyber Reasoning Systems in the Real World CRob and Jeff Diecks wrap up the AIxCC series by exploring how competition teams are applying their systems to real open source projects such as the Linux kernel and CUPS. They introduce the OSS-CRS initiative, which aims to standardize and combine components from multiple cyber reasoning systems, and share lessons learned about responsibly reporting AI-generated findings. The episode highlights how collaboration through OpenSSF’s AI/ML Security Working Group and Cyber Reasoning Systems SIG is shaping the next phase of AI-driven security. ## News from OpenSSF Community Meetings and Projects: _Upcoming community meetings_ * The ORBIT, AI / ML Security, and Securing Critical Projects working groups presented quarterly updates to the TAC. * A new paper “Forecasting the Maintained Score from the OpenSSF Scorecard for GitHub Repositories linked to PyPI libraries” was presented at the Scorecard community meeting. * The latest developments on EU CRA standards and CRA implementation steps were presented at the Standardization SIG meeting. * The ORBIT WG has created a new special interest group in collaboration with the Global Cyber Policy WG. The ORBIT Launchpad SIG held its first meeting on Friday, Feb 6 and hosted a CRA Tech Talk. * The E2E Model Provenance SIG has started a draft specification. * The Global Cyber Policy WG gave an overview of CRA Stewardship in its monthly CRA Tech Talk. * Zarf released version v0.70.1 including support for image volumes on supported clusters. * Gemara published its 2026 Roadmap. * The SAFE-MCP SIG is seeking input on the project’s name and branding. * The TAC elected Zach Steindler as 2026 Chair and Bob Callaway as Vice-Chair. * The Open Source Summit North America CFP closed on Feb 9 and the CFP for OpenSSF Community Day North America closed on Feb 15. * SLSA is now a graduated project of OpenSSF. * OSPS Security Baseline released v2026.02.19 with several new and updated controls, and mappings to BSI-TR-03185-2. * The Vulnerability Disclosures WG is working on best practices guidelines for open source projects impacted by AI Slop. * Participants in the AIxCC competition have published an SoK paper on Cyber Reasoning Systems. * The AI/ML Security WG has established a new bi-weekly meeting for collaboration on AI security work with representatives from OpenSSF, CoSAI, AGNTCY, NIST, SPDX, OWASP and more. * Alpha-Omega’s Michael Winser was featured in The Register about open source package registries facing severe financial pressure. * The Securing Software Repositories and Supply Chain Integrity working groups presented quarterly updates to the TAC. ## In the News: * The OpenSSF was featured in a Technology Magazine Q&A. CRob discusses OpenSSF’s goals, OSSAfrica, the BEAR Working Group, Security Baseline, and much more. This conversation was also covered by AI Magazine. ## Meet OpenSSF at These Upcoming Events! Connect with the OpenSSF Community at these key events: * FOSS Backstage – March 16 & 17, 2026 * Open Source SecurityCon Europe – March 23, 2026 * KubeCon + CloudNativeCon Europe – March 23 – 26, 2026 * Open Source Summit North America – May 18 – 20, 2026 * OpenSSF Community Day North America – May 21, 2026 Ways to Participate: There are a number of ways for individuals and organizations to participate in OpenSSF. Learn more here. You’re invited to… * Join a Working Group or Project * Chat with us on Slack * Follow us on X, Mastodon, Bluesky, and LinkedIn ## See You Next Month! We want to get you the information you most want to see in your inbox. Missed our previous newsletters? Read here! Have ideas or suggestions for next month’s newsletter about the OpenSSF? Let us know at marketing@openssf.org, and see you next month! Regards, The OpenSSF Team
openssf.org
February 27, 2026 at 1:33 PM
🛡️ Interested in securing open source systems at scale?

Open Source SecurityCon returns at KubeCon + CloudNativeCon EU to talk policy, supply chain, & security challenges.

More from co-chairs Brandt Keller & @entlein.bsky.social (Constanze Roedig): www.cncf.io/blog/2026/02...

#CNCF #Security
February 23, 2026 at 5:21 PM
Feed: "Open Source Security Foundation"
By: OpenSSF on Tuesday, February 3, 2026
Join Us at Open Source SecurityCon Europe 2026 in Amsterdam
Open Source SecurityCon Europe is approaching, which means we’ll be gathering again in Amsterdam this spring for one of the most focused, practitioner-driven events in open source security. Save your spot, register now, and add your favorite sessions to your calendar from the agenda.
openssf.org
February 3, 2026 at 10:49 PM
Open Source #SecurityCon Europe 2026 is heading to Amsterdam 🇳🇱

This blog highlights speakers & perspectives from across the OpenSSF community, all bringing hands-on experience from production environments.

Read the blog: openssf.org/blog/2026/02...

#OSSSecurity
February 3, 2026 at 8:21 PM
🔐 Open source security in 2026 is taking shape.

The January newsletter covers CRA readiness, 2026 themes, VEX adoption, AI security, and upcoming community events like #FOSDEM and Open Source SecurityCon Europe.

openssf.org/newsletter/2...
January 29, 2026 at 4:59 PM
Pavel Shukhman's talk about Transparency Exchange API (TEA) from Open Source SecurityCon 2025 in Atlanta is now live on YouTube - www.youtube.com/watch?v=na30... #TEA #SBOM #exchange #security #CyberSecurity
Transparency Exchange API: Where To Find Product SBOM? - Pavel Shukhman, Reliza
YouTube video by CNCF [Cloud Native Computing Foundation]
www.youtube.com
November 25, 2025 at 2:29 PM
Now that #KubeCon NA is wrapped up, it’s time for EU! 🚀
Just confirmed my spot at KubeCon + CloudNativeCon Europe 2026 in Amsterdam! 🌍
Can’t wait to bring ReeVo Cloud & Cyber Security’s vision, join the best sessions, and connect with partners.
I’ll also be at SecurityCon Europe, see you there! 🎉
November 18, 2025 at 2:14 PM