Podcast artwork thumbnail for Open Source Security

Open Source Security

Josh Bressers

Booking Overview

An interview-focused open-source security show that spotlights practitioners, maintainers, researchers, and teams working on real-world software security issues, typically featuring external technical and industry guests. Suitable pitches include open-source project leaders, vulnerability researchers, software supply-chain specialists, cybersecurity executives, and critical-infrastructure security experts; booking difficulty is medium because guests generally need direct practical experience or recognized subject-matter expertise.

Metrics

Episodes: 547

Frequency: Weekly

Rating: 4.8/5.0

Estimated listeners: 1k-10k

Gender skew: Male

Location: USA

Contact Information

Publicly listed emails

josh@bress.net

Looking for the right person? Join Podseeker to find direct host and producer contacts and manage your podcast outreach.

Host

Josh Bressers - Open-source security media publisher and host focused on educating developers and users about how open-source security works and highlighting the people and teams doing hands-on work in the field.

Booking Intelligence

Booking Requirements

medium
Typical Credentials:  
Open-source maintainers, cybersecurity practitioners, vulnerability researchers, software supply-chain specialists, critical-infrastructure security experts, and leaders of relevant initiatives or research organizations.
Required Achievements:  
Leading or maintaining an open-source project or security initiative, Producing vulnerability, exploitation, or software supply-chain research, Founding or directing a relevant organization or institute, Demonstrated hands-on work securing critical infrastructure or open-source ecosystems

Recent Guest Discussions

Rob Nalen - The Open Source Sustainability Initiative And Collaboration Between Corporations And Open-source Projects To Maintain End-of-life Software.

Erin Schnabel - The Open Source Sustainability Initiative And Collaboration Between Corporations And Open-source Projects To Maintain End-of-life Software.

Patrick Garrity - Trends In Vulnerability Exploitation, CVE Growth, And Findings From Vulncheck's State Of Exploitation Report.

Josh Corman - Securing Water Supplies And Other Critical Infrastructure, Nation-state Attacks, And Technical And Nontechnical Risk-reduction Measures.

Josh Marpet - Abandoned Open-source Packages, Software Supply-chain Risk, And Methods For Assessing Whether A Package May Be Abandoned.

Recent Topics

Open Source, Software Security, Cybersecurity, Vulnerabilities, Infrastructure

Episodes

Here's the recent few episodes on
Open Source Security
:

The curl summer of Bliss with Daniel and Stefan

September 21, 2026

Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experien...

CRA vulnerability reporting with Daniel Thompson

September 14, 2026

Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra    

Finding difficult vulnerabilities with Jaya Baloo from AISLE

September 07, 2026

Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights. The show notes and blog post...

Publicly listed emails

josh@bress.net

Looking for the right person? Join Podseeker to find direct host and producer contacts and manage your podcast outreach.

Get your clients booked on top podcasts

Try us risk free with a FREE 3 days trial.

Start Your Free Trial

Join hundreds of PR teams using Podseeker to pitch and land bookings