Episodes: 547
Frequency: Weekly
Rating: 4.8/5.0
Estimated listeners: 1k-10k
Gender skew: Male
Location: USA
Publicly listed emails
josh@bress.net
Looking for the right person? Join Podseeker to find direct host and producer contacts and manage your podcast outreach.
Josh Bressers - Open-source security media publisher and host focused on educating developers and users about how open-source security works and highlighting the people and teams doing hands-on work in the field.
Rob Nalen - The Open Source Sustainability Initiative And Collaboration Between Corporations And Open-source Projects To Maintain End-of-life Software.
Erin Schnabel - The Open Source Sustainability Initiative And Collaboration Between Corporations And Open-source Projects To Maintain End-of-life Software.
Patrick Garrity - Trends In Vulnerability Exploitation, CVE Growth, And Findings From Vulncheck's State Of Exploitation Report.
Josh Corman - Securing Water Supplies And Other Critical Infrastructure, Nation-state Attacks, And Technical And Nontechnical Risk-reduction Measures.
Josh Marpet - Abandoned Open-source Packages, Software Supply-chain Risk, And Methods For Assessing Whether A Package May Be Abandoned.
The curl summer of Bliss with Daniel and Stefan
September 21, 2026
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experien...
CRA vulnerability reporting with Daniel Thompson
September 14, 2026
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra
Finding difficult vulnerabilities with Jaya Baloo from AISLE
September 07, 2026
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights. The show notes and blog post...
Publicly listed emails
josh@bress.net
Looking for the right person? Join Podseeker to find direct host and producer contacts and manage your podcast outreach.
Try us risk free with a FREE 3 days trial.
Join hundreds of PR teams using Podseeker to pitch and land bookings