- 29 minutes 13 secondsFinding difficult vulnerabilities with Jaya Baloo from AISLE
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-jaya-aisle
7 September 2026, 12:00 am - 36 minutes 17 secondsSovereign Tech Agency with Erik Möller
Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-erik-sta
31 August 2026, 12:00 am - 38 minutes 7 secondsCVEs vs Advisories with Paul Asadoorian
Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve
24 August 2026, 12:00 am - 34 minutes 24 secondsMaintaining EOL Open Source with Commonhaus and HeroDevs
Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs
17 August 2026, 12:00 am - 35 minutes 8 secondsCleanup, Speedup, Levelup open source at e18e
Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james
10 August 2026, 12:00 am - 36 minutes 45 secondsVulnCheck's State of Exploitation Report with Patrick Garrity
Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation
3 August 2026, 12:00 am - 35 minutes 38 secondsSecuring critical infrastructure with Josh Corman
Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman
27 July 2026, 12:00 am - 34 minutes 16 secondsAbandoned open source with Josh Marpet
Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet
20 July 2026, 12:00 am - 32 minutes 32 secondsRed Hat's Project Lightwell with Mo Duffy
Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we can probably use technology to help. It will be interesting to see where Lightwell goes in the next few years.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-lightwell-mo-duffy
13 July 2026, 12:00 am - 32 minutes 46 secondsRust Foundation Maintainers Fund with Lori and Niko
Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko
6 July 2026, 12:00 am - 34 minutes 38 secondsAIBOM, CBOM, and HBOM with Allan Friedman
Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-allan-omnibom
29 June 2026, 12:00 am - More Episodes? Get the App