Rephonic
Artwork for Open Source Security

Open Source Security

Josh Bressers
Open Source
Open Source Software
Cybersecurity
Open Source Security
Cyber Resilience Act
Security
Vulnerabilities
Supply Chain Security
Kubernetes
NPM
Github
Vulnerability Management
Wordpress
CVE
CISA
Software Development
Github Actions
Open Source Malware
Red Hat
Security.txt

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hour... more

PublishesWeeklyEpisodes547Founded10 years ago
Number of ListenersCategory
Technology

Listen to this Podcast

Artwork for Open Source Security

Latest Episodes

Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability d... more

Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plent... more

Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners ... more

Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how ... more

Key Facts

Accepts Guests
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

LINUX Unplugged
LINUX UnpluggedJupiter Broadcasting
Risky Business
Risky BusinessRisky Business Media
Darknet Diaries
Darknet DiariesJack Rhysider
2.5 Admins
2.5 AdminsThe Late Night Linux Family

Recent Guests

Jaya Baloo
COO and CISO at AISLE
AISLE
Episode: Finding difficult vulnerabilities with Jaya Baloo from AISLE
Erik Möller
Director of Programs at The Sovereign Tech Agency
The Sovereign Tech Agency
Episode: Sovereign Tech Agency with Erik Möller
Paul Asadoorian
Principal Security Researcher at Eclipseum
Eclipseum
Episode: CVEs vs Advisories with Paul Asadoorian
Erin Schnabel
Chair of Commonhaus
Commonhaus
Episode: Maintaining EOL Open Source with Commonhaus and HeroDevs
Rob Nalen
Chief Operating Officer
HeroDevs
Episode: Maintaining EOL Open Source with Commonhaus and HeroDevs
Patrick Garrity
Security Researcher at VulnCheck
VulnCheck
Episode: VulnCheck's State of Exploitation Report with Patrick Garrity
Josh Corman
cyber safety philosopher warrior, public sector contributor
Undestructible 27 / Cavalry / public safety initiatives
Episode: Securing critical infrastructure with Josh Corman
Josh Marpet
Head of the Value Chain Risk Institute
Value Chain Risk Institute
Episode: Abandoned open source with Josh Marpet
Mo Duffy
Distinguished engineer at Red Hat
Red Hat
Episode: Red Hat's Project Lightwell with Mo Duffy

Host

Josh
Host of Open Source Security

Reviews

4.7 out of 5 stars from 440 ratings
  • Open source security and more

    Josh may no longer be with Kurt, he still makes a wicked podcast with a good concentrated dose of open source security.

    Apple Podcasts
    5
    LikeToTaste
    United Kingdom2 years ago
  • josh is insufferable

    I really enjoy Kurt’s perspective on stuff. Josh is insufferable. Not sure what complex he suffers from, but he can never be wrong and is always steamrolling Kurt.

    Apple Podcasts
    1
    letitsnowman
    United States2 years ago
  • Great Podcast

    I don't work in this field; I'm strictly a security hobbyist. Found this podcast through archive.org, incidentally. Listened to 5 minutes of one episode and that was enough for me to subscribe. Thanks for a great podcast!

    Apple Podcasts
    5
    CornOnTheMacabre
    United States2 years ago
  • Most frustrating show I continue listening to

    Like a meeting with no agenda it can be informative and entertaining and you’re never quite sure if you should attend again but usually you do.

    Apple Podcasts
    4
    cspeckrun
    United States3 years ago
  • The banter is spot on

    as of September 2023 be negative reviews may be from non-techs or squishy persons in general. I understand the humor, and every episode that I have listened to so far which is only half a dozen the hosts understand and get what they are talking about. having over 20 years both professionally and not in the information technology field I find myself quite amused at their observations, and more often than not not in agreement more than once an episode. If the hosts, however, ever come across this ... more

    Apple Podcasts
    4
    unbleachedbit
    United States3 years ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

Guests and topics are regularly highlighted as informative and actionable for practitioners.
Listeners value the practical, data-driven discussions and deep dives into OSS security and governance.
Some episodes are praised for pacing and expertise, while a few listeners wish for tighter agendas or less banter.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#78
Brazil/Technology
Apple Podcasts
#186
Austria/Technology
Apple Podcasts
#208
Finland/Technology
Apple Podcasts
#237
Ukraine/Technology
Apple Podcasts
#249
Saudi Arabia/Technology

Talking Points

Recent interactions between the hosts and their guests.

Finding difficult vulnerabilities with Jaya Baloo from AISLE
Q: What's next in this universe of AI-assisted security?
The conversation emphasizes sensible AI adoption, sovereignty concerns, and the need to manage model trust and governance, including potential model tampering and the importance of defense in depth as the ecosystem evolves.
Finding difficult vulnerabilities with Jaya Baloo from AISLE
Q: What does the signup and disclosure process look like for projects wanting AISLE to scan them?
Projects can sign up via their website, request a demo, and AISLE commits two people to sign up and scan the codebase, reporting back vulnerabilities with context, fixes, and POC where possible, and they participate in CNA/CVE workflows for open-source projects when applicable.
Finding difficult vulnerabilities with Jaya Baloo from AISLE
Q: What is different about AISLE's technology compared to other scanners?
AISLE uses a multi-agent cyber reasoning system that assigns different roles to multiple AI agents to triage and validate findings, combines AI with human review to reduce false positives, and relies on a strong benchmarking and post-training framework to continuously improve performance.
VulnCheck's State of Exploitation Report with Patrick Garrity
Q: What are the biggest takeaways for enterprises from this half-year report?
The biggest takeaways are that AI-enabled vulnerability discovery is real and creates a new attack surface, but fear-based narratives should be balanced with data; patching and reducing exposure at the network edge and in AI-related products are crucial, and coordinated vulnerability disclosure efforts need practical, human-backed processes to be effective.
VulnCheck's State of Exploitation Report with Patrick Garrity
Q: Why is your list of known exploited vulnerabilities larger than the CISA list?
Our list includes all publicly discussed exploited vulnerabilities from multiple sources, including advisories, honeypots, third-party intel groups, and our own Canary network, not just the CISA KeV. It's inclusive of a broad set of evidence, which naturally expands the catalog beyond CISA's scoped focus.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Open Source Security

What is Open Source Security about and what kind of topics does it cover?

A concise, data-forward look at open source security, governance, and supply chain transparency. Episodes frequently center on vulnerability disclosure, OSS risk management, and funding models that sustain critical open source projects. Notable threads include SBOMs and their evolving role in policy, AI-assisted tooling for security and discovery, upstream-downstream collaboration in ecosystems, and practical steps for organizations to improve resilience without resorting to hype. The show often features practitioners and community leaders who bring hands-on experience with governance, maintenance, and security practices across language ecosystems, tooling registries, and large foundations. A standout trait is its willingness to surface rea... more

Where can I find podcast stats for Open Source Security?

Rephonic provides a wide range of podcast stats for Open Source Security. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Open Source Security and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Open Source Security get?

Rephonic provides a full set of podcast information for four million podcasts, including the number of listeners. View further listenership figures for Open Source Security, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Open Source Security?

Rephonic provides comprehensive predictive audience data for Open Source Security, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Open Source Security have?

To see how many followers or subscribers Open Source Security has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Open Source Security?

These podcasts share a similar audience with Open Source Security:

1. SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
2. LINUX Unplugged
3. Risky Business
4. Darknet Diaries
5. 2.5 Admins

How many episodes of Open Source Security are there?

Open Source Security launched 10 years ago and published 547 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Open Source Security?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Open Source Security?

Rephonic pulls ratings and reviews for Open Source Security from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Open Source Security?

Rephonic provides full transcripts for episodes of Open Source Security. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Open Source Security?

Recent guests on Open Source Security include:

1. Jaya Baloo
2. Erik Möller
3. Paul Asadoorian
4. Erin Schnabel
5. Rob Nalen
6. Patrick Garrity
7. Josh Corman
8. Josh Marpet

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days