Josh Bressers
joshbressers@infosec.exchange
<p>VP of Security at Anchore - Podcaster (<a href="http://opensourcesecuritypodcast.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">http://</span><span class="">opensourcesecuritypodcast.com</span><span class="invisible"></span></a> <a href="http://hackerhistory.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">http://</span><span class="">hackerhistory.com</span><span class="invisible"></span></a>) - Blogger (<a href="http://opensourcesecurity.io" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">http://</span><span class="">opensourcesecurity.io</span><span class="invisible"></span></a>) - He/Him</p>
Posts
-
Post #4243639
I wrote a blog post You don't have a supply chain, you have a supply soup This is something I want to spend some time investigating in the future, it's all vastly more complicated and weird than we think it is https://opensourcesecurity.io/2026/07-supply-soup/
-
Post #4139488
I had a chat with @joshcorman@infosec.exchange about securing critical infrastructure on #OSSPodcast Josh is one of the best in the industry on this topic. He has a ton of interesting (and sometimes scary) things to say about it all https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman/
-
Post #3898235
I might be missing something here I'm seeing what I think is a pattern with all these vulnerability clearing houses coming out of the woodwork The common theme seems to be "give us money and we will make sure you know about embargoed vulnerabilities" It's hard to see the logical end to this is anything other than researchers just dropping 0days
-
Post #3801171
I miss the days when my spellchecker just worked
-
Post #3629701
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/ #OpenSourceSecurity #rust #RustFoundation
-
Post #3570418
I had the pleasure to chat with @allanfriedman@infosec.exchange about Bill of Materials things on #OpenSourceSecurity We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe https://opensourcesecurity.io/2026/2026-06-allan-omnibom/
-
Post #3417788
On this episode of @CypherCon@infosec.exchange #HackerHistory I talk to Michael Lenz It's a great story about starting out with what we now call retro computers, building a SOC and SIEM before those were really things, and eventually putting focus into Burbsec community meetups https://hackerhistory.com/podcast/the-history-of-michael-lenz/
-
Post #2165323
I love the hot takes that this Trivy debacle will be the end of open source Heartbleed didn&#39;t kill open source Log4Shell couldn&#39;t get the job done xz tried and failed This won&#39;t kill it either Free is too good of a deal
-
Post #2126396
For anyone who lacks the advanced level of age I mean experience some of us have, you should read this Wikipedia page on Embrace, Extend, and Extinguish I guarantee this is the goal of Meta joining the fediverse https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish
-
Post #2075442
This week on #OpenSourceSecurity I chat with Brad Axen about Goose and the Agentic AI Foundation I&#39;m often skeptical about AI claims, but I do approve the foundation model and seeing Goose donated to it Brad has some good insights into what we&#39;re seeing and what&#39;s probably coming in the future. It&#39;s hard to keep track of everything happening https://opensourcesecurity.io/2026/2026-02-goose-aaif-brad-axen/
-
Post #1561433
The year is 2050. The Onion is the only news company left They have been printing true stories for over ten years, but everyone thinks it&#39;s still parody
-
Post #1317003
I learned an incredible about from this chat I had with @adulau and @cedric about @gcve I&#39;m still working through all the details, but I&#39;m starting to suspect #GCVE solved many of the problems with vulnerability data I&#39;ve been complaining about for a very long time If you do anything with vulnerabilities this one is worth a listen https://opensourcesecurity.io/2025/2025-08-gcve-cedric-alex/
-
Post #1184575
I had a chat with Paul McCarty about his project Open Source Malware Paul has a ton of great insight into what&#39;s happening with the massive influx of malware into our open source ecosystems https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/
-
Post #1156484
The Register wrote a story about a single maintainer open source project, I think it&#39;s shameful and upsetting. So I wrote a blog post about it An absolutely ridiculous amount of open source is one person projects. I have the data to prove it https://opensourcesecurity.io/2025/08-oss-one-person/
-
Post #1102958
I wrote a blog post Open source was never about trust https://opensourcesecurity.io/2026/04-never-about-trust/ There&#39;s been a lot of really crazy events happening around open source for the last few months. But it&#39;s probably all going to be OK
-
Post #1083324
This week on #OpenSourceSecurity I chat with @Foxboron and @anthraxx about Arch Linux security. It&#39;s a great chat where we talk about all the difficulties and oddities of trying to keep a Linux distribution secure I learned a ton, I&#39;m sure you will too https://opensourcesecurity.io/2025/2025-09-arch-foxboron-anthraxx/
-
Post #978785
It was awesome to have @firstyear back on #OpenSourceSecurity to chat about about passkeys I was struggling to understand what a passkey actually is Apparently is because the definition of what a passkey is has changed over time There&#39;s so much to learn from this episode I don&#39;t even know where to start https://opensourcesecurity.io/2026/2026-01-passkey-william-brown/
-
Post #977743
The npm axios package was compromised. You know the drill https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat
-
Post #970883
This week I had a chat with Michael Winser about securing open source at scale We recorded prior to the events of the last few weeks, everything Michael talks about with securing our infrastructure is spot on We touch on package repositories, Alpha Omega, foundations, and more. Michael is doing some really interesting work https://opensourcesecurity.io/2026/2026-03-michael-winser/ #opensource #alphaomega #supplyChainSecurity
-
Post #970882
I had a chat with @andrewnez about why creating a new package repository is so hard. There are a ton of little details like support from SBOM and vulnerability scanners nobody even thinks about usually. There are so many little details Andrew does a great job explaining all this and more https://opensourcesecurity.io/2026/2026-04-ecosystems-andrew/
-
Post #739763
I had a chat on #OpenSourceSecurity with Luke Hinds about his project nono as well as MCP security nono is a sandbox for containing all these tools, which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up Luke has great insight into what&#39;s going on and what&#39;s wrong with what&#39;s going on https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/
-
Post #739760
1) A robot may not injure a human being or, through inaction, allow a human being to come to harm ... unless it makes a lot of money 2) A robot must obey the orders given it by human beings except where such orders would conflict with the First Law ... unless it makes a lot of money 3) A robot must protect its own existence as long as such protection does not conflict with the First or Second Law ... unless it makes a lot of money
-
Post #630617
Given the amount of containment and security we&#39;re seeing around all these AI agents I think it&#39;s a pretty safe bet that if we do create AGI, it&#39;s going to escape immediately and nobody will even notice
-
Post #630615
I&#39;m trying to find open source local caching package proxy software I don&#39;t want anything transparent, I want something that&#39;s a very deliberate local mirror The only thing that does more than one ecosystem I can find is https://github.com/git-pkgs/proxy which is from @andrewnez Does anyone know of anything else?
-
Post #625949
I keep seeing stories about LLMs finding vulnerabilities. Finding vulnerabilities was never the hard part, the hard part is coordinating the disclosure It looks like LLMs can find vulnerabilities at an alarming pace. Humans aren&#39;t great at this sort of thing, it&#39;s hard to wade through huge codebases, but there are people who have a talent for vulnerability hunting. This sort of reminds me of the early days of fuzzing. I remember fuzzing libraries and just giving up because they...
-
Post #291718
Does this Anthropic Red Team blog about the LLM finding vulnerabilities mean we&#39;re all doomed? I don&#39;t think so. So I wrote a blog about it https://ai-skeptic.bress.net/blog/0012-anthropic-vulns/ The smart people will figure this out, but there will be slop along the way