73 afleveringen
Balancing AI's Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich
08-09-2026 | 56 Min.In this episode of What's in the SOSS?, host CRob sits down with Mark Russinovich – CTO and Deputy CISO of Azure, as well as Board Chair for the Open Source Security Foundation (OpenSSF) – for a wide-ranging conversation on the changing landscape of software security. Mark shares insights from his journey from Sysinternals to Azure leadership, exploring how generative AI is delivering dramatic productivity boosts while creating new talent pipeline challenges for early-in-career engineers. The discussion dives into the shift toward hardware-backed "what, not who" supply chain identity, the urgent rolling Y2K effort to fix AI-discovered vulnerabilities via initiatives like Accretis, and the reality of persistent AI hallucinations. Finally, Mark details OpenSSF's strategic priorities for package registry sustainability and gives a sneak peek into his personal vibe-coded side projects like Polypost.
Chapters:
00:00 – Sysinternals & Career Journey: Mark reflects on his transition from Sysinternals to Microsoft Azure leadership.
02:08 – OpenSSF Board Leadership: Mark outlines his vision and key priorities as the new OpenSSF Board Chair.
03:32 – Corporate & Community Alignment: How Microsoft balances its enterprise goals with open source community needs.
05:40 – AI's Impact on Software Engineering: Why AI coding shifts developer roles toward architecture, review, and preceptorships. 1
2:35 – Finding vs. Fixing Vulnerabilities: Managing the rapid race against AI-assisted threats across modern systems.
16:07 – LLM Code Quality & Edge Cases: Exploring prompt specification limits and unexpected model behaviors.
22:07 – Navigating AI Hallucinations: Why model hallucinations persist despite web grounding and how experts mitigate them.
26:34 – Supply Chain: Shifting "Who" to "What": Establishing identity using hardware attestation and confidential computing.
30:44 – Machine Unlearning & Model Safety: Mark details his research on targeted unlearning and model alignment experiments.
34:06 – Rapid Response & Accretis: Standing up coordinated responses to patch critical open source vulnerabilities.
39:39 – Package Registry Sustainability: Securing package repositories and building sustainable funding models.
45:44 – Personal Projects & Vibe-Coding: Mark discusses his current AI coding stack, Polypost, and gaming.
53:44 – Rapid Fire Round: Quick takes on Emacs, Star Wars, and favorite dystopian robots.
Episode links:
Mark Russinovich’s LinkedIn page
Microsoft Azure
OpenSSF Guide: Principles for Package Repository Security
Who's Harry Potter? Approximate Unlearning in LLMs Paper
HALU Bench: Hallucination Benchmark Research
SCITT (Supply Chain Integrity, Transparency, and Trust - IETF)
Microsoft Signing Transparency
Polypost GitHub
Polypost WebApp
Get involved with the OpenSSF
Learn more about the OpenSSF Governing Board
Subscribe to the OpenSSF Newsletter
Follow the OpenSSF on LinkedIn- In this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of "open source software stewards," the importance of moving beyond passive consumption to active upstream contribution, and why compliance should be viewed as an outcome of good engineering rather than a separate checkbox exercise. Whether you are a manufacturer of smart devices or a volunteer maintainer, this episode provides essential insights into how the CRA will reshape the global software supply chain, encouraging a secure-by-design mindset that strengthens the entire digital ecosystem.
Chapters:
00:23 - Introductions and Madalin’s role at OpenSSF
03:42 - What is the Cyber Resilience Act (CRA)?
05:27 - The CRA in the global regulatory landscape
09:05 - Relevance to open source and the "Software Steward" concept
13:02 - Moving from passive consumption to upstream contribution
16:20 - Practical steps for organizational readiness
20:26 - Should open source maintainers be worried?
24:12 - Insights from the Linux Foundation CRA Readiness Report
31:32 - What to watch for in the coming year
34:07 - Rapid fire round and concluding thoughts
Episode links:
Madalin Neag’s LinkedIn page
Cyber Resilience Act - Implementation
Global Cyber Policy Working Group
Linux Foundation 2026 CRA Awareness and Readiness Report
Case Study: Defending the Open Source Supply Chain in a New Regulatory Era
OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
Open Source Project Security Baseline (OSPS)
SLSA
Gemara
GUAC
OpenSSF Projects
Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
Global Cyber Policy GitHub Repository
Join us at Open Source Summit and OpenSSF Community Day in Prague
Get involved with the OpenSSF
Subscribe to the OpenSSF newsletter
Follow the OpenSSF on LinkedIn Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo
25-08-2026 | 18 Min.In this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250,000-per-release financial toll of maintaining private forks, the crucial legal distinction between software manufacturers and open source stewards, and Red Hat's framework for "champion stewardship." Whether you are facing the upcoming September 2026 vulnerability reporting platform launch or preparing for full December 2027 enforcement, this conversation delivers clear, actionable guidance to get your organization compliant, collaborative, and secure.
Chapters:
00:25 - Welcome & Introductions
01:28 - Meet Dave Russo
02:01 - The Global CRA Awareness Gap
04:46 - The Hidden Cost of Private Forks
07:32 - Manufacturer vs. Open Source Steward
09:09 - Red Hat's Light vs. Champion Stewardship
11:37 - Crucial CRA Deadlines Explained
13:51 - Actionable Compliance Steps Today
16:47 - Rapid Fire Fun
Episode links:
Dave Russo’s LinkedIn page
Global Cyber Policy Working Group (policy.openssf.org)
European Commission CRA Implementation Website
European Commission CRA Guidance
European Commission CRA FAQ
Open Regulatory Compliance Working Group
Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group
Open Source Project Security (OSPS) Baseline
OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
Global Cyber Policy GitHub Repository
Add any other applicable links related to the episode
OpenSSF Community Calendar
Get involved with the OpenSSF
Subscribe to the OpenSSF newsletter
Follow the OpenSSF on LinkedInWatering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov
18-08-2026 | 47 Min.The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, to demystify this sweeping regulation. Using a brilliant "community garden" analogy, Roman breaks down the distinct roles of maintainers, stewards, and manufacturers under the law, illustrating why the traditional "consume and forget" model of open source is officially dead. They dive deep into the newly released 2026 CRA Awareness and Readiness Report, exposing the staggering $250,000+ engineering tax of maintaining private forks and detailing how active upstream collaboration is no longer just good citizenship—it’s a business and legal necessity. Tune in to discover actionable strategies, free educational resources, and how we can collectively bake "compliance as code" into the open source ecosystem.
Chapters:
00:01 – Introduction: The CRA Countdown is On
02:04 – Tomatoes, Gardens, and Restaurants: Defining the CRA Personas
06:40 – Reality Check: Shocking Findings from the 2026 Readiness Report
10:12 – The Awareness Gap: Why Are We Ignoring the Warning Signs?
15:01 – The End of "Consume and Forget"
17:49 – The Private Fork Tax: A $250K Engineering Trap
23:34 – Red Hat’s Blueprint & Free Community Security Tools
28:44 – Taming the AI Vulnerability Tsunami
31:27 – Build Your Program Now: Action Steps for Manufacturers
36:12 – Supporting SMEs & Navigating Free Resources
40:30 – Carrying the Torch as an OpenSSF Ambassador
43:35 – Rapid Fire & How to Get Involved
Episode links:
Roman Zhukov’s LinkedIn page
Cyber Resilience Act - Implementation
Global Cyber Policy Working Group
Linux Foundation 2026 CRA Awareness and Readiness Report
Case Study: Defending the Open Source Supply Chain in a New Regulatory Era
OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
Open Source Project Security Baseline (OSPS)
SLSA
Gemara
GUAC
OpenSSF Projects
Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
Global Cyber Policy GitHub Repository
Get involved with the OpenSSF
Subscribe to the OpenSSF newsletter
Follow the OpenSSF on LinkedInCRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
11-08-2026 | 16 Min.In this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across working groups like ORBIT and ORC, and shares key resources to help lower the barrier to compliance. Stick around for a fun rapid-fire round where favorite open source mascots steal the spotlight!
Chapters:
00:24 - Introduction and Welcome
01:44 - The current CRA landscape and key findings from recent LF Research reports.
04:23 - Actionable compliance steps for maintainers and organizations
07:16 - The mission of the OpenSSF Global Cyber Policy Working Group
10:28 - How to get involved
13:25 - Rapid-fire
15:12 - Key takeaways and resources for a deeper dive into CRA readiness
Episode links:
Megan Knight’s LinkedIn page
Cyber Resilience Act - Implementation
Global Cyber Policy Working Group (policy.openssf.org)
Linux Foundation 2025 CRA Awareness and Readiness Report
Linux Foundation 2026 CRA Awareness and Readiness Report
Open Regulatory Compliance Working Group
Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group
Open Source Project Security (OSPS) Baseline
OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
Global Cyber Policy GitHub Repository
Add any other applicable links related to the episode
OpenSSF Community Calendar
Get involved with the OpenSSF
Subscribe to the OpenSSF newsletter
Follow the OpenSSF on LinkedIn
Meer Technologie podcasts
Trending Technologie -podcasts
Over What's in the SOSS? An OpenSSF Podcast
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.
Podcast websiteLuister naar What's in the SOSS? An OpenSSF Podcast, Waveform: The MKBHD Podcast en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies


What's in the SOSS? An OpenSSF Podcast
Scan de code,
download de app,
luisteren.
download de app,
luisteren.






























