PodcastsTechnologieWhat's in the SOSS? An OpenSSF Podcast

What's in the SOSS? An OpenSSF Podcast

OpenSSF
What's in the SOSS? An OpenSSF Podcast
Nieuwste aflevering

55 afleveringen

  • What's in the SOSS? An OpenSSF Podcast

    AIxCC Part 4 – Cyber Reasoning Systems: The Real-World Journey After AIxCC

    10-2-2026 | 17 Min.
    In this final episode of our AI Cyber Challenge (AIxCC) series, CRob and Jeff Diecks wrap-up the journey from DARPA's groundbreaking two-year competition to the exciting collaborative phase happening now. Discover how winning teams are taking their AI-powered vulnerability detection systems into the real world, finding actual bugs in projects like the Linux kernel and CUPS. Learn about the innovative OSS-CRS project that aims to create a standard infrastructure for mixing and matching the best components from different systems, and hear valuable lessons about how to responsibly introduce AI-generated security findings to open source maintainers. The competition may be over, but the real work—and collaboration—is just beginning.
    This episode is part 4 of a four-part series on AIxCC:
    AIxCC part 1: From Skepticism to Success: The AI Cyber Challenge (AIxCC) with Andrew Carney
    AIxCC part 2: From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
    AIxCC part 3: Buttercup's Hybrid Approach: Trail of Bits' Journey to Second Place in AIxCC

    Chapters:
    00:00 - Welcome and Introduction to AICC
    01:37 - OpenSSF's AI Security Mission: Two Lenses
    03:54 - Competition Highlights: What the Teams Discovered
    07:43 - Real-World Impact: From Research to Production
    10:44 - Lessons Learned: Working with Open Source Maintainers
    13:13 - OSS-CRS: Building a Standard Infrastructure
    14:29 - Breaking Down Walls: Post-Competition Collaboration
    15:39 - How to Get Involved

    Episode links:
    Jeff Diecks LinkedIn page
    Christopher “CRob” Robinson LinkedIn page
    AI Cyber Challenge (AIxCC)
    OSS-CRS Project
    OpenSSF AI/ML Security Working Group
    Cyber Reasoning Systems Special Interest Group (Slack)
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    AIxCC Part 3 - Buttercup's Hybrid Approach: Trail of Bits' Journey to Second Place in AIxCC

    10-2-2026 | 23 Min.
    In the final episode of our AI Cyber Challenge (AIxCC) series, CRob sits down with Michael Brown, Principal Security Engineer at Trail of Bits, to discuss their runner-up cybersecurity reasoning system, Buttercup. Michael shares how their team took a hybrid approach - combining large language models with conventional software analysis tools like fuzzers - to create a system that exceeded even their own expectations. Learn how Trail of Bits made Buttercup fully open source and accessible to run on a laptop, their commitment to ongoing maintenance with prize winnings, and why they believe AI works best when applied to small, focused problems rather than trying to solve everything at once.
    This episode is part 3 of a four-part series on AIxCC:
    AIxCC part 1: From Skepticism to Success: The AI Cyber Challenge (AIxCC) with Andrew Carney
    AIxCC part 2: From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
    AIxCC part 4: Cyber Reasoning Systems: The Real-World Journey After AIxCC
    Chapters:
    00:04 - Introduction & Welcome
    00:12 - About Trail of Bits & Open Source Commitment
    03:16 - Buttercup: Second Place in AIxCC
    04:20 - The Hybrid Approach Strategy
    06:45 - From Skeptic to Believer
    09:28 - Surprises & Vindication During Competition
    11:36 - Multi-Agent Patching Success
    14:46 - Post-Competition Plans
    15:26 - Making Buttercup Run on a Laptop
    18:22 - The Giant Check & DEF CON
    18:59 - How to Access Buttercup on GitHub
    21:37 - Enterprise Deployment & Community Support
    22:23 - Closing Remarks

    Episode links:
    Michael Brown’s LinkedIn page
    AI Cyber Challenge (AIxCC)
    Trail of Bits
    Buttercup GitHub Repo
    OpenSSF AI/ML Security Working Group
    Cyber Reasoning Systems Special Interest Group (Slack)
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    AIxCC Part 2 - From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs

    10-2-2026 | 28 Min.
    In this 2nd episode in our series on DARPA's AI Cyber Challenge (AIxCC), CRob sits down with Professor Taesoo Kim from Georgia Tech to discuss Team Atlanta's journey to victory. Kim shares how his team - comprised of academics, world-class hackers, and Samsung engineers - initially skeptical of AI tools, underwent a complete mindset shift during the competition. He shares how they successfully augmented traditional security techniques like fuzzing and symbolic execution with LLM capabilities to find vulnerabilities in large-scale open source projects. Kim also reveals exciting post-competition developments, including commercialization efforts in smart contract auditing and plans to make their winning CRS accessible to the broader security community through integration with OSS-Fuzz.
    This episode is part 2 of a four-part series on AIxCC:
    AIxCC part 1: From Skepticism to Success: The AI Cyber Challenge (AIxCC) with Andrew Carney
    AIxCC part 3: Buttercup's Hybrid Approach: Trail of Bits' Journey to Second Place in AIxCC
    AIxCC part 4: Cyber Reasoning Systems: The Real-World Journey After AIxCC
    Chapters:
    00:00 - Introduction
    00:37 - Team Atlanta's Background and Competition Strategy
    03:43 - The Key to Victory: Combining Traditional and Modern Techniques
    05:22 - Proof of Vulnerability vs. Finding Bugs
    06:55 - The Mindset Shift: From AI Skeptics to Believers
    09:46 - Overcoming Scalability Challenges with LLMs
    10:53 - Post-Competition Plans and Commercialization
    12:25 - Smart Contract Auditing Applications
    14:20 - Making the CRS Accessible to the Community
    16:32 - Student Experience and Research Impact
    20:18 - Getting Started: Contributing to the Open Source CRS
    22:25 - Real-World Adoption and Industry Impact
    24:54 - The Future of AI-Powered Security Competitions

    Episodes Links:
    Taesoo Kim’s LinkedIn page
    AI Cyber Challenge (AIxCC)
    OSS-Fuzz Project
    OpenSSF AI/ML Security Working Group
    Cyber Reasoning Systems Special Interest Group (Slack)
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    AIxCC Part 1 - From Skepticism to Success: The AI Cyber Challenge (AIxCC) with Andrew Carney

    10-2-2026 | 23 Min.
    This episode of What’s in the SOSS features Andrew Carney from DARPA and ARPA-H, discussing the groundbreaking AI Cyber Challenge (AIxCC). The competition was designed to create autonomous systems capable of finding and patching vulnerabilities in open source software, a crucial effort given the pervasive nature of open source in the tech ecosystem. Carney shares insights into the two-year journey, highlighting the initial skepticism from experts that ultimately turned into belief, and reveals the surprising efficiency of the competing teams, who collectively found over 80% of inserted vulnerabilities and patched nearly 70%, with remarkably low compute costs. The discussion concludes with a look at the next steps: integrating these cyber reasoning systems into the open source community to support maintainers and supercharge automated patching in development workflows.

    This episode is part 1 of a four-part series on AIxCC:
    AIxCC part 2: From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
    AIxCC part 3: Buttercup's Hybrid Approach: Trail of Bits' Journey to Second Place in AIxCC
    AIxCC part 4: Cyber Reasoning Systems: The Real-World Journey After AIxCC
    Chapters:
    00:00 - Introduction and Guest Welcome 
    00:59 - Guest Background: Andrew Carney's Role at DARPA/ARPA-H
    02:20 - Overview of the AI Cyber Challenge (AIxCC)
    03:48 - Competition History and Structure
    04:44 - The Value of Skepticism and Surprising Learnings
    07:11 - Surprising Efficiency and Low Compute Costs
    08:15 - Major Competition Highlights and Results
    13:09 - What's Next: Integrating Cyber Reasoning Systems into Open Source
    16:55 - A Favorite Tale of "Robots Gone Bad"
    18:37 - Call to Action and Closing Thoughts

    Episode links:
    Andrew Carney’s LinkedIn page
    AI Cyber Challenge (AIxCC)
    OpenSSF AI/ML Security Working Group
    Cyber Reasoning Systems Special Interest Group (Slack)
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    Demystifying the CFP Process with KubeCon North America Keynote Speakers

    03-2-2026 | 33 Min.
    Ever wondered what it takes to get your talk accepted at a major open source tech conference – or even land a keynote slot? Join What’s in the Sauce new co-host Sally Cooper, as she sits down with Stacey Potter and Adolfo “Puerco” García Veytia, fresh off their viral KubeCon keynote "Supply Chain Reaction." In this episode, they pull back the curtain on the CFP review process, share what makes a strong proposal stand out, and offer honest advice about overcoming imposter syndrome. Whether you're a first-time speaker or a seasoned presenter, you'll learn practical tips for crafting compelling abstracts, avoiding common pitfalls, and why your unique voice matters more than you think.

    Chapters:
    00:00 - Introduction and Guest Welcome
    01:40 - Meet the Keynote Speakers
    05:27 - Why CFPs Matter for Open Source Communities
    08:29 - Inside the Review Process: What Reviewers Look For
    14:29 - Crafting a Strong Abstract: Dos and Don'ts
    21:05 - From Regular Talk to Keynote: What Changed
    25:24 - Conquering Imposter Syndrome
    29:11 - Rapid Fire CFP Tips
    30:45 - Upcoming Speaking Opportunities
    33:08 - Closing Thoughts

    Episode links:
    Adolfo García Veytia LinkedIn page
    Stacey Potter LinkedIn page
    KubeCon North America Keynote: Supply Chain Reaction: A Cautionary Tale in K8s Security
    OpenSSF Slack CFP Announce channel (#cfp-nnounce)
    Open Source Summit North America - CFP Closes February 9
    OpenSSF Community Day North America - CFP Closes February 15
    Open Source Summit Europe - CFP opens end of April or early May
    OpenSSF Community Day Europe - CFP opens early May
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn

Meer Technologie podcasts

Over What's in the SOSS? An OpenSSF Podcast

What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.
Podcast website

Luister naar What's in the SOSS? An OpenSSF Podcast, Acquired en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies