Josh Bressers's Avatar

Josh Bressers

@josh.bressers.name

Mostly on Mastodon - VP of Security at Anchore - Open Source Security https://opensourcesecurity.io - Hacker History http://hackerhistory.com - He/Him

381
Followers
463
Following
173
Posts
20.10.2024
Joined
Posts Following

Latest posts by Josh Bressers @josh.bressers.name

Preview
Rust coreutils with Sylvestre Ledru Josh talks to Sylvestre Ledru about the Rust coreutils project. We’ve been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason...

I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work

Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age

I learned a ton from this disucssion

02.03.2026 16:02 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Goose and the Agentic AI Foundation with Brad Axen Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things...

This week on #OpenSourceSecurity I chat with Brad Axen about Goose and the Agentic AI Foundation

I'm often skeptical about AI claims, but I do approve the foundation model and seeing Goose donated to it

23.02.2026 16:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Digital Sovereignty and Nextcloud with Frank Karlitschek Episode Links Frank Nextcloud Nextcloud getting started Digital Sovereignty Index This episode is also available as a podcast, search for β€œOpen Source Security” on your favorite podcast player.…

How does open source business model work, why is user empowerment so important, and when is the right time for digital sovereignty?

Find out in the new episode of the @josh.bressers.name podcast as he is joined by our founder @karlitschek.bsky.social

17.02.2026 18:25 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
The Global Vulnerability Intelligence Platform with Olle E. Johansson Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It’s no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few pe...

I had a chat with @oej.edvina.net about The Global Vulnerability Intelligence Platform

Olle is working to build a community around the future of vulnerability identifiers

Don't just give it a listen, but also come help Olle. It's a pretty important problem that nobody can solve alone

16.02.2026 17:47 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Digital Sovereignty and Nextcloud with Frank Karlitschek Episode Links Frank Nextcloud Nextcloud getting started Digital Sovereignty Index This episode is also available as a podcast, search for β€œOpen Source Security” on your favorite podcast player. Episod...

I had a chat with Frank Karlitschek from @nextcloud.bsky.social about digital sovereignty

There's a lot of attention lately around digital sovereignty and often that conversation also includes Nextcloud

09.02.2026 15:43 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
The Art of Crisis Management with David Bernstein Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical disruptions...

This episode of #OpenSourceSecurity I have a chat with David Bernstein about crisis response

I love this topic because responding to a crisis is pretty common in security work, but doesn't have to be a gong show

This is one of those topics that can go deep. David did a nice job covering basics

02.02.2026 15:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

In a recent episode of Open Source Security, @josh.bressers.name sits down with Victor Julien, founder and lead developer of the #Suricata project.

Tune in now! opensourcesecurity.io/2026/2026-01...

29.01.2026 14:56 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1
Preview
All about Suricata with Victor Julien Josh discusses Suricata with Victor Julien, the founder and lead developer of the Suricata project. Victor explains the history of Suricata, its impact on cybersecurity, and the community that keeps i...

This episode of #OpenSourceSecurity I discuss @suricata.io with Victor Julian

Victor tells us all about the past, present, and future of #Suricata

I learned a ton

opensourcesecurity.io/2026/2026-01...

19.01.2026 16:17 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Iocaine poisons bots with Gergely Nagy Josh talks to Gergely Nagy (algernon) about his tool Iocaine. Iocaine creates a maze to trap scraping bots in a world a fake pages they cannot escape. algernon tells us how Iocaine effectively traps b...

This week on #OpenSourceSecurity I have a chat with Gergely Nagy about Iocaine

Iocaine creates a maze of garbage to trap scraping bots. I love this idea, it has amazing chaotic good energy!

I learn all about how Iocaine works, and even got to see some dashboards showing off the size of the problem

12.01.2026 15:29 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Anubis with Xe Iaso Josh chats with Xe Iaso, the creator of Anubis the web AI firewall. We discuss how Anubis is tackling bots and scrapers. The discussion around the scrapers is fascinating and challenging, these things...

This week on #OpenSourceSecurity I have a chat with Xe Iaso about #Anubis, the tool that stops web AI scrapers

The scale of web scraping is way worse than I expected, and blocking things is also a lot harder than I expected

This is one of those conversations where I learned how little I know

05.01.2026 14:29 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Rustls with Dirkjan and Joe Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...

This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety

29.12.2025 14:49 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Daniel Thompson answers: Does the CRA apply to Santa? Josh welcomes back Daniel Thompson explore the rather silly question of whether Santa Claus needs to be compliant with the Cyber Resilience Act (CRA). This episode was intended to be silly, but it end...

On a very special Christmas episode of #OpenSourceSecurity I asked Daniel Thompson-Yvetot how the #CRA will impact Santa Claus

I meant the episode to be silly, just in time for Christmas, but I think I learned more from Daniel in those 50 minutes than I have in the last 3 years reading about CRA

22.12.2025 17:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Linux Foundation Europe with Gabriele Columbro Josh has a chat with Gabriele Columbro, Executive Director of the Fintech Open Source Foundation and General Manager of Linux Foundation Europe. We of course discuss the Cyber Resilience Act (CRA), th...

This #OpenSourceSecurity episode I chat with Gabriele Columbro from @linuxfoundationeu.bsky.social

We of course chat about the #CRA and how he helped with shaping what we see today

We also cover open source sustainability, vertical foundations, and all the attention open source is receiving

15.12.2025 15:32 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Updating open source dependencies with Jamie Tanna Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the cha...

This week on #OpenSourceSecurity I chat with Jamie Tanna about updating open source dependencies. It's usually not as simple as "just update" and Jamie has a ton of real world experience in this working on Renovate

opensourcesecurity.io/2025/2025-12...

08.12.2025 15:53 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

This was so much fun to talk about! If you want to find out how we found this bug, the raw story is here first, in my own words :)

01.12.2025 19:08 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Preview
TARmageddon with Alex Zenla Josh discusses the TARmageddon vulnerability with Alex Zenla, CTO of Edera. In this episode, we explore the discovery of the TARmageddon vulnerability. It’s especially interesting because it’s Rust, b...

This episode of #OpenSourceSecurity I chat with @alex.zenla.io from @edera.dev about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one

01.12.2025 19:04 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 2
Preview
Python Security with Seth Larson In this episode Seth Larson gives us a cornucopia of topics relating to Python security. Seth discusses the Python Software Foundation’s decision to reject a significant grant NSF. Diversity is a big ...

#OpenSourceSecurity has a chat with @sethmlarson.dev about @python.org security

Seth has a new whitepaper, there's a CFP open (which you should submit a paper to), and some discussion about the PSF grant situation

It's always fun to chat with Seth, I learn a ton every time!

24.11.2025 15:58 πŸ‘ 9 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Linux Vendor Firmware Service with Richard Hughes Josh talks to Richard Hughes about the world of firmware. We cover how Richard’s journey from developing the ColorHug led to the creation of the Linux Vendor Firmware Service (LVFS), changing how firm...

On this episode of #OpenSourceSecurity I chat with Richard Hughes about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

17.11.2025 15:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
NPM supply chain attacks with Charlie Eriksen Josh chats with Charlie Eriksen, a security researcher at Aikido Security. We discuss the recent NPM supply chain attacks that affect hundreds of packages. Charlie shares his experiences dealing with ...

I had a chat with @charlieeriksen.bsky.social about the recent NPM attacks

We chat about what happened (now that the dust settled), and we discuss what's next.

Charlie is doing some great work in this space, he understands the problem better than most

10.11.2025 14:58 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Detecting XZ in Debian with Otto KekΓ€lΓ€inen In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’...

This week on #OpenSourceSecurity I talk to @ottoke.bsky.social about his blog post about detecting an attack like xz in Debian

It's a fascinating conversation about a very complicated topic

There are things that could be detected, but this one would have been very very difficult

03.11.2025 15:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Rock over London, rock on Chicago

01.11.2025 00:18 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Eclipse Foundation SBOMs with Mikael Barbero In this conversation, Josh speaks with Mikael Barbero, head of security at the Eclipse Foundation. They discuss the foundation’s role in enhancing the security posture of open source projects, the imp...

I chat with @mikael.barbero.tech about security happenings at the Eclipse Foundation

My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

20.10.2025 14:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

πŸŽ™ Just wrapped a fantastic conversation with @josh.bressers.name. We dive deep into enhancing open source security and how we do it at the @eclipse.org

Can't wait for you to hear the full episode, coming soon!

16.10.2025 16:18 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Sustaining Package Repositories with Brian Fox Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import...

On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries

This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter

opensourcesecurity.io/2025/2025-10...

06.10.2025 14:26 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?

9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images

Not fear-mongeringβ€”just data-driven real... https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #ContainerSecurity

02.10.2025 22:50 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Arch Linux Security with Foxboron and Anthraxx Join us for a conversation with Foxboron (Morten Linderud) and Anthraxx (Levente Polyak), members of the Arch Linux security team. We talk about the difficulties of maintaining a Linux distribution, t...

This week on #OpenSourceSecurity I chat with @foxboron.bsky.social and Levente Polyak about Arch Linux security. It's a great chat where we talk about all the difficulties and oddities of trying to keep a Linux distribution secure

I learned a ton, I'm sure you will too

29.09.2025 15:00 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Home - Hacker History Podcast Hacker History: Explore where it all began, interviews with retro hackers, the pioneers and forefathers of yesteryear. The true old school hackers amongst our societies have an unquenchable thirst for...

If you ever want to tell some stories, I have a podcast I run for @cyphercon.bsky.social called Hacker History

hackerhistory.com

25.09.2025 03:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
OpenSSL with Hana Andersen and Anton Arapov I discuss all things OpenSSL with Hana Andersen and Anton Arapov from the OpenSSL Corporation. Discover the intricacies of organizing the first-ever OpenSSL conference in Prague, the importance of pos...

This episode of #OpenSourceSecurity I chat with Hana Andersen and Anton Arapov about their upcoming #OpenSSL conference

They also answer a bunch of my questions about the structure of the OpenSSL project, how we got where we are today, and what's coming next

opensourcesecurity.io/2025/2025-09...

22.09.2025 14:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Don’t miss this podcast episode with the PSF’s Executive Director, @eximious.bsky.social, on funding open source, PyCon US, global community support & the importance of sustainability!

17.09.2025 12:51 πŸ‘ 7 πŸ” 6 πŸ’¬ 1 πŸ“Œ 0
Preview
The Python Software Foundation with Deb Nicholson In this episode I discuss the Python Software Foundation with Deb Nicholson. We discuss their contributions to the Python programming community. Learn how this dedicated organization supports the grow...

This episode of #OpenSourceSecurity I chat with Deb Nicholson about the Python Software Foundation. We discuss what they do, their current grant program, and how you can get involved

The PSF is the group behind the legendary Python community. It's a fun chat, Deb has so much knowledge to share

15.09.2025 15:52 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1