Listen "PSW #770 - Brian Behlendorf"
Episode Synopsis
This week in the Security News: GetVariable strikes again, attackers could blow up your computer remotely, escaping containers, null-dereferences and faulty evaluations, 31 new CPU vulnerabilities for AMD, a look into Chrome, santa, not-so-secure secure booting, and malware included! Open source is the bedrock of most of the world's software today, so how to raise the floor on software quality across the industry? First, we need better tools to measure the trustworthiness of code based on objective measures, processes that encourage better security practices by developers, and tools and processes that encourage teamwork and shared responsibility for security. Several efforts are underway in major open source communities to address these issues. At the Open Source Security Foundation (OpenSSF), major companies, open source software maintainers, startup companies and government actors are working together to improve open source software supply chain security. Brian will share his view of this landscape, detail the work being done at the OpenSSF, show where those efforts are already bearing fruit, and demonstrate what you and your organization can (must!) do to participate in these efforts. Segment Resources: https://openssf.org/ Visit https://www.securityweekly.com/psw for all the latest episodes! Visit https://securityweekly.com/acm to sign up for a demo or buy our AI Hunter! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly Show Notes: https://securityweekly.com/psw770
More episodes of the podcast Paul's Security Weekly (Audio)
Going Around EDR - PSW #900
13/11/2025
Cybersecurity Is Dead - PSW #898
30/10/2025
Its Always DNS - PSW #897
23/10/2025
AI, EDR, and Hacking Things - PSW #896
16/10/2025
IoT Hacks Galore - Kieran Human - PSW #895
09/10/2025
Broadcom, LastPass, SEO Poisoning, QR codes, H1B visas, Distributed Computing... - PSW #893
25/09/2025
Safes, Hackers, and Web Servers - PSW #892
18/09/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.