We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=52p2WywWq7g
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=52p2WywWq7g

๐Ÿ” COSCUP x UbuCon Asia 2026 CFP closes in 3 days โ€” and today happens to be World Password Day.

๐Ÿ“… CFP Deadline: 2026/5/9 AoE
๐Ÿ“จ Submit your proposal: https://pretalx.coscup.org/coscup-2026/cfp
๐Ÿ“– CFP announcement: https://blog.coscup.org/2026/03/coscup-x-ubucon-asia-2026-coscup-x.html

#COSCUP2026 #UbuConAsia #HITCON #CyberResilience #CyberSecurity #OpenSource #OpenSourceSecurity

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team and our guest Michael Cotรฉ from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=m7RfVrN1TUc
We're LIVE! Join the Anchore Open Source team and our guest Michael Cotรฉ from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=m7RfVrN1TUc

โšก New Secure Development Talk at BSides Luxembourg 2026!

๐—•๐—จ๐—œ๐—Ÿ๐——๐—œ๐—ก๐—š ๐—ฉ๐—ฆ. ๐—•๐—จ๐—ฌ๐—œ๐—ก๐—š โ€“ ๐—” ๐—ง๐—”๐—Ÿ๐—˜ ๐—ข๐—™ ๐——๐—˜๐—ฉ๐—˜๐—Ÿ๐—ข๐—ฃ๐—œ๐—ก๐—š ๐—”๐—ก ๐—œ๐—ก-๐—›๐—ข๐—จ๐—ฆ๐—˜ ๐—ฆ๐—–๐—” ๐—ง๐—ข๐—ข๐—Ÿ โ€“ Diogo Lemos

Why do Software Composition Analysis tools so often fail in practice? This 40-minute talk takes you inside the journey of building a production-ready, open-source SCA platform designed to fix exactly that problem. Instead of drowning teams in noisy alerts and inconsistent findings, the focus shifts to clarity, prioritization, and actionable risk reduction.

The session explores how to design and implement an SCA system that scales across large organizationsโ€”covering dependency discovery (including transitive ones), vulnerability aggregation from multiple sources, normalization of inconsistent data, and a risk-based scoring model that helps teams focus on what actually matters. A live demo will show a real repository being scanned, vulnerabilities being identified, and results flowing directly into CI/CD pipelines for actionable enforcement.

Diogo Lemos is an Application Security Engineer with deep experience in building security tooling at scale. Having worked at Checkmarx, Flutter Entertainment, and OLX, he specializes in automation, SCA, SAST, and scalable AppSec programs, and actively contributes to open-source security initiatives.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #SecureDevelopment #SCA #SupplyChainSecurity #AppSec #OpenSourceSecurity

โšก New Talk Spotlight at BSides Luxembourg 2026!

๐—–๐—จ๐—ฅ๐—”๐—ง๐—œ๐—ก๐—š ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—ฆ๐—ข๐—™๐—ง๐—ช๐—”๐—ฅ๐—˜: ๐—ง๐—›๐—˜ ๐—”๐—ฅ๐—ง ๐—ข๐—™ ๐—ฆ๐—˜๐—Ÿ๐—˜๐—–๐—ง๐—œ๐—ก๐—š ๐—ฆ๐—”๐—™๐—˜ ๐——๐—˜๐—ฃ๐—˜๐—ก๐——๐—˜๐—ก๐—–๐—œ๐—˜๐—ฆ โ€“ Frithjof Hoffmann

Rethink how you build software in this insightful 40-minute session from the Secure Development track. Just like curating an art gallery, selecting dependencies requires careful evaluation, authenticity checks, and long-term consideration. This talk explores how overlooked third-party components can introduce hidden risksโ€”from vulnerabilities and malware to licensing and maintenance issues.

Discover practical strategies to assess, manage, and automate dependency selection, while building a trusted and resilient software supply chain. Learn how adopting a โ€œcuration mindsetโ€ can transform development practicesโ€”helping teams move beyond blind trust and toward secure, high-quality foundations.

Frithjof Hoffmann is a cybersecurity professional specializing in software supply-chain security, threat intelligence, and risk management. With a strong focus on helping organizations reduce risk and improve visibility, he brings practical expertise in building secure and scalable software ecosystems.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #SecureDevelopment #SupplyChainSecurity #OpenSourceSecurity #AppSec #CyberSecurity

I had another chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity

With all the events unfolding almost every day lately, there's never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it

It's a lot less complicated than it seems, I know I've made this a lot harder than it needs to be

https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/

Building a plan for disaster with David Bernstein

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. Itโ€™s a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, itโ€™s really not that hard to put some plans together. Itโ€™s easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident.

Open Source Security