







I’m a Principal Engineer at MITRE helping people make informed decisions about the software they depend on. I lead Hipcheck and contribute to the CVE system.
Bailey Townsend | Software Developer
Bandaid Engineer and open source software developer.


Josh Miller on Twitter / X
Starting today, Cory Hardman is @browsercompany's new head of security engineering. Cory was previously Head of Security for OpenSea, and a senior security engineer at Google (9 years) & Notion. Whether Arc for Teams or Dia for Consumers, security is a top 2025 priority.— Josh Miller (@joshm) January 8, 2025
Developer Ecosystems for Software Safety
How to design and implement information systems so they are safe and secure is a complex topic. Both high-level design principles and implementation guidance for software safety and security are well established and broadly accepted. For example, Jerome Saltzer and Michael Schroeder’s seminal overview of principles of secure design was published almost 50 years ago,10 and various community and governmental bodies have published comprehensive best practices about how to avoid common software weaknesses—for example, Common Weakness Enumeration (CWE)a and Open Worldwide Application Security Project (OWASP) Cheat Sheet Series.b

Graham Fleming | Software & Hardware Engineer
The Human Co-Pilot for Early-Stage Founders. Expert software & hardware engineer specializing in Next.js, AI integration, scaling infrastructure, and fixing tech debt.


imput
We develop private, efficient, and respectful software. We also do security research, reverse engineering, and develop network services.
Scan's lab
Full stack developer who likes making open source software and exploring the web.

AI CVE Slop: The Crisis Drowning Open Source Security
The proliferation of AI-generated vulnerability reports — commonly termed “AI slop” — has emerged as one of the most significant…
argv*mory
it was a not really sunny day in tpa, fl, when i got the message from cpp swift's president. it was an invite to help with their info sec conference, the Tech Symposium. they were looking for community members who would be willing to help with different aspects, tabling, ctf challenges, organization. my brain started to turn and i knew i wanted to do something really funny. last year in october, i had tabled at the CSUF's OSScon, ran by their security club, OSS. the tabling was fun and i got to present some malware that i was working on for a research project with mitre , which is avalible here. it was cool to get people to mess around with malware when they've never seen it before, but for the tech Symposium, i had a more substantial idea of what i wanted to do.
Alex Casillas - Senior Software Engineer, aspiring Principal Engineer, Entrepreneur, Open Source Developer
I'm Alex Casillas, a Senior Software Engineer working for Toptal working towards Principal Engineering. I'm based in Córdoba, Spain. I'm an entrepreneur constantly working on side-projects and an avid open source developer
AI Agents Security Incidents and related CVEs for Enterprise Security Teams - DataBahn
Comprehensive CVE & Incident Database for Enterprise Security Teams
.avif)
oss-security - Dirty Frag: Universal Linux LPE
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
The Last Software Engineer
Kent C. Dodds is a web development educator working on Epic Product Engineer and he's the father of five kids in Utah.