Achieving Positive Outcomes Across Ecosystems: Security Audits in Action - Amir Montazery

Presenters Amir Montazery Source OpenSource SecurityCon NA 2025 Fortifying the Digital Frontier: A Decade of Open-Source Security Audits 🛡️✨ Open-source software is the bedrock of our digital world, powering everything from your favorite apps to critical infrastructure. But with great power comes great responsibility, especially when it comes to security. Amir Montazeri, Managing Director of the Open-Source Technology Improvement Fund (OTF), recently shared invaluable insights into how we can collectively bolster the security of these essential projects. Celebrating its 10th anniversary, OTF is at the forefront of this crucial mission, and their work with the Cloud Native Computing Foundation (CNCF) is a shining example of what can be achieved through dedicated collaboration. ...

November 24, 2025 · 4 min

The State of Git Security With SLSA and Gittuf - Patrick Zielinski & Aditya Sirish A Yelgundhalli

Presenters Patrick Zielinski Aditya Sirish A Yelgundhalli Source OpenSource SecurityCon NA 2025 Fortifying Your Code: A Deep Dive into SLSA and GitHub for Unbreakable Software Supply Chains 🚀 In today’s interconnected digital world, the integrity of our software supply chain is paramount. We’ve all heard the alarming stories: compromised GitHub actions, hijacked organizations, and even vulnerabilities in widely used projects like PHP and Juniper. These incidents underscore a critical truth: a breach at the source code level can have devastating ripple effects. But fear not! The open-source community is tirelessly working to build stronger defenses, and at the forefront of this effort are SLSA and GitHub. ...

November 24, 2025 · 6 min

Can We Really Parse DNS in eBPF? Improving Cilium ToFQDN With In-kernel Policy Upda... Hemanth Malla

Presenters Hemanth Malla Source CiliumCon NA 2025 Unleashing the Power of eBPF: Cilium’s DNS Parsing Revolution 🚀 Hey tech enthusiasts! Ever found yourself frustrated by network policies that feel a bit… clunky? Especially when dealing with those ever-changing IP addresses tied to domain names? Well, get ready for some exciting news! Hemanth, a rockstar Cilium CNCF maintainer and principal engineer at Microsoft on the Azure container networking team, has just dropped a bombshell: Cilium can now parse DNS directly within eBPF! This isn’t just an incremental update; it’s a leap forward that promises to transform how we handle FQDN (Fully Qualified Domain Name) network policies. ...

November 24, 2025 · 5 min

From Adoption to Innovation: LinkedIn’s SPIRE Journey - Junyuan Zeng & Wei Zhang, LinkedIn

Presenters Junyuan Zeng Wei Zhang Source OpenSource SecurityCon NA 2025 LinkedIn’s Identity Revolution: From Fragile PKI to Spire-Powered Security! 🚀 Ever feel like your security infrastructure is a house of cards? 🃏 That’s exactly where LinkedIn found itself a few years ago. Their homegrown Public Key Infrastructure (PKI) system, built on a basic Python server, was buckling under the weight of their massive microservice architecture. It was a system that screamed “legacy” – lacking scalability, standard identity formats, and the ability to efficiently manage certificates. Imagine trying to build a skyscraper on a sandcastle foundation! 🏗️ ...

November 24, 2025 · 7 min

Lightning Talk: AIxCC Results and New Open Source AI Projects To Help Secure Open Sou... Jeff Diecks

Presenters Jeff Diecks Source OpenSource SecurityCon NA 2025 AI Cyber Challenge: Revolutionizing Open Source Security with Intelligent Automation 🚀 The world of open-source software is the backbone of our digital infrastructure, but it’s also a prime target for cyber threats. For years, the challenge has been not just finding vulnerabilities, but fixing them efficiently. Enter the AI Cyber Challenge (AICC), a groundbreaking initiative that brought together cutting-edge AI and the open-source community to tackle this critical problem head-on. ...

November 24, 2025 · 5 min