

Josh Bressers
Longtime Open Source Security show host and moderator who guides conversations on open-source security topics and coordinates interviews with distro security teams.
Top 3 podcasts with Josh Bressers
Ranked by the Snipd community

May 6, 2025 • 53min
The Hidden Risks of Open Source Components - BTS #49
Josh Bressers, a supply chain and open source security expert at Anchore, dives into the intricate world of open source components. He discusses the pervasive challenges of managing vulnerabilities in legacy systems and the critical role of Software Bill of Materials (SBOMs). They tackle regulatory pressures around software liability and the automation needed to tackle the increasing volume of CVEs. Josh also highlights innovative tools like SIFT and Gripe, emphasizing their importance in enhancing transparency and security in software development.

Aug 22, 2024 • 2h 59min
How do we patch the right things? - Josh Bressers - PSW #840
Josh Bressers, a knowledgeable figure in vulnerabilities and exploits, dives into the complexities of patch management. He discusses the limitations of tools like MITRE ATT&CK and CVSS in accurately prioritizing vulnerabilities. The conversation emphasizes the importance of context in patching decisions and addresses the challenges of tracking incidents that lack CVEs. Bressers shares insights on the balance between urgent patches and asset criticality, highlighting personal anecdotes that shed light on navigating the evolving cybersecurity landscape.

Mar 22, 2024 • 29min
S6E11: Josh Bressers & Dan Lorenc - Untangling the NVD Chaos
Experts discuss the drama around NVD and its impact on vulnerability management. They highlight concerns about lack of CVE enrichment and the grassroots effort to raise awareness. The podcast explores the underfunding and oversight of critical software ecosystem components. Future solutions from NIST/NVD, government, and industry are discussed to resolve the issue.