<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Tue, 21 Apr 2026 23:38:31 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Open Source Software”</title>
    <link>https://securityconversations.fireside.fm/tags/open%20source%20software</link>
    <pubDate>Tue, 12 Sep 2023 16:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>Abhishek Arya on Google's AI cybersecurity experiments</title>
  <link>http://securityconversations.fireside.fm/abhishek-arya-google-open-source-supply-chain</link>
  <guid isPermaLink="false">013e4610-5aeb-4cb3-89d1-509db8c25ffd</guid>
  <pubDate>Tue, 12 Sep 2023 16:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/013e4610-5aeb-4cb3-89d1-509db8c25ffd.mp3" length="31344253" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly (https://binarly.io)
- FwHunt (https://fwhunt.run)

Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  

In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry's over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</itunes:subtitle>
  <itunes:duration>33:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/013e4610-5aeb-4cb3-89d1-509db8c25ffd/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  
In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry's over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains. 
</description>
  <itunes:keywords>supply chain, open source software, sbom, log4j, codecov, solarwinds, sunburst, apt, credential theft, npm, typosquatting, code quality, shift-left</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  </p>

<p>In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry&#39;s over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</p><p>Links:</p><ul><li><a title="Abhishek Arya on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/abhishek-arya-a565373/">Abhishek Arya on LinkedIn</a></li><li><a title="OSS-Fuzz: Continuous fuzzing for open source software" rel="nofollow" href="https://github.com/google/oss-fuzz/blob/master/README.md">OSS-Fuzz: Continuous fuzzing for open source software</a></li><li><a title="Google Brings AI Magic to Fuzz Testing" rel="nofollow" href="https://www.securityweek.com/google-brings-ai-magic-to-fuzz-testing-with-eye-opening-results/">Google Brings AI Magic to Fuzz Testing</a></li><li><a title="AI-Powered Fuzzing: Breaking the Bug Hunting Barrier" rel="nofollow" href="https://security.googleblog.com/2023/08/ai-powered-fuzzing-breaking-bug-hunting.html">AI-Powered Fuzzing: Breaking the Bug Hunting Barrier</a></li><li><a title="AI Cyber Challenge" rel="nofollow" href="https://aicyberchallenge.com/">AI Cyber Challenge</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  </p>

<p>In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry&#39;s over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</p><p>Links:</p><ul><li><a title="Abhishek Arya on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/abhishek-arya-a565373/">Abhishek Arya on LinkedIn</a></li><li><a title="OSS-Fuzz: Continuous fuzzing for open source software" rel="nofollow" href="https://github.com/google/oss-fuzz/blob/master/README.md">OSS-Fuzz: Continuous fuzzing for open source software</a></li><li><a title="Google Brings AI Magic to Fuzz Testing" rel="nofollow" href="https://www.securityweek.com/google-brings-ai-magic-to-fuzz-testing-with-eye-opening-results/">Google Brings AI Magic to Fuzz Testing</a></li><li><a title="AI-Powered Fuzzing: Breaking the Bug Hunting Barrier" rel="nofollow" href="https://security.googleblog.com/2023/08/ai-powered-fuzzing-breaking-bug-hunting.html">AI-Powered Fuzzing: Breaking the Bug Hunting Barrier</a></li><li><a title="AI Cyber Challenge" rel="nofollow" href="https://aicyberchallenge.com/">AI Cyber Challenge</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Jason Chan on Microsoft's security problems, layoffs and startups</title>
  <link>http://securityconversations.fireside.fm/jason-chan-bessemer-venture-partners</link>
  <guid isPermaLink="false">c38cc994-c217-4b50-b5bb-07900a1bee04</guid>
  <pubDate>Mon, 07 Aug 2023 07:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/c38cc994-c217-4b50-b5bb-07900a1bee04.mp3" length="19285621" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly (https://binarly.io)
- FwHunt (https://fwhunt.run)

Bessemer Venture Partner's Jason Chan returns to the show for a frank discussion on the state of cyber, including thoughts on Microsoft's prominent security failures, the meaning of layoffs hitting security teams, the excitement around AI, and the long road ahead.  The former Netflix security chief also talks about merging of the IT and security functions and the importance of cybersecurity proving its value to the business.</itunes:subtitle>
  <itunes:duration>27:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/c38cc994-c217-4b50-b5bb-07900a1bee04/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Bessemer Venture Partner's Jason Chan returns to the show for a frank discussion on the state of cyber, including thoughts on Microsoft's prominent security failures, the meaning of layoffs hitting security teams, the excitement around AI, and the long road ahead.  The former Netflix security chief also talks about merging of the IT and security functions and the importance of cybersecurity proving its value to the business. 
</description>
  <itunes:keywords>Microsoft, entrepreneurship, generative ai, layoffs, VC funding, open source software, CISO, transparency</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Bessemer Venture Partner&#39;s Jason Chan returns to the show for a frank discussion on the state of cyber, including thoughts on Microsoft&#39;s prominent security failures, the meaning of layoffs hitting security teams, the excitement around AI, and the long road ahead.  The former Netflix security chief also talks about merging of the IT and security functions and the importance of cybersecurity proving its value to the business.</p><p>Links:</p><ul><li><a title="Jason Chan, VP, Information Security, Netflix" rel="nofollow" href="https://securityconversations.com/episode/jason-chan-vp-information-security-netflix/">Jason Chan, VP, Information Security, Netflix</a></li><li><a title="Jason Chan on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/jasonbchan/">Jason Chan on LinkedIn</a></li><li><a title="Follow Jason on Twitter / X" rel="nofollow" href="https://twitter.com/chanjbs">Follow Jason on Twitter / X</a></li><li><a title="Jason Chan - Bessemer Venture Partners" rel="nofollow" href="https://www.bvp.com/team/jason-chan">Jason Chan - Bessemer Venture Partners</a> &mdash; Jason Chan is an operating advisor at Bessemer where he brings over twenty years of experience in cybersecurity and is especially passionate about large-scale systems, cloud security, and improving security in modern software development practices. Most recently, Jason built and led the information security team at Netflix for over a decade. His team at Netflix was known for its contributions to the security community, including over 30 open-source security releases and dozens of conference presentations. He also previously led the security team at VMware and spent most of his earlier career in security consulting. </li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Bessemer Venture Partner&#39;s Jason Chan returns to the show for a frank discussion on the state of cyber, including thoughts on Microsoft&#39;s prominent security failures, the meaning of layoffs hitting security teams, the excitement around AI, and the long road ahead.  The former Netflix security chief also talks about merging of the IT and security functions and the importance of cybersecurity proving its value to the business.</p><p>Links:</p><ul><li><a title="Jason Chan, VP, Information Security, Netflix" rel="nofollow" href="https://securityconversations.com/episode/jason-chan-vp-information-security-netflix/">Jason Chan, VP, Information Security, Netflix</a></li><li><a title="Jason Chan on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/jasonbchan/">Jason Chan on LinkedIn</a></li><li><a title="Follow Jason on Twitter / X" rel="nofollow" href="https://twitter.com/chanjbs">Follow Jason on Twitter / X</a></li><li><a title="Jason Chan - Bessemer Venture Partners" rel="nofollow" href="https://www.bvp.com/team/jason-chan">Jason Chan - Bessemer Venture Partners</a> &mdash; Jason Chan is an operating advisor at Bessemer where he brings over twenty years of experience in cybersecurity and is especially passionate about large-scale systems, cloud security, and improving security in modern software development practices. Most recently, Jason built and led the information security team at Netflix for over a decade. His team at Netflix was known for its contributions to the security community, including over 30 open-source security releases and dozens of conference presentations. He also previously led the security team at VMware and spent most of his earlier career in security consulting. </li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Chainguard's Dan Lorenc gets real on software supply chain problems</title>
  <link>http://securityconversations.fireside.fm/dan-lorenc-chainguard-supply-chain</link>
  <guid isPermaLink="false">04e22eb6-dc8d-4dae-af5b-44f4d4aca81d</guid>
  <pubDate>Thu, 13 Oct 2022 08:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/04e22eb6-dc8d-4dae-af5b-44f4d4aca81d.mp3" length="36469411" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>* Episode sponsors: [Binarly](https://binarly.io/) and [FwHunt](https://fwhunt.run/) - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence.

Dan Lorenc and team or ex-Googlers raised $55 million in early-stage funding to build technology to secure software supply chains. On this episode of the show, Dan joins Ryan to talk about the different faces of the supply chain problem, the security gaps that will never go away, the decision to raise an unusually large early-stage funding round, and how the U.S. government's efforts will speed up technology innovation.</itunes:subtitle>
  <itunes:duration>47:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/04e22eb6-dc8d-4dae-af5b-44f4d4aca81d/cover.jpg?v=1"/>
  <description>Episode sponsors: Binarly (https://binarly.io/) and FwHunt (https://fwhunt.run/) - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence.
Dan Lorenc and a team or ex-Googlers raised $55 million in early-stage funding to build technology to secure software supply chains. On this episode of the show, Dan joins Ryan to talk about the different faces of the supply chain problem, the security gaps that will never go away, the decision to raise an unusually large early-stage funding round, and how the U.S. government's efforts will speed up technology innovation.  
</description>
  <itunes:keywords>supply chain, open source software, sbom, log4j, codecov, solarwinds, sunburst, apt, credential theft, npm, typosquatting, code quality, shift-left</itunes:keywords>
  <content:encoded>
    <![CDATA[<ul>
<li>Episode sponsors: <a href="https://binarly.io/" rel="nofollow">Binarly</a> and <a href="https://fwhunt.run/" rel="nofollow">FwHunt</a> - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence.</li>
</ul>

<p>Dan Lorenc and a team or ex-Googlers raised $55 million in early-stage funding to build technology to secure software supply chains. On this episode of the show, Dan joins Ryan to talk about the different faces of the supply chain problem, the security gaps that will never go away, the decision to raise an unusually large early-stage funding round, and how the U.S. government&#39;s efforts will speed up technology innovation. </p><p>Links:</p><ul><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Chainguard Enforce" rel="nofollow" href="https://www.chainguard.dev/chainguard-enforce">Chainguard Enforce</a></li><li><a title="Sounil Yu on SBOMs, software supply chain security" rel="nofollow" href="https://securityconversations.com/episode/sounil-yu-on-sboms-software-supply-chain-security/">Sounil Yu on SBOMs, software supply chain security</a></li><li><a title="Extending SBOMs to the firmware layer" rel="nofollow" href="https://securityconversations.com/extending-sboms-to-the-firmware-layer/">Extending SBOMs to the firmware layer</a></li><li><a title="Cybersecurity Leaders Scramble to Decipher SBOM Mandate" rel="nofollow" href="https://www.securityweek.com/cybersecurity-leaders-scramble-decipher-sbom-mandate">Cybersecurity Leaders Scramble to Decipher SBOM Mandate</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<ul>
<li>Episode sponsors: <a href="https://binarly.io/" rel="nofollow">Binarly</a> and <a href="https://fwhunt.run/" rel="nofollow">FwHunt</a> - Protecting devices from emerging firmware and hardware threats using modern artificial intelligence.</li>
</ul>

<p>Dan Lorenc and a team or ex-Googlers raised $55 million in early-stage funding to build technology to secure software supply chains. On this episode of the show, Dan joins Ryan to talk about the different faces of the supply chain problem, the security gaps that will never go away, the decision to raise an unusually large early-stage funding round, and how the U.S. government&#39;s efforts will speed up technology innovation. </p><p>Links:</p><ul><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Chainguard Enforce" rel="nofollow" href="https://www.chainguard.dev/chainguard-enforce">Chainguard Enforce</a></li><li><a title="Sounil Yu on SBOMs, software supply chain security" rel="nofollow" href="https://securityconversations.com/episode/sounil-yu-on-sboms-software-supply-chain-security/">Sounil Yu on SBOMs, software supply chain security</a></li><li><a title="Extending SBOMs to the firmware layer" rel="nofollow" href="https://securityconversations.com/extending-sboms-to-the-firmware-layer/">Extending SBOMs to the firmware layer</a></li><li><a title="Cybersecurity Leaders Scramble to Decipher SBOM Mandate" rel="nofollow" href="https://www.securityweek.com/cybersecurity-leaders-scramble-decipher-sbom-mandate">Cybersecurity Leaders Scramble to Decipher SBOM Mandate</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
