<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Wed, 22 Apr 2026 03:34:36 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Oss Fuzz”</title>
    <link>https://securityconversations.fireside.fm/tags/oss-fuzz</link>
    <pubDate>Tue, 12 Sep 2023 16:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>Abhishek Arya on Google's AI cybersecurity experiments</title>
  <link>http://securityconversations.fireside.fm/abhishek-arya-google-open-source-supply-chain</link>
  <guid isPermaLink="false">013e4610-5aeb-4cb3-89d1-509db8c25ffd</guid>
  <pubDate>Tue, 12 Sep 2023 16:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/013e4610-5aeb-4cb3-89d1-509db8c25ffd.mp3" length="31344253" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly (https://binarly.io)
- FwHunt (https://fwhunt.run)

Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  

In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry's over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</itunes:subtitle>
  <itunes:duration>33:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/013e4610-5aeb-4cb3-89d1-509db8c25ffd/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  
In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry's over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains. 
</description>
  <itunes:keywords>supply chain, open source software, sbom, log4j, codecov, solarwinds, sunburst, apt, credential theft, npm, typosquatting, code quality, shift-left</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  </p>

<p>In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry&#39;s over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</p><p>Links:</p><ul><li><a title="Abhishek Arya on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/abhishek-arya-a565373/">Abhishek Arya on LinkedIn</a></li><li><a title="OSS-Fuzz: Continuous fuzzing for open source software" rel="nofollow" href="https://github.com/google/oss-fuzz/blob/master/README.md">OSS-Fuzz: Continuous fuzzing for open source software</a></li><li><a title="Google Brings AI Magic to Fuzz Testing" rel="nofollow" href="https://www.securityweek.com/google-brings-ai-magic-to-fuzz-testing-with-eye-opening-results/">Google Brings AI Magic to Fuzz Testing</a></li><li><a title="AI-Powered Fuzzing: Breaking the Bug Hunting Barrier" rel="nofollow" href="https://security.googleblog.com/2023/08/ai-powered-fuzzing-breaking-bug-hunting.html">AI-Powered Fuzzing: Breaking the Bug Hunting Barrier</a></li><li><a title="AI Cyber Challenge" rel="nofollow" href="https://aicyberchallenge.com/">AI Cyber Challenge</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Abhishek Arya is director of engineering at Google, overseeing open source and supply chain security efforts that include OSS-Fuzz, SLSA, GUAC and OSV DB.  </p>

<p>In this episode, Arya talks about some early success experimenting with AI and LLMs on fuzzing and vulnerability management, the industry&#39;s over-pivoting on SBOMs, regulations and liability for software vendors, and the long road ahead for securing software supply chains.</p><p>Links:</p><ul><li><a title="Abhishek Arya on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/abhishek-arya-a565373/">Abhishek Arya on LinkedIn</a></li><li><a title="OSS-Fuzz: Continuous fuzzing for open source software" rel="nofollow" href="https://github.com/google/oss-fuzz/blob/master/README.md">OSS-Fuzz: Continuous fuzzing for open source software</a></li><li><a title="Google Brings AI Magic to Fuzz Testing" rel="nofollow" href="https://www.securityweek.com/google-brings-ai-magic-to-fuzz-testing-with-eye-opening-results/">Google Brings AI Magic to Fuzz Testing</a></li><li><a title="AI-Powered Fuzzing: Breaking the Bug Hunting Barrier" rel="nofollow" href="https://security.googleblog.com/2023/08/ai-powered-fuzzing-breaking-bug-hunting.html">AI-Powered Fuzzing: Breaking the Bug Hunting Barrier</a></li><li><a title="AI Cyber Challenge" rel="nofollow" href="https://aicyberchallenge.com/">AI Cyber Challenge</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
