Advertisement · 728 × 90

Posts by

With the help of Ada Logics, 7ASecurity, and the Sovereign Tech Agency, this project received expert security review, testing, and custom documentation contributing to DEfO’s ongoing development and security.

1 week ago 0 0 0 0
DEfO Audit Complete! – OSTIF.org

The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”).

ostif.org/defo-audit-c...

#OSTIF #DEfO #AdaLogics #7ASecurity #SovereignTechAgency

1 week ago 0 0 1 0
Post image

#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social!

🗓️ March 25 - 16:45 CET
📍 Hall 8 | Room F

4 weeks ago 3 5 1 1
Preview
Linux Foundation Announces $12.5 Million in Grant Funding from Leading Organizations to Advance Open Source Security Linux Foundation announces launch of the React Foundation

The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and @openssf.org)

Anthropic, AmazonWebServices, GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource

1 month ago 22 4 3 0
Post image

We are proud to announce our top 3 bugs of the year on our blog: ostif.org/bug-of-the-y...

#OSTIF #BOTY #7ASecurity

1 month ago 2 1 0 0
Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David
Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David YouTube video by Open Source Technology Improvement Fund (OSTIF)

Miss our last OSTIF meetup?

You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".

www.youtube.com/watch?v=J1Y1...

#OSTIF #bitcoin

1 month ago 0 0 0 0
Preview
Kea and Stork Projects Audited In mid-2025 ISC contracted with OSTIF to identify an external organization to audit our Kea and Stork code for security issues.

ISC is pleased to announce the results of code audits for our Kea DHCP and Stork graphical management software projects! Thank you to @ostifofficial.bsky.social and the ICANN Grant Program for their support and assistance.

Read more about the audits at www.isc.org/blogs/2026-t...

1 month ago 1 1 0 0
Advertisement
Preview
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…

Don't miss tomorrow's OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".

luma.com/gjnorzq0

#OSTIF #OpenSource #bitcoin

1 month ago 1 0 0 0
Post image

OSTIF is proud to share the results of our security audit of Stork, an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers.

ostif.org/stork-audit-...

#OSTIF #Stork #7ASecurity

1 month ago 2 0 0 0

While there is a lot to address, an important point of this story sticks out to us at OSTIF- that it was best practices, the secondary review of code before a push, that caught this before disaster struck.

1 month ago 0 0 0 0
The Internet Was Weeks Away From Disaster and No One Knew
The Internet Was Weeks Away From Disaster and No One Knew YouTube video by Veritasium

We, like everyone else, couldn't look away from the Veritasium video on the XZ vulnerability.

Watch the video here www.youtube.com/watch?v=aoag... to learn more details about this incredible story of open source security and community.

#OSTIF #Veritasium #XZ

1 month ago 1 0 1 0
Post image

For the past 4 years, OSTIF has run a Managed Audit Program for the CNCF. We’ve audited 33 projects in that time, working with maintainers all over the world to reinforce the security health of cloud native open source for billions of end users.

Read the full report here: ostif.org/cncfmanagedp...

1 month ago 0 0 0 0
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi YouTube video by Open Source Technology Improvement Fund (OSTIF)

Miss yesterday's amazing audit meetup "High Assurance Cryptography and the Ethics of Disclosure" w/ @nadim.computer ?

Catch the video here www.youtube.com/watch?v=TdOX...

Make sure you're subscribed for notifications of any new meetups! luma.com/ostif-meetups

#OSTIF #meetup #audit

1 month ago 1 0 0 0
Preview
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…

Join us next Wednesday for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". luma.com/gjnorzq0

#OSTIF #OpenSource #bitcoin

1 month ago 1 0 0 0
Preview
Powered by LimeSurvey – The Freshest Online Survey Tool Create surveys in seconds with LimeSurvey. Easy to use, secure, and trusted by professionals worldwide. Get started free and unlock fresh insights today!

Reminder: The Sovereign Tech Agency is gathering feedback from open source maintainers and contributors working with technology standards to inform the Agency's future work and new initiatives.

➡️ survey.sovereigntechfund.de/999999?lang=...

1 month ago 1 2 1 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

TODAY: Join my livestreamed talk on my Cryspen findings and ask me questions! 5:00pm Paris time, coordinated with @ostifofficial.bsky.social.

Register here: luma.com/xc4yuezb?tk=...

1 month ago 1 2 1 0
Sovereign Tech Agency and OSTIF Security Audit Report – OSTIF.org

Our work with @sovereign.tech over the past two years resulted in 9 published audits with 6 more underway. OSTIF doesn't take lightly the responsibility we feel to help make a more resilient and secure open source ecosystem. Read more in our 2 year report: ostif.org/sovereigntec...

1 month ago 3 0 0 0
Advertisement
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

RSVP fornext week's OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure".

RSVPing adds the event to your calendar and lets us know you're coming!

luma.com/xc4yuezb

#OSTIF #OpenSource #disclosure

2 months ago 1 0 0 0
zlib Audit Complete! – OSTIF.org

Zlib is an open source lossless data-compression library for use on virtually any computer hardware and operating system.

Read about the audit process and results here 👉 ostif.org/zlib-audit-c...

2 months ago 0 0 0 0
Post image

The Open Source Technology Improvement Fund is proud to share the results of our security audit of zlib.

Thanks to the efforts of 7ASecurity and the Sovereign Tech Fund, this project underwent a holistic security review.

See 🧵 below 👇

#OSTIF #7ASecurity #audit #zlib

2 months ago 0 0 1 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

We look forward to the great conversations that happen when you can get passionate folks together to talk open source security!

Make sure to RSVP to add the event to your calendar and let us know you're coming: luma.com/xc4yuezb

2 months ago 0 0 0 0
Post image

Join us in 2 weeks on Wednesday, February 25th, for an OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure".

#OSTIF #OpenSource #disclosure

2 months ago 1 0 1 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

I'm giving a talk soon about my Cryspen findings, in collaboration with @ostifofficial.bsky.social. Happening online, will be live-streamed.

Register here: luma.com/xc4yuezb?tk=...

2 months ago 1 1 0 0
Post image

This month's Community Spotlight shines on Peter Hunt, Principal Software Engineer at Red Hat who has contributed to both of OSTIF's audits of CRI-O (cri-o.io). Come check out our interview!

ostif.org/feb-2026-com...

#OSTIF #Spotlight #RedHat

2 months ago 0 0 0 0
Video

🆓 🎉 It's Free Open Source Software Month! Learn open source skills for FREE!

From Linux fundamentals to Kubernetes, secure software, and emerging tech, check out Linux Foundation Education’s free learning library today: training.linuxfoundation.org/resources/

#OSS #CloudNative #Linux #Kubernetes

2 months ago 19 13 0 1

We couldn't have done it without: @sovereign.tech @cncf.io @lfenergy.bsky.social @aswf.io @quarkslab.bsky.social @shielder.com @trailofbits.bsky.social @openssf.org @opensource.org @puerco.mx @funnelfiasco.bsky.social @nadim.computer @adamshostack.bsky.social @openforumeurope.org and so many more!

2 months ago 5 1 0 0
2025 Annual Report – OSTIF.org

Presenting our 2025 annual report! In our report, you’ll see that OSTIF's story and mission are intertwined. OSTIF will continue to fight for open source infrastructure and the privacy rights of users for as many decades as you’ll let us.

Our statement and report link: ostif.org/2025-annual-...

2 months ago 3 2 0 1
Advertisement
Preview
The Sovereign Tech Fund invests in Scala

Congratulations to the Scala team for securing investment in open source infrastructure with the @sovereign.tech! We're proud to contribute to this effort, and look forward to the future of Scala and this endowment's positive impact: scala-lang.org/blog/2026/01...

2 months ago 1 1 0 0
Post image

@lfenergy.bsky.social EVerest underwent a security engagement facilitated by us with auditing by @quarkslab.bsky.social. This holistic security work impacts millions of EV charging stations worldwide. Read more at our blog:
ostif.org/everest-secu...

3 months ago 1 1 0 0
Post image

We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide.
The audit was mandated by @ostifofficial.bsky.social 🙏

blog.quarkslab.com/everest-secu...

3 months ago 2 2 0 0