AI Is Exposing a Huge Problem With Open Source. Now What? | Josh Bressers | S2 E7

AI Is Exposing a Huge Problem With Open Source. Now What? | Josh Bressers | S2 E7

🎙 Eva Benn 👥 117K 📅 August 31, 2026 ⏱ 38 min 👁 4K 📄 expert opinion 🧭 2026-09-01
Available in: English (current) Français

Keywords

AI vulnerability discoveryLinus's Lawmaintainer burnoutCVE/NVDSBOM

Summary

In this episode of Security Mondays, host Eva Benn interviews Josh Bressers, VP of Security at Anchore, about the impending flood of AI-discovered vulnerabilities in open-source software. Bressers argues that Linus’s Law (‘given enough eyeballs, all bugs are shallow’) never truly held, and AI tools now act as those ’enough eyeballs,’ finding real vulnerabilities in nearly every project. The bottleneck shifts from discovery to disclosure and remediation, overwhelming already-burnt-out maintainers. He cites curl’s shutdown of its bug bounty due to AI-generated reports as a concrete example. Bressers advises security leaders to accept that open source is here to stay, focus on threat modeling and SBOMs to prioritize vulnerabilities in their specific context, and treat maintainer sustainability as a security risk. He also discusses the unreliability of CVE/NVD and suggests alternative databases. The conversation covers the potential for AI to automate parts of the vulnerability lifecycle, but Bressers remains uncertain about full automation due to the human element in open source. He concludes by emphasizing that open source is ‘free’ and that companies must take responsibility for the code they use, whether by hiring maintainers, donating, or using commercial support.

189 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for security practitioners, offering a clear-eyed view of the coming challenges and practical advice. Bressers’ argument is well-structured: he establishes the problem (AI finds bugs everywhere), identifies the real bottleneck (disclosure/remediation), and provides actionable strategies (threat modeling, SBOMs, alternative databases). He supports his claims with concrete examples like curl’s bug bounty shutdown and his own experience with fuzzing. The discussion is balanced, acknowledging uncertainties about the future and avoiding hype. The argumentation is solid, though it relies heavily on anecdotal evidence and expert opinion rather than quantitative data.

Scientific Rigor, Source Quality, Title Accuracy

The discussion is grounded in the guest’s extensive experience and references several linked resources, including essays by Bressers and a blog post by Daniel Stenberg about curl. The sources are relevant and credible within the open-source security community. The title accurately reflects the content, focusing on the problem AI exposes and the question of what to do next. The video is an expert interview, so the rigor is appropriate for that format, though it lacks formal citations or data. The description provides a comprehensive list of resources, which enhances the credibility of the claims made.

205 words

Title / Content Match

The title accurately reflects the core topic: AI's impact on open-source security and the resulting challenges.

Quality & Reliability

8/10

The discussion is grounded in the guest's extensive experience in open-source security and references concrete examples (curl bug bounty shutdown, NVD changes) and linked resources. However, it is primarily opinion-based with limited empirical data presented.

Key Moments

Cited Sources

Concurring Sources

Dissenting Sources

  • No discordant sources found — The video presents a consistent viewpoint without contradicting sources.

External References

Contribution & Novelties

The video provides a timely expert perspective on the intersection of AI and open-source security, articulating the shift from bug discovery to disclosure as the critical bottleneck. It offers practical advice for security leaders, such as using AI for threat modeling and prioritization, and highlights the human element of maintainer burnout as a security risk. The discussion of alternative vulnerability databases (GCVE, OSV, etc.) is particularly useful.

Pour aller plus loin :

111 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the depth of the discussion. The technical level is moderately high, suitable for a professional audience. The overall reliability is good, though the content is primarily opinion-based.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être dégagée.