What’s in the SOSS? Podcast #72 – S3E24 Balancing AI’s Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich
AI Cybersecurity Classified by Officially
Summary
In this episode of What’s in the SOSS?, host CRob sits down with Mark Russinovich – CTO and Deputy CISO of Azure, as well as Board Chair for the Open Source Security Foundation (OpenSSF) – for a wide-ranging conversation on the changing landscape of software security. Mark shares insights from his journey from Sysinternals to Azure leadership, exploring how generative AI is delivering dramatic productivity boosts while creating new talent pipeline challenges for early-in-career engineers. The discussion dives into the shift toward hardware-backed “what, not who” supply chain identity, the urgent rolling Y2K effort to fix AI-discovered vulnerabilities via initiatives like Akrites, and the reality of persistent AI hallucinations. Finally, Mark details OpenSSF’s strategic priorities for package registry sustainability and gives a sneak peek into his personal vibe-coded side projects like Polypost.
Listen on Apple PodcastsListen on SpotifyListen on OvercastListen on Pocket CastsConversation Highlights
00:00 – Introductions, Mark’s Sysinternals & Career Journey
02:34 – OpenSSF Board Leadership
04:25 – Corporate & Community Alignment
06:28 – AI’s Impact on Software Engineering
13:23 – Finding vs. Fixing Vulnerabilities
16:29 – LLM Code Quality & Edge Cases
22:51 – Navigating AI Hallucinations
26:56 – Supply Chain: Shifting “Who” to “What”
31:13 – Machine Unlearning & Model Safety
35:05 – Rapid Response & Akrites
41:16 – Package Registry Sustainability
46:07 – Personal Projects & Vibe-Coding
54:21 – Rapid Fire Round
Episode Links
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/podcast/2026/09/08/whats-in-the-soss-podcast-72-s3e24-balancing-ais-double-edged-sword-software-engineering-unlearning-and-ecosystem-sustainability-with-mark-russinovich/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11667