OpenSSF Newsletter – August 2026
Cybersecurity Classified by Officially
The August 2026 OpenSSF Newsletter spotlights a wave of CRA readiness content, from a new Ericsson case study to a CRA podcast playlist. This issue also highlights new project announcements, releases, and working group updates. Learn more about securing agentic AI with OpenSSF at AGNTCon and MCPCon North America.
TL;DR:
- Join OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI → Two sessions and a booth focused on securing agentic AI.
- Case Study: Ericsson Conquers the CRA with 1,400 Upstream Fixes → How shifting to upstream collaboration eliminated private forks and met CRA obligations.
- CRA Readiness: A Practitioner’s Guide to Compliance → A pragmatic path forward as the September 2026 reporting deadline nears.
- Announcing BOMHort → Kubernetes-Native SBOM visualization and governance at scale
- Podcast: Four New Episodes → CRA deadlines with Dave Russo, community gardening the CRA with Roman Zhukov, practical CRA strategies with Megan Knight, and funding open source with AWS’s Mila Zhou.
- ENISA’s Single Reporting Platform guides updated ahead of the September 11 CRA reporting go-live.
5 min read
Happy 35th Birthday to Linux!
(Image created with Gemini using prompt: “Image of the OpenSSF mascot, Honk, celebrating Linux’s birthday with Linux’s mascot, Tux”)
From a “just a hobby, won’t be big and professional” Usenet post by Linus Torvalds on August 25, 1991, to the powerhouse driving world-class servers, supercomputers, cloud infrastructure, and billions of mobile devices today, the kernel’s journey is unmatched.
Want to hear how the kernel stays secure after 35 years? Listen to What’s in the SOSS? Podcast (#64) where CRob sits down with Linux kernel maintainer and legend Greg Kroah-Hartman to discuss how a weekend driver project turned into 25+ years of kernel maintenance, why upstream bug fixes are the ultimate security strategy, and how OpenSSF collaborates to protect open source maintainers amid global regulations like the EU’s Cyber Resilience Act (CRA).
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/newsletter/2026/08/31/openssf-newsletter-august-2026/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11629