Loading…
May 21, 2026 | Minneapolis, Minnesota, USA
Learn More and Register To Attend
Schedule is subject to change.

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day NA 2026. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.












Type: Keynote Sessions clear filter
Thursday, May 21
 

9:00am CDT

Welcome & Opening Remarks - Stacey Potter, Community Manager - OpenSSF, The Linux Foundation
Thursday May 21, 2026 9:00am - 9:10am CDT

Speakers
avatar for Stacey Potter

Stacey Potter

Community Manager, OpenSSF

Thursday May 21, 2026 9:00am - 9:10am CDT
101E

9:15am CDT

Keynote: Securing the Agentic Future: How OpenSSF is Leading the AI Security Transition - Steven Fernandez, OpenSSF Managing Director, The Linux Foundation
Thursday May 21, 2026 9:15am - 9:35am CDT
As AI becomes a bigger part of software and open source development, security needs are changing quickly. This talk will cover how the Open Source Security Foundation is ramping up the use of and support for AI security across the open source ecosystem.
Speakers
avatar for Steven Fernandez

Steven Fernandez

OpenSSF Managing Director, The Linux Foundation

Thursday May 21, 2026 9:15am - 9:35am CDT
101E

9:40am CDT

Keynote: Anatomy of a Phishing Campaign - Mike Fiedler, Python Software Foundation
Thursday May 21, 2026 9:40am - 10:00am CDT
In July 2025, PyPI users received emails directing them to another site - a near-perfect clone transparently proxying requests to pypi.org. Within hours, attackers compromised four accounts and uploaded malicious releases of the popular num2words package.

This talk dissects the complete attack chain: how attackers harvested email addresses from public package metadata, built a transparent proxy that relayed TOTP codes in real-time, and why traditional 2FA failed while WebAuthn-based authentication stopped the attack cold.

The session covers the incident response timeline, challenges getting malicious infrastructure taken down (including initial rejection of abuse reports), and defensive measures deployed afterward—including new email verification for TOTP logins from unrecognized devices.

Attendees will learn exactly how modern phishing attacks work against package repositories, the critical difference between "phishable" and "phishing-resistant" 2FA, and practical steps to protect accounts and packages from the next campaign. The talk also examines the September 2025 follow-up campaign targeting another domain and patterns across these ongoing attacks.
Speakers
avatar for Mike Fiedler

Mike Fiedler

PyPI Safety & Security Engineer, Python Software Foundation
Mike’s been in the engineering game for 30+ years, leading teams at Datadog, MongoDB, LeafLink, Warby Parker, and Capital One. He’s a big believer in learning from every peer and helping others navigate tech’s complexities. An AWS Hero and Awesome Community Chef, Mike loves... Read More →
Thursday May 21, 2026 9:40am - 10:00am CDT
101E

10:05am CDT

Keynote: BEAR-ing Fruit: A Year of Learning, Mentorship, and Community Building in Open Source Security - Marcela Melara, Research Scientist, Intel Corporation
Thursday May 21, 2026 10:05am - 10:20am CDT
The OpenSSF BEAR (Belonging, Empowerment, Allyship, and Representation) Working Group is on a mission to make cybersecurity a place where everyone belongs! We knock down barriers and crank up the volume for underrepresented voices. We've learned that true representation is about building fun, lasting paths for participation.

In this session, we'll take you on a journey through the evolution of BEAR, culminating in the exciting launch of our newest global family member, SIG OpenSSF Africa (Open Source Security Foundation Africa)! We'll share some insights and "Aha!" moments from our monthly Community Office Hours - including those unexpected successful strategies - and get honest about the triumphs and challenges of our mentorship program.

Looking to level up your community game? Whether you want to understand the real-world challenges facing diverse groups in security or just need some practical, battle-tested frameworks for building vibrant community programs, this session is your toolkit. Get ready for an open, fun look at building a truly inclusive open source security community!
Speakers
avatar for Marcela Melara

Marcela Melara

Research Scientist, Intel Corporation
Marcela Melara is a research scientist at Intel making distributed and cloud systems more trustworthy. Her current work focuses on developing solutions for high-integrity software and AI supply chains. She leads a number of internal, academic and open-source projects on supply chain... Read More →
Thursday May 21, 2026 10:05am - 10:20am CDT
101E

5:05pm CDT

Keynote: OSS-CRS: Next Generation Bug-Finding and Remediation for the LLM Era - Andrew Chin, Georgia Institute of Technology
Thursday May 21, 2026 5:05pm - 5:25pm CDT
The AI Cyber Challenge demonstrated that AI-powered Cyber Reasoning Systems (CRS) can autonomously find and fix software vulnerabilities at scale. But how do we take those advancements and make them accessible to the broader security community? Enter OSS-CRS: an open-source, standardized framework designed to accelerate the development of AI-assisted bug-finding and remediation systems. In this session, we'll walk through the design principles of OSS-CRS, show how it lowers the barriers to building and benchmarking next-generation CRS tooling, and demonstrate how users can easily deploy and run CRSs against their own codebases. Whether you're a security researcher, tooling developer, AI practitioner, or project maintainer, come learn about the growing ecosystem around AI-powered CRSs.
Speakers
avatar for Andrew Chin

Andrew Chin

Ph.D. Student, Georgia Institute of Technology
Andrew is part of Team Atlanta, the winning team in the AIxCC finals competition at DEF CON 33.

He is currently a Ph.D. student at the Georgia Institute of Technology, working with Prof. Taesoo Kim at the Systems Software & Security Lab. Building on the work from AIxCC, Andrew is leading a Team Atlanta effort — in partnership with the OpenSSF — to strengthen the security... Read More →
Thursday May 21, 2026 5:05pm - 5:25pm CDT
101E

5:25pm CDT

Closing Remarks
Thursday May 21, 2026 5:25pm - 5:30pm CDT

Thursday May 21, 2026 5:25pm - 5:30pm CDT
101E
 
  • Filter By Venue
  • Filter By Type
  • Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.