Hack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

AIxCC Competition Background & Results:  In 2023, DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC) with the goal to safeguard open source software used in critical infrastructure throughout America. The intent is to hasten the development of open source AI tooling that can assist developers…

Continue ReadingHack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

DEfO Audit Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”). DEfO is an open source implementation of Encrypted Client Hello (ECH) for OpenSSL, and provides proof-of-concept implementations for various clients and servers that use OpenSSL as a demonstration…

Continue ReadingDEfO Audit Complete!

2025 Annual Report

2025 marked the 10th year of OSTIF. This year, we published 24 audits, worked on behalf of almost 50 projects, and partnered with 10 different funding bodies to create security outcomes for open source projects. As a result, 231 findings with security impact have been reported and over 98% of…

Continue Reading2025 Annual Report

The Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned

By Adam Korczynski and David Korczynski of Ada Logics In late 2024, Alpha-Omega partnered with Ada Logics and the Open Source Technology Improvement Fund (OSTIF) to audit 25 widely used open source projects in the AI and large language model (LLM) ecosystem. This initiative aimed at evaluating the overall security…

Continue ReadingThe Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned

OpenSSF Scorecard Audit is Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of OpenSSF Scorecard. OpenSSF Scorecard is an open source automated testing resource to help projects continually assess security risks. With the help of ADA Logics and the OpenSSF, this project can continue to provide…

Continue ReadingOpenSSF Scorecard Audit is Complete!

GNU libmicrohttpd2 Audit Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of GNU libmicrohttpd2. GNU libmicrohttpd2 is an open source library that “embeds a HTTP or HTTPS daemon into host applications.”* With the help of ADA Logics and the Sovereign Tech Agency, this project has…

Continue ReadingGNU libmicrohttpd2 Audit Complete!

Jan 2025 Community Spotlight: Introduction, David Korczynski and Adam Korczynski of Ada Logics

OSTIF would not be possible without our fantastic collaborators, partnerships, funders, and friends. Over the past 10 years, we’ve met so many amazing people, several of whom we have the utmost privilege of working with. It is deeply important to us that we give credit where credit is due. OSTIF…

Continue ReadingJan 2025 Community Spotlight: Introduction, David Korczynski and Adam Korczynski of Ada Logics

Express Audit Complete!

OSTIF is proud to share the results of our security audit of Express. Express is an open source web framework for Node.js that prioritizes performance and flexibility. With the help of the OpenJS Foundation and ADA Logics, this project can continue to thrive as a web application framework for users needing lightweight HTTP server tooling. Audit Process:…

Continue ReadingExpress Audit Complete!