The Open Source Security Foundation (OpenSSF) this week announced that it has added four new members and that Microsoft and Google have pledged $5 million in funding for the Alpha-Omega project.
Founded in 2020 and hosted by the Linux Foundation, OpenSSF is a cross-industry organization focused on improving the security of the open source software supply chain through collaboration between tech companies.
OpenSSF founding members include GitHub, Google, IBM, Microsoft, NCC Group, OWASP Foundation, Intel, Okta, and VMware.
This week, the foundation announced that Hitachi, Lockheed Martin, Salesforce, and SAP have joined the effort as general members. In addition, veteran cybersecurity expert Omkhar Arasaratnam has become the organization’s new general manager and Brian Behlendorf is now the new OpenSSF chief technical officer (CTO).
OpenSSF also announced that Microsoft and Google have pledged $2.5 million each to fund the Alpha-Omega Project, an initiative aimed at improving open source software security by identifying and patching vulnerabilities in source code.
Launched in February 2022, Alpha-Omega bolsters collaboration between code maintainers and focuses on identifying critical open source software to strengthen through automated security analysis, scoring, and remediation guidance.
In December 2022, OpenSSF announced that Amazon Web Services (AWS) had agreed to fund Alpha-Omega with $2.5 million.
Related: OpenSSF Adopts Microsoft-Built Supply Chain Security Framework
Related: New OpenSSF Project Hunts for Malicious Packages in Open Source Repositories
Related: OpenSSF Bags $10 Million Investment

More from Ionut Arghire
- Toyota Discloses New Data Breach Involving Vehicle, Customer Information
- Adobe Inviting Researchers to Private Bug Bounty Program
- Critical Vulnerabilities Found in Faronics Education Software
- Chrome 114 Released With 18 Security Fixes
- Spyware Found in Google Play Apps With Over 420 Million Downloads
- Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability
- PyPI Enforcing 2FA for All Project Maintainers to Boost Security
- Personal Information of 9 Million Individuals Stolen in MCNA Ransomware Attack
Latest News
- Russia Blames US Intelligence for iOS Zero-Click Attacks
- Toyota Discloses New Data Breach Involving Vehicle, Customer Information
- Cisco Acquiring Armorblox for Predictive and Generative AI Technology
- Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks
- Amazon Settles Ring Customer Spying Complaint
- Organizations Warned of Salesforce ‘Ghost Sites’ Exposing Sensitive Information
- Adobe Inviting Researchers to Private Bug Bounty Program
- Critical Vulnerabilities Found in Faronics Education Software
