Vista elenco

Il furto delle opere di Antonello da Messina solleva un’altra domanda: lo Stato sa quante opere confiscate possiede?

17 Agosto 2026 ore 12:39

Il furto di quattro opere di Antonello da Messina dal Museo regionale della sua città, comprese tre delle cinque tavole superstiti del Polittico di San Gregorio, pone una domanda che va molto oltre la sicurezza dei musei: che cosa significa davvero proteggere e restituire alla collettività un patrimonio culturale?

Perché esiste un’altra enorme questione, assai meno spettacolare di un furto nella notte di Ferragosto: quella delle opere d’arte sequestrate e confiscate alla criminalità organizzata. Qui non servono proclami sulla legalità. Servono numeri. L’Agenzia nazionale per i beni sequestrati e confiscati, Anbsc, è diretta dal settembre 2024 dal prefetto Maria Rosaria Laganà. La delega politica sui beni confiscati al Ministero dell’Interno è della sottosegretaria Wanda Ferro. Dal maggio 2026 l’Ufficio nazionale beni mobili e immobili sequestrati e confiscati è diretto da Rossana Bellantoni.

A loro si potrebbero rivolgere alcune domande semplicissime. Quante opere d’arte confiscate definitivamente gestisce oggi lo Stato italiano? Dove sono? Quante sono esposte? Quante sono in deposito? Quante aspettano una destinazione? Da quanti anni? Qual è il loro valore complessivo? Provate a cercare le risposte. L’Anbsc pubblica relazioni, statistiche e dati sui beni confiscati. Ha costruito strumenti informatici e piattaforme per immobili e beni mobili registrati. Già dal 2021 esiste persino una “vetrina” telematica attraverso la quale vedere autoveicoli, motoveicoli, autocarri, macchine operatrici e altri mezzi confiscati.

Per un’automobile confiscata abbiamo dunque concepito una vetrina digitale. Per un Fontana, un De Chirico o un Warhol confiscato, il cittadino non dispone invece di un catalogo nazionale pubblico che permetta di ricostruire sistematicamente identificazione, provenienza, stato conservativo, luogo di custodia, destinazione e fruibilità.

L’Italia possiede il Comando Carabinieri Tutela Patrimonio Culturale e una delle più importanti banche dati mondiali delle opere illecitamente sottratte: oltre 1,3 milioni di file. Nel solo 2024 i Carabinieri TPC hanno recuperato 80.437 beni d’arte per un valore stimato di circa 130 milioni di euro. Sappiamo dunque costruire una formidabile macchina per cercare l’arte quando scompare. E c’è un paradosso ancora più evidente che emerge proprio dall’operazione della quale le istituzioni vanno più orgogliose: SalvArti. Dalle confische alle collezioni pubbliche.

Nel dicembre 2024 il Ministero dell’Interno annunciava trionfalmente l’esposizione a Palazzo Reale di Milano di oltre ottanta opere sottratte alla criminalità organizzata: De Chirico, Sironi, Fontana, Dalí, Warhol, Schifano, Rauschenberg.

La sottosegretaria Wanda Ferro parlò di opere “restituite alla collettività” e della necessità di rendere l’arte accessibile. Giustissimo. Ma quelle oltre ottanta opere provenivano da due sole procedure di confisca. E quindi, è precisamente questo successo a rendere gigantesca la domanda su tutto il resto. Dov’è il resto? Non si sostiene, ovviamente, che le opere siano scomparse. Si sta evidenziando, al contrario, qualcosa di amministrativamente più grave: il cittadino non dispone di uno strumento pubblico che gli consenta di misurare l’efficienza della loro restituzione.

È un problema di accountability. La direttrice Laganà ha dichiarato ancora nel dicembre 2025 che i beni confiscati rappresentano una risorsa fondamentale per le comunità. Nel marzo 2026 Anbsc e Legacoop hanno firmato un altro protocollo per la loro valorizzazione. Nel luglio 2026, alla presenza del ministro Matteo Piantedosi e della sottosegretaria Ferro, l’Agenzia ha sottoscritto un nuovo accordo con la Regione Piemonte per accelerarne destinazione e riutilizzo.

Protocolli, accordi, convegni, relazioni semestrali. Benissimo! Adesso, però, si chiede un Excel. Una riga per ogni opera d’arte definitivamente confiscata. Autore. Titolo. Procedimento. Data della confisca definitiva. Valore stimato. Luogo di custodia. Stato di conservazione. Data della destinazione. Ente destinatario. Fruibile: sì o no. Naturalmente oscurando le informazioni che possano compromettere sicurezza e indagini.

Non occorre una nuova legge, dunque. Occorre trasformare la gestione patrimoniale in una gestione misurabile. Perché esiste una differenza enorme fra confiscare un’opera e restituirla. La prima è un’attività giudiziaria. La seconda è un risultato amministrativo. E un risultato si misura. L’Anbsc dovrebbe quindi pubblicare ogni anno cinque numeri: opere prese in carico; opere catalogate; opere destinate; opere effettivamente esposte; tempo medio trascorso dalla confisca definitiva alla fruizione. E dovrebbe indicare il patrimonio ancora in attesa. Altrimenti la parola “restituzione” rischia di diventare una formula da inaugurazione.

Il furto di Messina dimostra quanto sia devastante perdere fisicamente un’opera d’arte. Ma c’è una seconda forma di sottrazione, meno cinematografica: possedere un patrimonio pubblico senza consentire al pubblico di sapere esattamente che cosa possiede, dove si trova e quando potrà vederlo. Per questo Piantedosi, Ferro e Laganà dovrebbero rispondere a una domanda che non è ideologica e non è di destra o di sinistra: quante opere d’arte confiscate possiede oggi lo Stato italiano e quante di esse possiamo vedere?

Se il numero esiste, lo pubblichino. Se non esiste, il problema è ancora più serio. Perché contro la mafia lo Stato non vince quando sequestra un quadro. Vince quando quel quadro smette di essere il trofeo privato di un criminale e diventa davvero patrimonio di tutti.

L'articolo Il furto delle opere di Antonello da Messina solleva un’altra domanda: lo Stato sa quante opere confiscate possiede? proviene da Il Fatto Quotidiano.

Oggi sono sedici anni dalla morte di Cossiga: perché per me è stato il peggior presidente della Repubblica

17 Agosto 2026 ore 07:53

Il 17 agosto sono trascorsi sedici anni dalla morte di Francesco Cossiga, tra i peggiori politici e certamente il peggior Presidente della Repubblica italiana.

Giovanissimo deputato democristiano, quindi ministro dell’Interno con Moro e poi con Andreotti, passando per la presidenza del Consiglio e fino al Quirinale, quella del “picconatore” è la metafora della storia stessa dell’Italia del secondo dopoguerra. Come ricordò Nando dalla Chiesa all’indomani della sua morte (Lo statista. Promemoria su un presidente eversivo, Melampo 2011), “di segreti Cossiga ne ha conservati tanti e falsi segreti li ha alimentati con le sue interviste”. Basti pensare alla fantomatica (e depistante) pista palestinese per la strage piduista alla stazione di Bologna.

Uno dei pochi giornalisti viventi che ha ben descritto il ruolo di depistatore di Stato di Cossiga è Gianni Barbacetto: “il non detto del passato, con i suoi segreti impronunciabili e i suoi ricatti, resterà a fare da trama al futuro e le vecchie ferite resteranno cicatrici nascoste, focolai di nuove infezioni.”

Chi però, più di chiunque altro, ha documentato il carattere eversivo dell’ex capo di stato sardo è Sergio Flamigni, l’ex senatore berlingueriano scomparso a 100 anni lo scorso 10 dicembre. Ecco un estratto dal suo documentatissimo libro I fantasmi del passato (edizioni Kaos 2001): Il 6 gennaio 1980 la mafia [non solo la mafia, nda] uccise a Palermo il presidente della Regione Sicilia, il Dc Piersanti Mattarella. Convinto sostenitore della politica morotea, Mattarella era impegnato a costituire una giunta con il Pci. Tra il 15 e il 19 febbraio 1980 il XIV Congresso nazionale della Dc, svoltosi a Roma, sconfessò ufficialmente la linea politica di Moro, liquidò la segreteria Zaccagnini, e con una maggioranza (58%) formata da Flaminio Piccoli (eletto nuovo segretario), Antonio Bisaglia, Carlo Donat Cattin, Gianni Prandini, Amintore Fanfani e Arnaldo Forlani (eletto presidente del partito) approvò il “preambolo”, cioè il rifiuto da parte della Dc di ogni “corresponsabilità di gestione” con il Pci.

L’estensore del “preambolo” anticomunista, e vero uomo forte della coalizione congressuale vittoriosa, era il senatore Carlo Donat Cattin, che infatti venne nominato vicesegretario del partito. Tutti i 19 parlamentari della Dc segretamente iscritti alla P2 votarono il “preambolo”, e del resto lo stesso segretario particolare di Donat Cattin, Ilio Giasolli, era affiliato alla Loggia massonica gelliana.

Anche nel primo governo Cossiga, al momento in carica, la P2 era ben rappresentata, con due ministri (i Dc Gaetano Stammati e Adolfo Sarti), tre sottosegretari (il Pli Antonio Baslini, il Psdi Costantino Belluscio, il Dc Rolando Picchioni), e lo stesso presidente del Consiglio era in buoni rapporti col capo della P2 Licio Gelli. Infiltrata nella Dc, nel Psi, in tutti i partiti laici minori, e perfino nel Msi, la Loggia segreta stava svolgendo un intenso lavorìo occulto per pilotare il quadro politico verso i dettami del “Piano di rinascita democratica”. Così, dopo la restaurazione della Dc, la P2 si attivò per consolidare nel Partito socialista la leadership “anticomunista” di Bettino Craxi, e per portare il Psi nel governo Cossiga. (…)

Il 5 agosto 1990 un servizio del settimanale L’Espresso raccontò quelli che erano stati i rapporti di Cossiga con il capo della P2 Licio Gelli, rapporti che erano già emersi nel corso dei lavori della Commissione parlamentare d’inchiesta sulla Loggia massonica segreta. (…) il settimanale ricordava le parole di Federico Umberto D’Amato, dirigente delle polizie speciali del Viminale e affiliato alla P2 [uno dei mandanti della strage alla stazione di Bologna, nda], a proposito di una presunta telefonata Cossiga-Gelli: “D’Amato stava da Gelli – in uno dei sei incontri che ha avuto – e sentì il maestro venerabile rispondere al telefono con una persona che chiamava “presidente”. Finita la telefonata Gelli disse a D’Amato: ‘Ho parlato con il principale candidato alla presidenza del Consiglio, l’onorevole Cossiga. Mi ha detto ‘Se tu mi appoggi, io accetto!’. Credo proprio che lo farò’.

L’Espresso riportava poi la testimonianza del massone Francesco Pazienza, il quale aveva dichiarato che un giorno – presente nell’ufficio di Cossiga insieme a Luigi Zanda (collaboratore cossighiano, ex senatore del Pd) e a Michael Ledeen, professore legato all’entourage di Kissinger e ai servizi segreti americani (in “rapporti cordiali con l’on. Cossiga da darsi del tu”) – aveva avuto modo di assistere a “una telefonata giunta a Cossiga durante la nostra presenza e che durò circa 15 minuti, egli fu particolarmente affettuoso con un interlocutore che continuava a chiamare Licino. Venni poi a sapere da D’Amato che il Licino era in effetti il Licio nazionale”.

Piccole soddisfazioni. All’inizio del nuovo millennio Cossiga fu condannato a risarcire Sergio Flamigni: da presidente della Repubblica, lo aveva definito pubblicamente “un poveretto”.

Prima o poi qualche storico dovrebbe tentare di rispondere a una domanda: perché il Pci (orfano di Berlinguer) nel 1985 accettò di contribuire ad eleggere Cossiga al Quirinale?

L'articolo Oggi sono sedici anni dalla morte di Cossiga: perché per me è stato il peggior presidente della Repubblica proviene da Il Fatto Quotidiano.

Oltre i cliché del Settantasette e dell’estremismo: i due volumi di Franculli e Fantini

17 Agosto 2026 ore 07:51

Il 1977 e gli anni complessi della lotta armata continuano a generare narrazioni saggistiche e letterarie. Molte di queste opere restano tuttavia ripetitive, bloccate entro schemi ideologici rigidi o limitate a memorie difensive prodotte dai singoli protagonisti.

L’editore DeriveApprodi pubblica ora due libri che scelgono di deviare da questa abitudine consolidata. Si tratta di due volumi originali ed efficaci, capaci di affrontare la storia politica italiana recente attraverso prospettive poco esplorate e lontane dalle convenzioni della solita memorialistica. Entrambi i testi offrono un quadro privo di retorica su stagioni complesse della Repubblica.

Il primo libro è Appuntamento al San Callisto. Viaggio nei sogni del ’77 romano firmato da Canio Franculli. Il volume si impone per una precisa scelta di campo: descrive il movimento direttamente dal suo interno, evitando qualunque lettura ortodossa o dogmatica dei fatti. Franculli adotta un registro rigorosamente umano e asciutto, raccontando la vicenda di un giovane provinciale che arriva nella capitale negli anni Settanta.

Il testo rifiuta le consuete celebrazioni ideologiche, così come evita qualsiasi forma di compiacimento nostalgico sul valore dei militanti dell’epoca. Al contempo, la narrazione esclude ogni tipo di atteggiamento vittimistico. Franculli ricostruisce il quotidiano di chi partecipava alle lotte politiche attraverso i fatti reali, le contraddizioni interne, la ricerca artistica, i luoghi di ritrovo urbani, i cortei e gli scontri di piazza.

La prospettiva mantenuta dall’autore è strettamente personale e concreta. Non si nota la pretesa di formulare un giudizio politico globale sul decennio, bensì l’intento di registrare le modalità con cui i singoli individui vivevano la collettività. Si tratta di un’opera di ricostruzione che rifiuta tanto la criminalizzazione a priori quanto la beatificazione retrospettiva, mettendo al centro le scelte individuali, la disillusione e le relazioni umane reali formatesi tra i giovani romani di quegli anni.

Il secondo volume è Storia di Roby il pazzo. La parabola di Sandalo nella lotta armata scritto da Gabriele Fantini. La biografia tratta la figura di Roberto Sandalo, militante in Lotta Continua e Prima Linea, poi collaboratore di giustizia, arrivato nei decenni successivi ad avvicinarsi alla Lega Nord e a compiere attacchi contro strutture della comunità islamica.

Sul piano strettamente politico, Sandalo rimane una figura poco interessante, sprovvista di uno spessore teorico o di una visione strategica significativa. Nel lavoro di Fantini si nota inoltre qualche giustificazione di troppo riservata al protagonista. Nonostante questo limite analitico, il testo rappresenta un lavoro documentaristico eccezionale. Il valore principale dell’autore consiste nell’aver esaminato e incrociato una grande mole di documenti d’archivio e di testimonianze dirette per ricostruire un itinerario personale che altrimenti verrebbe archiviato come semplice stravaganza individuale.

Il libro consente di analizzare un fenomeno inedito e poco indagato: la conversione verso la Lega Nord e la successiva partecipazione agli assalti contro le moschee da parte di un ex terrorista di sinistra. Fantini registra questi passaggi senza cedere al sensazionalismo, dimostrando come una specifica attitudine al radicalismo possa mutare la propria appartenenza politica mantenendo inalterate le forme della violenza illegale.

Sia il lavoro narrativo di Franculli sia la ricerca biografica di Fantini forniscono un contributo solido per la comprensione fattuale dell’Italia degli anni Settanta e delle sue dirette conseguenze nei decenni seguenti. Franculli analizza la dimensione vissuta e umana del movimento al di fuori delle rigide direttive di partito. Fantini raccoglie dati, verbali giudiziari e fatti storici indispensabili per valutare le successive trasformazioni dell’estremismo. Si tratta di due testi originali che rifiutano categoricamente le valutazioni sbrigative e arricchiscono il dibattito storiografico corrente con elementi certi e incontestabili di analisi reale.

L'articolo Oltre i cliché del Settantasette e dell’estremismo: i due volumi di Franculli e Fantini proviene da Il Fatto Quotidiano.

La richiesta all’Ue di scostamento di bilancio per 36 miliardi è una scelta da buon padre di famiglia?

17 Agosto 2026 ore 07:42

di Carmelo Pennisi

Mi è sempre stata cara un’espressione dalla forte carica evocativa usata nel Codice Civile: la diligenza del buon padre di famiglia. Una linea di condotta prescritta dal Codice a qualunque cittadino nell’adempimento di un’obbligazione e in particolare al mandatario nell’esecuzione del mandato ma che dovrebbe valere tanto più per chi ricopre funzioni pubbliche.

Ciononostante, nell’agire di questo Governo si fa fatica a riscontrare sia la diligenza sia l’emulazione del buon padre di famiglia e mi riferisco, in particolare, alla scelta dell’Esecutivo di chiedere all’Ue l’attivazione della clausola di salvaguardia nazionale al fine di consentire uno scostamento di bilancio di circa 36 miliardi di euro.

Cioè, siccome il bilancio italiano presenta attualmente un deficit superiore al 3% del Pil, motivo per cui è in corso una procedura d’infrazione che non consente di aumentare le spese, si chiede all’Ue un’autorizzazione “eccezionale” a spendere quest’anno e nei prossimi due 14 miliardi per la transizione energetica e 22 miliardi per la difesa.

Eppure i problemi veri e gravi del Paese sarebbero altri: i salari e gli stipendi reali sempre più bassi, con impoverimento di lavoratori dipendenti e pensionati (un docente di scuola media superiore tra il 1990 e il 2026 ha visto ridursi il potere d’acquisto del suo stipendio del 29,7%); i prezzi dei carburanti e dell’energia a livelli record e sui quali nessun impatto nel breve e medio periodo avrebbero gli eventuali fondi per la transizione energetica (Nomisma stima rincari annuali delle bollette del 54% per le imprese e del 23% per le famiglie che, pertanto, dovranno sopportare un aggravio medio di 1.000 euro su base annuale); i bassissimi livelli di crescita del Pil (+0,5% nel 2025 nonostante le iniezioni dei fondi Pnrr che solo in quell’anno sono stati di 31,1 miliardi di euro); il Sistema Sanitario Nazionale, questo sì, in disarmo (nel 2024 le famiglie hanno dovuto sostenere direttamente il 22% delle spese per le cure e sono in aumento gli italiani che hanno rinunciato ad almeno una prestazione sanitaria). Ma la lista è molto più lunga.

Un solo dato a riprova delle difficoltà: per abbassare per pochi giorni le accise e, quindi, il prezzo del gasolio di appena 17 centesimi è stato necessario tagliare 245 milioni alle spese dei ministeri.

Di fronte a tutto ciò il Ministro Giorgetti, nel motivare la richiesta di scostamento, si è riconosciuto il coraggio di fare scelte impopolari e ha rivendicato la coerenza rispetto al suo senso del dovere e al giuramento prestato sulla Costituzione con riferimento al dovere di difesa della Patria (art. 52 Cost.).

Per chiarezza e completezza avrebbe dovuto anche dire da chi e da che cosa difendere la Patria. Ma è un particolare che non è dato sapere neanche leggendo le Faq sul “ReArm Europe Plan/Readiness 2030” disponibili sul sito della Commissione Europea ma solo in inglese, tedesco e francese, giusto per invogliare l’italiano medio a leggerle.

Se il non detto alluderebbe ad una presunta minaccia russa può essere rassicurante la dichiarazione “Russia is not looking for conflict” del generale americano Grynkewich: un giudizio probabilmente condiviso dalla maggioranza degli italiani o perlomeno da quelli che conoscono un po’ di storia (intese Gorbaciov-Nato, fatti di Maidan, accordi di Minsk, ecc.).

Nell’attuale contesto, far indebitare lo Stato italiano di ulteriori 22 miliardi di euro (Safe o titoli del debito pubblico è una questione poco rilevante) per spese militari non è una scelta coraggiosa ma semplicemente assurda. E pare quanto meno fuori luogo invocare l’art. 52 della Costituzione in mancanza di un reale, attuale e concreto pericolo per la Patria; piuttosto si applichi l’art. 11 della Costituzione, non solo come mera enunciazione di un principio ma come divieto cogente di porre in essere azioni che anziché scoraggiare i conflitti armati ne possano essere pericolose incubatrici. E su questo il buon padre di famiglia non avrebbe avuto alcun dubbio.

Il blog Sostenitore ospita i post scritti dai lettori che hanno deciso di contribuire alla crescita de ilfattoquotidiano.it, sottoscrivendo l’offerta Sostenitore e diventando così parte attiva della nostra community. Tra i post inviati, Peter Gomez e la redazione selezioneranno e pubblicheranno quelli più interessanti. Questo blog nasce da un’idea dei lettori, continuate a renderlo il vostro spazio. Diventare Sostenitore significa anche metterci la faccia, la firma o l’impegno: aderisci alle nostre campagne, pensate perché tu abbia un ruolo attivo! Se vuoi partecipare, al prezzo di “un cappuccino alla settimana” potrai anche seguire in diretta streaming la riunione di redazione del giovedì – mandandoci in tempo reale suggerimenti, notizie e idee – e accedere al Forum riservato dove discutere e interagire con la redazione.

L'articolo La richiesta all’Ue di scostamento di bilancio per 36 miliardi è una scelta da buon padre di famiglia? proviene da Il Fatto Quotidiano.

Così gli Angels of Love di Napoli conquistano il festival house più grande del mondo

17 Agosto 2026 ore 07:13

Per la prima volta nei suoi 36 anni di vita, gli organizzatori del Chosen Few DJs Picnic & Music Festival – l’evento di musica house più importante e blasonato del pianeta – hanno deciso di spalancare le porte a un collettivo europeo, puntando dritto sul Sud.

È toccato agli Angels of Love, storico gruppo originato a Napoli di dj e producers, rappresentare ben 27 Stati dell’Unione Europea nel più grande circuito del clubbing mondiale, traghettando la storia della house italiana ad un festival che ha coinvolto, nella giornata clou, oltre 60.000 partecipanti provenienti da tutto il mondo. Guidati da Alex Serafini con il supporto del fondatore storico di Angels of Love, Maurizio Luise, e con la partecipazione del dj campano dAPULEO, agli Angels è toccato il compito di rappresentare l’Europa su un palcoscenico di caratura mondiale.

Il festival americano ha visto in cartellone leggende assolute del genere: da Alan King (figura legale e amico di Barack Obama, di cui ha sostenuto attivamente la campagna presidenziale) al candidato ai Grammy Award Terry Hunter; da Mike Dunn, pilastro della musica house di Chicago da quasi trent’anni, a Wayne Williams, produttore di hit per superstar mondiali come Aretha Franklin e Justin Timberlake.

Il cast è proseguito con il dj Jazzy Jeff, noto al grande pubblico anche come co-protagonista della serie Willy, il principe di Bel-Air; la storica cantante Christine Wiltshire, voce di successi planetari come “Keep on Jumping” e “Weekend”; Kenny Dope, quattro volte candidato ai Grammy Award; e la celebre Kym Mazelle, voce iconica della colonna sonora del film cult Romeo + Giulietta. E poi ci sono loro, Maurizio Luise e dAPULEO, che nel silenzio mediatico italiano sono stati i primi europei ad essere consacrati nel palcoscenico house più importante degli ultimi 40 anni, un successo che ha portato il collettivo nato a Napoli (ora leader di mercato in Italia) sul tetto del mondo.

Dopo 36 anni di storia, dunque, il collettivo meridionale, che conta una community di oltre 250mila partecipanti, ha così esportato l’house italiana nel festival più importante degli ultimi quarant’anni. Questo traguardo arriva poco dopo il riconoscimento ricevuto in Parlamento dall’intergruppo “Sviluppo Sud” (guidato dal Presidente on. Alessandro Caramiello e composto da 50 parlamentari) che ha premiato gli Angels of Love come “eccellenza meridionale”.

L'articolo Così gli Angels of Love di Napoli conquistano il festival house più grande del mondo proviene da Il Fatto Quotidiano.

L’attacco israeliano contro la giornalista libanese Amal Khalil, minuto per minuto

17 Agosto 2026 ore 06:51

Il 22 aprile 2026, nel sud del Libano, un attacco israeliano ha ucciso la giornalista del quotidiano Al Akhbar Amal Khalil e ferito gravemente l’operatrice di ripresa Zeinab Faraj.

Per Amnesty International è stato un crimine di guerra: a confermarlo è stata la ricostruzione dell’accaduto, basata sulle testimonianze dell’unica sopravvissuta e delle prime persone intervenute sul posto, su materiale audiovisivo e sulle comunicazioni tra i vari soggetti coinvolti nei mancati soccorsi.

Le due giornaliste hanno cercato riparo dopo che un attacco aereo israeliano contro l’automobile che le precedeva aveva ucciso due uomini. Nelle due ore successive, mentre alcuni droni sorvolavano la zona a distanza ravvicinata, altri due attacchi aerei hanno colpito prima la loro automobile, parcheggiata nelle vicinanze, e poi l’edificio in cui si erano rifugiate.

Dopo che il primo attacco aveva eliminato l’obiettivo dichiarato dalle forze armate israeliane e mentre due droni stavano sorvolando la zona a bassa quota, queste ultime sapevano, o avrebbero dovuto sapere, che due civili si erano rifugiate in quell’edificio.

L’attacco è avvenuto nel villaggio di al-Tiri, situato a circa sette chilometri dal confine israeliano, nel distretto di Bint Jbeil, nel sud del Libano. Il villaggio rientrava nella zona di “difesa avanzata”, il sei per cento del territorio libanese. Le forze armate israeliane presenti in questa zona avevano vietato il ritorno (il che non le esonerava dal rispetto degli obblighi del diritto internazionale umanitario) alle persone residenti e compiuto vaste distruzioni.

Amal Khalil e Zeinab Faraj stavano seguendo un veicolo a bordo del quale si trovavano Ali Nabil Bazzi, mukhtar di Bint Jbeil, un ruolo assimilabile a quello di un sindaco locale, e il suo amico Mohammed Hourani, residente sfollato, che volevano a loro volta verificare direttamente se le forze israeliane si fossero davvero ritirate da al-Tiri.

Intorno alle 14.25, subito dopo l’ingresso nel villaggio, le forze israeliane hanno centrato il veicolo con a bordo Ali Nabil Bazzi e Mohammed Hourani.

Zeinab Faraj ha raccontato ad Amnesty International che, al momento dell’attacco, lei e Amal Khalil si trovavano dietro, a bordo dell’automobile di Amal. Ha riferito di aver visto il veicolo davanti a loro esplodere, proiettando i due uomini fuori dall’abitacolo e prendendo fuoco.

Alle 14.36 Amal Khalil ha telefonato al soccorritore della Protezione civile libanese Moussa Chaalan per segnalare l’attacco. Questi ha subito contattato i colleghi della Protezione civile, la Croce rossa libanese e l’esercito libanese. La Croce rossa libanese ha così ricevuto la prima richiesta di un’ambulanza alle 14.38.

Mentre era in procinto di dirigersi sul posto, Moussa Chaalan ha ricevuto l’ordine di fermarsi a un posto di blocco dell’esercito libanese all’ingresso di al-Tiri. Infatti, l’autorizzazione ad accedere ai villaggi situati nella cosiddetta zona di “difesa avanzata” veniva coordinata dal Comitato tecnico militare per il Libano, comunemente indicato come Meccanismo di attuazione e monitoraggio del cessate il fuoco.

Mentre i droni israeliani continuavano a sorvolare la zona, le due giornaliste sono scese dall’automobile e hanno cercato riparo accanto a un muretto, vicino a un edificio abbandonato del villaggio, poi sotto la tettoia di lamiera danneggiata di un negozio situato al piano terra dell’edificio.

Alle 15.31 Moussa Chaalan, ancora fermo al posto di blocco, ha telefonato ad Amal Khalil esortandola a risalire in automobile e ad allontanarsi dalla zona. Non aveva infatti ancora ricevuto dal Meccanismo di monitoraggio l’autorizzazione a entrare nel villaggio e, di conseguenza, non disponeva di alcuna garanzia che l’esercito israeliano non avrebbe effettuato altri attacchi.

Intorno alle 15.40 un secondo attacco ha colpito l’automobile delle giornaliste, ferma nei pressi del luogo in cui si erano rifugiate.

Alle 15.48 Amal Khalil ha richiamato Moussa Chaalan per comunicargli di essere rimasta ferita: “Non riesco a fare nulla. Moussa, vieni a prendermi”.

Entrambe le donne sono rimaste ferite nell’esplosione. Una portiera dell’automobile è stata scagliata verso di loro e Zeinab Faraj l’ha usata per proteggere sé e la collega dalle fiamme. Ha raccontato: “Vetri e detriti sono volati verso di noi. Ho avuto la sensazione che mi fosse scoppiato un orecchio. Lei [Amal Khalil] perdeva molto sangue dal naso e dalla testa e aveva ferite da schegge al braccio e alla coscia; non riusciva a muovere la gamba”.

Con l’intensificarsi dell’incendio, le due donne sono riuscite a strisciare all’interno dell’edificio, passando attraverso una saracinesca danneggiata, e si sono nascoste in una piccola stanza. Una volta all’interno, Amal Khalil ha continuato a telefonare per chiedere soccorso. Zeinab Faraj ha riferito ad Amnesty International che tutte le persone contattate avevano detto di non poter raggiungere il luogo in cui si trovavano perché erano “in attesa dell’autorizzazione” del Meccanismo di monitoraggio, in pratica il consenso delle forze armate israeliane a sospendere il fuoco per consentire l’ingresso delle squadre di soccorso.

Moussa Chaalan ha raccontato ad Amnesty International: “Ho detto all’ufficiale dell’esercito al posto di blocco che sarei entrato, nonostante il rischio. Ma mi ha convinto a non farlo dicendomi: ‘E se venissi colpito prima di riuscire a raggiungerla? È meglio aspettare l’autorizzazione, per il suo bene e per il tuo’”.

Alla fine, Amal Khalil si è molto indebolita. Zeinab Faraj ha raccontato: “L’ho vista via via senza forze […] e poi ha perso conoscenza”.

L’ultima telefonata di Amal Khalil è stata alla sorella, alle 16.22.

Intorno alle 16.25 un terzo attacco ha colpito l’edificio in cui le giornaliste si erano rifugiate, provocandone il crollo e seppellendo entrambe sotto le macerie.

Poco dopo le 17 è stata concessa l’autorizzazione a entrare nella zona, ma soltanto alla Croce rossa libanese. I soccorritori hanno estratto Zeinab Faraj, che aveva riportato una frattura cranica, gravi ferite alla gamba destra e a un occhio e lo schiacciamento di una mano. Non sono invece riusciti a raggiungere Amal Khalil, che risultava ancora dispersa sotto le macerie.

Poco prima delle 18, le persone volontarie della Croce rossa libanese arrivate sul posto hanno riferito di essere state costrette a ritirarsi a causa della minaccia di ulteriori attacchi, portando via Zeinab Faraj e i corpi dei due uomini uccisi nel primo attacco.

Dopo un’ulteriore serie di telefonate da parte di organismi internazionali e delle autorità libanesi, compresi l’ufficio del presidente e quello del primo ministro, alle 19.20 è stata nuovamente concessa l’autorizzazione. Ciò ha consentito ai soccorritori della Croce rossa, a un’ambulanza e a un piccolo bulldozer di tornare sul luogo dell’attacco. Per rimuovere le macerie dei tre piani crollati erano tuttavia necessari mezzi più pesanti. Le operazioni di recupero, effettuate con un escavatore, sono iniziate intorno alle 21.

Moussa Chaalan ha raccontato che Amal Khalil è stata trovata sepolta sotto una colonna e un muro: “Era completamente schiacciata […] L’ho estratta con le mie mani”.

Nel certificato di morte, il medico legale ha indicato come ora del decesso le 19 e come causa “un arresto cardiaco dovuto a un trauma cranico e a una grave emorragia”.

L'articolo L’attacco israeliano contro la giornalista libanese Amal Khalil, minuto per minuto proviene da Il Fatto Quotidiano.

Perché i decreti meloniani hanno smantellato la legge per gli anziani non autosufficienti

17 Agosto 2026 ore 06:40

di Enza Plotino

Gli anziani siamo noi! Ci dirigiamo a gambe levate verso un invecchiamento della popolazione ed un aumento vertiginoso di quella non autosufficiente per la quale la Riforma n.33 del 2023, che era stata presentata dal governo Draghi e che andava incontro alle esigenze degli anziani non autosufficienti e alle loro famiglie, rappresentava un atto importante atteso da 30 anni per eliminare le debolezze e le mancanze del welfare attuale. Purtroppo la riforma è finita nelle mani del governo Meloni, e quella che poteva essere un vero passo avanti per 10 milioni di persone, anziani, famigliari e caregiver di professione per i quali la legge introdotta grazie al Pnrr puntava a ridisegnare il sistema di welfare per rispondere alla loro sempre più diffusa presenza e a bisogni di cura sempre più complessi e che voleva colmare la mancanza in Italia di un servizio domiciliare pubblico progettato per la non autosufficienza, è precipitata nell’obbrobrio attuativo (Decreti attuativi del 2023) approvato dal governo Meloni, in palese contraddizione con le indicazioni della Delega.

Perché ne parlo oggi? Perché si iniziano a vederne gli effetti. Milioni di anziani, soprattutto non autosufficienti, con le loro famiglie, lasciati senza risorse, senza assistenza qualificata, senza servizi domiciliari anziché in strutture residenziali, senza prevenzione e, per peggiorare questo quadro già drammatico, smantellando il principio cardine del nostro welfare, quello della protezione universale, prevedendo, per ricevere assistenza, di dover dimostrare ridotte disponibilità economiche. Ciliegina sulla torta, le Regioni tagliate completamente fuori dai decreti. In nessun passaggio, sebbene l’assistenza agli anziani venga realizzata a livello territoriale, quindi sancendo alte possibilità di fallimento nella fase di attuazione degli interventi.

Tutte le migliori intenzioni contenute nella riforma si si sono arenate, bloccandosi definitivamente, nelle leggi attuative promosse da Meloni. All’intento di rimettere al centro le persone, la destra ha risposto con approssimazione, ideologia a favore dei ricchi, di coloro che possono e con bieca propaganda assistenziale.

La riforma aveva l’intento di superare la frammentazione delle misure e dei servizi, dare risposte diverse ai diversi bisogni, puntare a percorsi di assistenza semplici ed unitari, riportare la tutela pubblica della non autosufficienza. I decreti meloniani non prevedono risorse per rendere concrete le indicazioni normative, cancellano l’accesso universalistico ai servizi, dimenticano l’assistenza domiciliare integrata, peraltro in coerenza con l’impostazione generale del governo in materia di welfare: destrutturazione dei servizi di territorio, abbandono delle politiche di prevenzione e prossimità. Un disastro che 10 milioni di persone pagheranno sulla propria pelle.

E’ urgente, in un programma del centrosinistra che si rispetti, l’impegno a ritornare allo spirito e ai principi universalistici e solidaristici della Riforma, smantellando l’obbrobrio della destra e ripristinando l’approccio giusto ad una problematica drammaticamente attuale per milioni di famiglie.

Il blog Sostenitore ospita i post scritti dai lettori che hanno deciso di contribuire alla crescita de ilfattoquotidiano.it, sottoscrivendo l’offerta Sostenitore e diventando così parte attiva della nostra community. Tra i post inviati, Peter Gomez e la redazione selezioneranno e pubblicheranno quelli più interessanti. Questo blog nasce da un’idea dei lettori, continuate a renderlo il vostro spazio. Diventare Sostenitore significa anche metterci la faccia, la firma o l’impegno: aderisci alle nostre campagne, pensate perché tu abbia un ruolo attivo! Se vuoi partecipare, al prezzo di “un cappuccino alla settimana” potrai anche seguire in diretta streaming la riunione di redazione del giovedì – mandandoci in tempo reale suggerimenti, notizie e idee – e accedere al Forum riservato dove discutere e interagire con la redazione.

L'articolo Perché i decreti meloniani hanno smantellato la legge per gli anziani non autosufficienti proviene da Il Fatto Quotidiano.

Chi era Marianne Weber, madre negletta della sociologia

Riletto oggi, "La Donna e la Cultura" non perde nulla in termini di attualità. Sostiene l’opportunità di una revisione fondativa del canone sociologico, che vada oltre l’incorporazione delle pensatrici di fine '800 come tessere di un mosaico che nei contenuti principali resta inalterato

L'Africa di fronte a un grande test democratico

Il continente africano si prepara a numerose consultazioni elettorali, regolari o anticipate, tra cui nove elezioni presidenziali. Il futuro della democrazia dipenderà da due condizioni

Per Eglantyne Jebb e tutte le donne che sono scese in piazza nell'ultimo secolo

Ai primi del Novecento, la fondatrice di Save the Children ha reclamato uno spazio di azione pubblica, rivoluzionando il concetto di “prendersi cura” dell’infanzia. Non più atto caritatevole, ma investimento per creare società giuste, democratiche e sostenibili

Oltre 230 milioni di donne hanno subito mutilazioni genitali

Nella Giornata internazionale della Donna voglio ricordare che questa pratica causa gravi complicanze e persino la morte. I rischi più diretti sono emorragie, shock settico, infezioni, ritenzione urinaria e forte dolore

Primavera alle Bahamas tra cibo, vini pregiati e immersioni a colori

Oltre 700 isole e isolotti e 16 destinazioni insulari che nascondono baie e tradizioni meravigliose, eventi culturali spettacolari e antiche storie che rendono questa meta turistica un vero tesoro da scoprire

"Stasera sono in vena". Ovvero splendere di solitudine dentro la notte dell'Italia

Oscar De Summa riporta in forma di teatro-concerto il monologo di racconto dell’altra Italia degli anni ’80, quella che nel vuoto della provincia trovò solo l’eroina

L’importanza della prevenzione nelle malattie cardiovascolari

A giocare un ruolo fondamentale sono tutti quei fattori su cui è possibile intervenire. Un corretto stile di vita, un’alimentazione sana, un’adeguata attività fisica sono tutti insegnamenti che ci vengono dati sin dalla nascita, ma che possono davvero far la differenza e ridurre il rischio cardiovascolare

Insegnare alle donne come uscirne

Un rapporto Osce indica che il divario fra ruoli maschili e femminili nella criminalità organizzata è relativamente ridotto. E sorprendentemente le donne sono assenti dai programmi statali di protezione dei testimoni. Anche lì, non vengono offerte le stesse opportunità degli uomini

Welcoming PyTorch to the Linux Foundation

12 Settembre 2022 ore 15:25

Today we are more than thrilled to welcome PyTorch to the Linux Foundation. Honestly, it’s hard to capture how big a deal this is for us in a single post but I’ll try. 

TL;DR — PyTorch is one of the most important and successful machine learning software projects in the world today. We are excited to work with the project maintainers, contributors and community to transition PyTorch to a neutral home where it can continue to enjoy strong growth and rapid innovation. We are grateful to the team at Meta, where PyTorch was incubated and grew into a massive ecosystem, for trusting the Linux Foundation with this crucial effort. The journey will be epic.

The AI Imperative, Open Source and PyTorch

Artificial Intelligence, Machine Learning, and Deep Learning are critical to present and future technology innovation. Growth around AI and ML communities and the code they generate has been nothing short of extraordinary. AI/ML is also a truly “open source-first” ecosystem. The majority of popular AI and ML tools and frameworks are open source. The community clearly values transparency and the ethos of open source. Open source communities are playing and will play a leading role in development of the tools and solutions that make AI and ML possible — and make it better over time. 

For all of the above reasons, the Linux Foundation understands that fostering open source in AI and ML is a key priority. The Linux Foundation already hosts and works with many projects that are either contributing directly to foundational AI/ML projects (LF AI & Data) or contributing to their use cases and integrating with their platforms. (e.g., LF Networking, AGL, Delta Lake, RISC-V, CNCF, Hyperledger). 

PyTorch extends and builds on these efforts. Obviously, PyTorch is one of the most important foundational platforms for development, testing and deployment of AI/ML and Deep Learning applications. If you need to build something in AI, if you need a library or a module, chances are there is something in PyTorch for that. If you peel back the cover of any AI application, there is a strong chance PyTorch is involved in some way. From improving the accuracy of disease diagnosis and heart attacks, to machine learning frameworks for self-driving cars, to image quality assessment tools for astronomers, PyTorch is there.

Originally incubated by Meta’s AI team, PyTorch has grown to include a massive community of contributors and users under their community-focused stewardship. The genius of PyTorch (and a credit to its maintainers) is that it is truly a foundational platform for so much AI/ML today, a real Swiss Army Knife. Just as developers built so much of the technology we know today atop Linux, the AI/ML community is building atop PyTorch – further enabling emerging technologies and evolving user needs. As of August 2022, PyTorch was one of the five-fastest growing open source software communities in the world alongside the Linux kernel and Kubernetes. From August 2021 through August 2022, PyTorch counted over 65,000 commits. Over 2,400 contributors participated in the effort, filing issues or PRs or writing documentation. These numbers place PyTorch among the most successful open source projects in history.  

Neutrality as a Catalyst

Projects like PyTorch that have the potential to become a foundational platform for critical technology benefit from a neutral home. Neutrality and true community ownership are what has enabled Linux and Kubernetes to defy expectations by continuing to accelerate and grow faster even as they become more mature. Users, maintainers and the community begin to see them as part of a commons that they can rely on and trust, in perpetuity. By creating a neutral home, the PyTorch Foundation, we are collectively locking in a future of transparency, communal governance, and unprecedented scale for all.

As part of the Linux Foundation, PyTorch and its community will benefit from our many programs and support communities like training and certification programs (we already have one in the works), to community research (like our Project Journey Reports) and, of course, community events. Working inside and alongside the Linux Foundation, the PyTorch community also has access to our LFX collaboration portal, enabling mentorships and helping the PyTorch community identify future leaders, find potential hires, and observe shared community dynamics. 

PyTorch has gotten to its current state through sound maintainership and open source community management. We’re not going to change any of the good things about PyTorch. In fact, we can’t wait to learn from Meta and the PyTorch community to improve the experiences and outcomes of other projects in the Foundation. For those wanting more insight about our plans for the PyTorch Foundation, I invite you to join Soumith Chintala (co-creator of PyTorch) and Dr. Ibrahim Haddad (Executive Director of the PyTorch Foundation) for a live discussion on Thursday entitled, PyTorch: A Foundation for Open Source AI/ML.

We are grateful for Meta’s trust in “passing us the torch” (pun intended). Together with the community, we can build something (even more) insanely great and add to the global heritage of invaluable technology that underpins the present and the future of our lives. Welcome, PyTorch! We can’t wait to get started!

The post Welcoming PyTorch to the Linux Foundation appeared first on Linux Foundation.

35 Podcasts Recommended by People You Can Trust

2 Settembre 2022 ore 17:00
recommended podcasts from people you trust

Because of my position as Executive Producer and host of The Untold Stories of Open Source, I frequently get asked, “What podcasts do you listen to when you’re not producing your own.” Interesting question. However, my personal preference, This American Life, is more about how they create their shows, how they use sound and music to supplement the narration, and just in general, how Ira Glass does what he does. Only podcast geeks would be interested in that, so I reached out to my friends in the tech industry to ask them what THEY listen to.

The most surprising thing I learned was people professing to not listen to podcasts. “I don’t listen to podcasts, but if I had to choose one…”, kept popping up. The second thing was people in the industry need a break and use podcasts to escape from the mayhem of their day. I like the way Jennifer says it best, “Since much of my role is getting developers on board with security actions, I gravitate toward more psychology based podcasts – Adam Grant’s is amazing (it’s called WorkLife).”

Now that I think of it, same here. This American Life. Revisionist History. Radio Lab. The Moth. You get the picture. Escaping from the mayhem of the day.

Without further digression, here are the podcasts recommended by the people I trust, no particular order. No favoritism.

The Haunted Hacker

The Haunted Hacker

Hosted by Mike Jones and Mike LeBlanc

Mike Jones and Mike LeBlanc built the H4unt3d Hacker podcast and group from a really grass roots point of view. The idea was spawned over a glass of bourbon on the top of a mountain. The group consists of members from around the globe and from various walks of life, religions, backgrounds and is all inclusive. They pride themselves in giving back and helping people understand the cybersecurity industry and navigate through the various challenges one faces when they decide cybersecurity is where they belong.

“I think he strikes a great balance between newbie/expert, current events and all purpose security and it has a nice vibe” – Alan Shimel, CEO, Founder, TechStrong Group

Risky Biz Security Podcast

Risky Biz Security Podcast

Hosted by Patrick Gray

Published weekly, the Risky Business podcast features news and in-depth commentary from security industry luminaries. Hosted by award-winning journalist Patrick Gray, Risky Business has become a must-listen digest for information security professionals. We are also known to publish blog posts from time to time.

“My single listen-every-week-when-it-comes out is not that revolutionary: the classic Risky Biz security podcast. As a defender, I learn from the offense perspective, and they also aren’t shy about touching on the policy side.” – Allan Friedman, Cybersecurity and Infrastructure Security Agency

Security Weekly Podcast

Application Security Weekly

Hosted by Mike Shema, Matt Alderman, and John Kinsella

If you’re looking to understand DevOps, application security, or cloud security, then Application Security Weekly is your show! Mike, Matt, and John decrypt application development  – exploring how to inject security into the organization’s Software Development Lifecycle (SDLC); learn the tools, techniques, and processes necessary to move at the speed of DevOps, and cover the latest application security news.

“Easily my favorite hosts and content. Professional production, big personality host, and deeply technical co-host. Combined with great topics and guests.” – Larry Maccherone, Dev[Sec]Ops Transformation Architect, Contrast Security

Azure DevOps Podcast

Hosted by Jeffrey Palermo

The Azure DevOps Podcast is a show for developers and devops professionals shipping software using Microsoft technologies. Each show brings you hard-hitting interviews with industry experts innovating better methods and sharing success stories. Listen in to learn how to increase quality, ship quickly, and operate well.

“I am pretty focused on Microsoft Azure these days so on my list is Azure DevOps” – Bob Aiello CM Best Practices Founder, CTO, and Principal Consultant

Chaos Community Broadcast

Chaos Community Broadcast

Hosted by Community of Chaos Engineering Practitioners

We are a community of chaos engineering practitioners. Chaos Engineering is the discipline of experimenting on a system in order to build confidence in the system’s capability to withstand turbulent conditions in production.

“This is so good, it’s hardly even fair to compare it to other podcasts!” – Casey Rosenthal, CEO, Co-founder, Verica

Daily Beans Podcast

The Daily Beans. News. With Swearing

Hosted by Allison Gill (A.G.)

The Daily Beans is a women-owned and operated progressive news podcast for your morning commute brought to you by the webby award-winning hosts of Mueller, She Wrote. Get your social justice and political news with just the right amount of snark.

The Daily Beans covers political news without hype. The host is a lawyer and restricts her coverage to what can actually happen while other outlets are hyping every possibility under the sun including possibilities that get good ratings but will never happen. She mostly covers the former president’s criminal cases.” – Tom Limoncelli, Manager, Stack Overflow

Software Engineering Radio

Software Engineering Radio

Hosted by Community of Various Contributors

Software Engineering Radio is a podcast targeted at the professional software developer. The goal is to be a lasting educational resource, not a newscast. Now a weekly show, we talk to experts from throughout the software engineering world about the full range of topics that matter to professional developers. All SE Radio episodes feature original content; we don’t record conferences or talks given in other venues.

The one that I love to keep tabs on is called Software Engineering Radio, published by the IEEE computer society. It is absolutely a haberdashery of new ideas, processes, lessons learned. It also ranges from very practical action oriented advice the whole way over to philosophical discussions that are necessary for us to drive innovation forward. Professionals from all different domains contribute. It’s not a platform for sales and marketing pitches!” – Tracy Bannon, Senior Principal/ Software Architect & DevOps Advisor, MITRE

Cybrary Podcast

Cybrary Podcast

Hosted by Various Contributors

Join thousands of other listeners to hear from the current leaders, experts, vendors, and instructors in the IT and Cybersecurity fields regarding DevSecOps, InfoSec, Ransomware attacks, the diversity and the retention of talent, and more. Gain the confidence, consistency, and courage to succees at work and in life.

Relaxed chat, full of good info, and they got right to the point. Would recommend.” – Wendy Nather, Head of Advisory CISOs, CISCO

Open Source Underdogs Podcast

Open Source Underdogs

Hosted by Michael Schwartz

Open Source Underdogs is the podcast for entrepreneurs about open source software. In each episode, we chat with a founder or leader to explore how they are building thriving businesses around open source software. Our goal is to demystify how entrepreneurs can stay true to their open source objectives while also building sustainable, profitable businesses that fuel innovation and ensure longevity.

Mike Schwartz’s podcast is my favourite. Really good insights from founders.” – Amanda Brock, CEO, OpenUK

Ten Percent Happier

Hosted by Dan Harris

Ten Percent Happier publishes a variety of podcasts that offer relatable wisdom designed to help you meet the challenges and opportunities in your daily life.

I listen to Ten Percent Happier as my go-to podcast. It helps me with mindfulness practice, provides a perspective on real-life situations, and makes me a kinder person. That is one of the most important traits we all need these days.” – Arun Gupta, Vice President and General Manager for Open Ecosystem, Intel

Making Sense Podcast

Making Sense

Hosted by Sam Harris

Sam Harris is the author of five New York Times best sellers. His books include The End of Faith, Letter to a Christian Nation, The Moral Landscape, Free Will, Lying, Waking Up, and Islam and the Future of Tolerance (with Maajid Nawaz). The End of Faith won the 2005 PEN Award for Nonfiction. His writing and public lectures cover a wide range of topics—neuroscience, moral philosophy, religion, meditation practice, human violence, rationality—but generally focus on how a growing understanding of ourselves and the world is changing our sense of how we should live.

Sam dives deep on topics rooted in our culture, business, and minds. The conversations are very approachable and rational. With some episodes reaching an hour or more, Sam gives topics enough space to cover the necessary angles.” – Derek Weeks, CMO, The Linux Foundation

Darknet Diaries

Darknet Diaries

Hosted by Jack Rhysider

Darknet Diaries produces audio stories specifically intended to capture, preserve, and explain the culture around hacking and cyber security in order to educate and entertain both technical and non-technical audiences.

This is a podcast about hackers, breaches, shadow government activity, hacktivism, cybercrime, and all the things that dwell on the hidden parts of the network.

Darknet Diaries would be my recommendation. Provided insights into the world of hacking, data breaches and cyber crime. And Jack Rhysider is a good storyteller ” – Edwin Kwan, Head of Application Security and Advisory, Tyro Payments

Under the Skin

Under the Skin

Hosted by Russel Brand

Under the Skin asks: what’s beneath the surface – of the people we admire, of the ideas that define our times, of the history we are told. Speaking with guests from the world of academia, popular culture and the arts, they’ll teach us to see the ulterior truth behind or constructed reality. And have a laugh.

“He interviews influential people from all different backgrounds and covers everything from academia to tech to culture to spiritual issues” – Ashleigh Auld, Global Director Partner Marketing, Linnwood

Cyberwire Daily

Hosted by Dave Bittner

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also included interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

“I’d recommend the CyberWire daily podcast has got most relevant InfoSec news items and stories industry pros care about. XX” – Ax Sharma, Security Researcher, Tech Reporter, Sonatype

7 Minute Security Podcast

Hosted by Brian Johnson

7 Minute Security is a weekly audio podcast (once in a while with video!) released on Wednesdays and covering topics such Penetration testing, Blue teaming, and Building a career in security.

In 2013 I took on a new adventure to focus 100% on information security. There’s a ton to learn, so I wanted to write it all down in a blog format and share with others. However, I’m a family man too, and didn’t want this project to offset the work/family balance.

So I thought a podcast might fill in the gaps for stuff I can’t – or don’t have time to – write out in full form. I always loved the idea of a podcast, but the good ones are usually in a longer format, and I knew I didn’t have time for that either. I was inspired by the format of the 10 Minute Podcast and figured if it can work for comedy, maybe it can work for information security!

Thus, the 7 Minute Security blog and its child podcast was born.

7 Minute Security Podcast – because Brian makes the best jingles!” – Björn Kimminich, Product Group Lead Architecture Governance, Kuehne + Nagel (AG & Co.) KG

Continuous Delivery

Continuous Delivery

Hosted by Dave Farley

Explores ideas that help to produce Better Software Faster: Continuous Delivery, DevOps, TDD and Software Engineering.

Hosted by Dave Farley – a software developer who has done pioneering work in DevOps, CD, CI, BDD, TDD and Software Engineering. Dave has challenged conventional thinking and led teams to build world class software.

Dave is co-author of the award wining book – “Continuous Delivery”, and a popular conference speaker on Software Engineering. He built one of the world’s fastest financial exchanges, is a pioneer of BDD, an author of the Reactive Manifesto, and winner of the Duke award for open source software – the LMAX Disruptor.

Dave Farley’s videos are a treasure trove of knowledge that took me and others years to uncover when we were starting out. His focus on engineering and business outcomes rather than processes and frameworks is a breath of fresh air. If you only have time for one source of information, use his.Bryan Finster, Value Stream Architect, Defense Unicorns

The Prof G Show

The Prof G Show

Hosted by Scott Galloway

A fast and fluid weekly thirty minute show where Scott tears into the taxonomy of the tech business with unfiltered, data-driven insights, bold predictions, and thoughtful advice.

Very current very modern. Business and tech oriented. Talks about markets and economics and people and tech.” – Caroline Wong, Chief Strategy Officer, Cobalt

Open Source Security Podcast

Open Source Security Podcast

Hosted by Josh Bressers and Kurt Seifried

Open Source Security is a collaboration by Josh Bressers and Kurt Seifried. We publish the Open Source Security Podcast and the Open Source Security Blog.

We have a security tabletop game that Josh created some time ago. Rather than play a boring security tabletop exercise, what if had things like dice and fun? Take a look at the Dungeons and Data tabletop game

It has been something I’ve been listening to a lot lately with all of the focus on Software Supply Chain Security and Open Source Security. The hosts have very deep software and security backgrounds but keep the show light-hearted and engaging as well. ” – Chris Hughes, CISO, Co-Founder Aquia Inc

Pivot Podcast

Pivot

Hosted by Kara Swisher and Professor Scott Galloway

Every Tuesday and Friday, tech journalist Kara Swisher and NYU Professor Scott Galloway offer sharp, unfiltered insights into the biggest stories in tech, business, and politics. They make bold predictions, pick winners and losers, and bicker and banter like no one else. After all, with great power comes great scrutiny. From New York Magazine and the Vox Media Podcast Network.

As a rule, I don’t listen to tech podcasts much at all, since I write about tech almost all day. I check out podcasts about theater or culture — about as far away from my day job as I can get. However, I follow a ‘man-about-town’ guy named George Hahn on social media, who’s a lot of fun. Last year, he mentioned he’d be a guest host of the ‘Pivot’ podcast with Kara Swisher and Scott Galloway, so I checked out Pivot. It’s about tech but it’s also about culture, politics, business, you name it. So that’s become the podcast I dip into when I want to hear a bit about tech, but in a cocktail-party/talk show kind of way.” – Christine Kent, Communications Strategist, Christine Kent Communications

The Idealcast

The Idealcast

Hosted by Gene Kim

Conversations with experts about the important ideas changing how organizations compete and win. In The Idealcast, multiple award-winning CTO, researcher and bestselling author Gene Kim hosts technology and business leaders to explore the dangerous, shifting digital landscape. Listeners will hear insights and gain solutions to help their enterprises thrive in an evolving business world.

“I like this because it has a good balance of technical and culture/leadership content.” – Courtney Kissler, CTO, Zulily

Trustedsec Security Podcast

TrustedSec Security Podcast

Hosted by Dave Kennedy and Various Team Contributors

Our team records a regular podcast covering the latest security news and stories in an entertaining and informational discussion. Hear what our experts are thinking and talking about.

I LOVE LOVE LOVE the TrustedSec Security Podcast. Dave Kennedy’s team puts on a very nice and often deeply technical conversation every two weeks. The talk about timely topics from today’s headlines as well as jumping into purple team hackery which is a real treat to listen in and learn from.” – CRob Robinson, Director of Security Communications Intel Product Assurance and Security, Intel

Profound Podcast

Profound Podcast

Hosted by John Willis

Ramblings about W. Edwards Deming in the digital transformation era. The general idea of the podcast is derived from Dr. Demming’s seminal work described in his New Economics book – System of Profound Knowledge ( SoPK ). We’ll try and get a mix of interviews from IT, Healthcare, and Manufacturing with the goal of aligning these ideas with Digital Transformation possibilities. Everything related to Dr. Deming’s ideas is on the table (e.g., Goldratt, C.I. Lewis, Ohno, Shingo, Lean, Agile, and DevOps).

I don’t listen to podcasts much these days (found that consuming books via audible was more useful… but I guess it all depends on how emerging the topics are you are interested in). I only mention this as I am thin I recommendations. I’d go with John Willis’s Profound or Gene Kim’s Idealcast. Some overlap in (world class) guests but different interview approaches and perspectives.” – Damon Edwards, Sr. Director, Product PagerDuty

Security Now Podcast

Security Now

Hosted by Steve Gibson and Leo Laporte

Stay up-to-date and deepen your cybersecurity acumen with Security Now. On this long-running podcast, cybersecurity authority Steve Gibson and technology expert Leo Laporte bring their extensive and historical knowledge to explore digital security topics in depth. Each week, they take complex issues and break them down for clarity and big-picture understanding. And they do it all in an approachable, conversational style infused with their unique sense of humor. Listen and subscribe, and stay on top of the constantly changing world of Internet security. Security Now records every Tuesday afternoon and hits your podcatcher later that evening.

“The shows cover a wide range of security topics, from the basics of technologies such as DNSSec & Bitcoin, to in depth, tech analysis of the latest hacks hitting the news, The main host, Steve Gibson, is great at breaking down tech subjects over an audio . It’s running at over 800 episodes now, regular as clockwork every week, so you can rely on it. Funnily Steve Gibson has often reminded me of you – able to assess what’s going on with a subject, calmly find the important points, and describe them to the rest of us in way that’s engaging and relatable.medium – in a way you can follow and be interested in during your commute or flight.” – Gary Robinson, Chief Security Officer, Ulseka

The Jordan Harbinger Show Podcast

The Jordan Harbinger Show

Hosted by Jordan Harbinger

Today, The Jordan Harbinger Show has over 15 million downloads per month and features a wide array of guests like Kobe Bryant, Moby, Dennis Rodman, Tip “T.I.” Harris, Tony Hawk, Cesar Millan, Simon Sinek, Eric Schmidt, and Neil deGrasse Tyson, to name a few. Jordan continues to teach his skills, for free, at 6-Minute Networking. In addition to hosting The Jordan Harbinger Show, Jordan is a consultant for law enforcement, military, and security companies and is a member of the New York State Bar Association and the Northern California Chapter of the Society of Professional Journalists.

Excellent podcasts where he interviews people from literally every walk of life, how they have become successful, why they have failed (if they have) as well as great personal development coaching ideas.” – Jeff DeVerter, CTO, Products and Services, RackSpace

WorkLife Podcast

WorkLife with Adam Grant

Hosted by Adam Grant

Adam hosts WorkLife, a chart-topping TED original podcast. His TED talks on languishing, original thinkers, and givers and takers have been viewed more than 30 million times. His speaking and consulting clients include Google, the NBA, Bridgewater, and the Gates Foundation. He writes on work and psychology for the New York Times, has served on the Defense Innovation Board at the Pentagon, has been honored as a Young Global Leader by the World Economic Forum, and has appeared on Billions.

I don’t listen to many technical podcasts. I like Caroline Wongs and have listened to it a number of times (Humans of InfoSec) but since much of my role is getting developers on board with security actions, I gravitate toward more psychology based podcasts – Adam Grant’s is amazing (it’s called WorkLife).” – Jennifer Czaplewski, Senior Director, Cyber Security, Target

You know lately I have been listening to WorkLife with Adam Grant. Not a tech podcast but a management one.” – Paula Thrasher, Senior Director Infrastructure, PagerDuty

SRE Podcast

SRE Prodcast

Hosted by Core Team Members:  Betsy Beyer, MP English, Salim Virji, Viv

The Google Prodcast Team has gone through quite a few iterations and hiatuses over the years, and many people have had a hand in its existence. For the longest time, a handful of SREs produced the Prodcast for the listening pleasure of the other engineers here at Google.

We wanted to make something that would be of interest to folks across organizations and technical implementations. In his last act as part of the Prodcast, JTR put us in touch with Jennifer Petoff, Director of SRE Education, in order to have the support of the SRE organization behind us.

The SRE Prodcast is Google’s podcast about Site Reliability Engineering and production software. In Season 1, we discuss concepts from the SRE Book with experts at Google.” – Jennifer Petoff, Director, Program Management, Cloud Technical Education Google

Make Me Smart Podcast

Make Me Smart

Hosted by Kai Ryssdal And Kimberly Adams

Every weekday, Kai Ryssdal and Kimberly Adams break down the news in tech, the economy and culture. How do companies make money from disinformation? How can we tackle student debt? Why do 401(k)s exist? What will it take to keep working moms from leaving the workforce? Together, we dig into complex topics to help make today make sense

I literally learn 3 new things about topics i never would have tried to learn about.” – Kadi Grigg, Enablement Specialist, Sonatype

EconTalk

EconTalk

Hosted by Russ Roberts

Conversations for the Curious is an award-winning weekly podcast hosted by Russ Roberts of Shalem College in Jerusalem and Stanford’s Hoover Institution. The eclectic guest list includes authors, doctors, psychologists, historians, philosophers, economists, and more. Learn how the health care system really works, the serenity that comes from humility, the challenge of interpreting data, how potato chips are made, what it’s like to run an upscale Manhattan restaurant, what caused the 2008 financial crisis, the nature of consciousness, and more.

The only podcast I listen to is actually EconTalk, which has nothing to do with tech!” – Kelly Shortridge, Senior Principal, Product Technology, Fastly

Leading the Future of Work

Leading the Future of Work

Hosted by Jacob Morgan

The Future of Work With Jacob Morgan is a unique show that explores how the world of
work is changing, and what we need to do in order to thrive. Each week several episodes are
released which range from long-form interviews with the world’s top business leaders and
authors to shorter form episodes which provide a strategy or tip that listeners can apply to
become more successful.

The show is hosted by 4x best-selling author, speaker and futurist Jacob Morgan and the
goal is to give listeners the inspiration, the tools, and the resources they need to succeed
and grow at work and in life.

Episodes are not scripted which makes for fun, authentic, engaging, and educational
episodes filled with insights and practical advice.

It is hard for me to keep up with podcasts. The one I listen to regularly is “Leading The Future of Work” by Jacob Morgan. I know it is not technical, but I think it is extremely important for technical people to understand what the business thinks and is concerned about.” – Keyaan Williams, Managing Director, CLASS-LLC

Hacking Humans Podcast

Hacking Humans

Hosted by Dave Bittner and Joe Carrigan

Deception, influence, and social engineering in the world of cyber crime.

Join Dave Bittner and Joe Carrigan each week as they look behind the social engineering scams, phishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world.

In case we needed any reminders that humanity is a scary place.” – Matt Howard, SVP and CMO, Virtu

Cloud Security Podcast

Cloud SecurityPodcast

Hosted by Ashish Rajan, Shilpi Bhattacharjee, and Various Contributors

Cloud Security Podcast is a WEEKLY Video and Audio Podcast that brings in-depth cloud security knowledge to you from the best and brightest cloud security experts and leaders in the industry each week over our LIVE STREAMs.

We are the FIRST podcast that carved the niche for Cloud Security in late 2019. As of 2021, the large cloud service providers (Azure, Google Cloud, etc.) have all followed suit and started their own cloud security podcasts. While we recommend you listen to their podcasts as well, we’re the ONLY VENDOR NEUTRAL podcast in the space and will preserve our neutrality indefinitely.

I really love Ashish’s cloud security podcast, listened to it for a while now. He gets really good people on it and it’s a nice laid back listen, too.” – Simon Maple, Field CTO, Snyk

DSO Overflow Podcast

DSO Overflow

Hosted by Glenn Wilson, Steve Giguere, Jessica Cregg

In depth conversations with influencers blurring the lines between Dev, Sec, and Ops!

We speak with professionals working in cyber security, software engineering and operations to talks about a number of DevSecOps topics. We discuss how organisations factor security into their product delivery cycles without compromising the value of doing DevOps and Agile.

One of my favourite meetups in London ‘DevSecOps London Gathering’ has a podcast where they invite their speakers https://dsolg.com/#podcast” – Stefania Chaplin, Solutions Architect UK&I, GitLab

Pardon the Interruption

Pardon the Interruption

Hosted by Tony Kornheiser and Mike Wilbon

Longtime sportswriters Tony Kornheiser and Mike Wilbon debate and discuss the hottest topics, issues and events in the world of sports in a provocative and fast-paced format.

Similar in format to Gene Siskel and Roger Ebert‘s At the Movies,[2][3] PTI is known for its humorous and often loud tone, as well as the “rundown” graphic which lists the topics yet to be discussed on the right-hand side of the screen. The show’s popularity has led to the creation of similar shows on ESPN and similar segments on other series, and the rundown graphic has since been implemented on the morning editions of SportsCenter, among many imitators.[4] – Wikipedia

I’m interested in sports, and Tony and Mike are well-informed, amusing, and opinionated. It also doesn’t hurt any that I’ve known them since they were at The Washington Post and I was freelancing there. What you see on television, or hear on their podcast, is exactly how they are in real life. This sincerity of personality is a big reason why they’ve become so successful.” – Steven Vaughan-Nichols, Technology and business journalist and analyst. Red Ventures

The post 35 Podcasts Recommended by People You Can Trust appeared first on Linux Foundation.

You want content? We’ve got your content right here!

2 Settembre 2022 ore 16:47
ONE Summit LF Networking November 15-16

ONE Summit Agenda is now live!

This post originally appeared on LF Networking’s blog. The author, Heather Kirksey, is VP Community & Ecosystem. ONE Summit is the Linux Foundation Networking event that focuses on the networking and automation ecosystem that is transforming public and private sector innovation across 5G network edge, and cloud native solutions. Our family of open source projects address every layer of infrastructure needs from the user edge to the cloud/core. Attend ONE Summit to get the scoop on hot topics for 2022!

Today LF Networking announced our schedule for ONE Summit, and I have to say that I’m extraordinarily excited. I’m excited because it means we’re growing closer to returning to meeting in-person, but more importantly I was blown away by the quality of our speaking submissions. Before I talk more about the schedule itself, I want to say that this quality is all down to you: You sent us a large number of thoughtful, interesting, and innovative ideas; You did the work that underpins the ideas; You did the work to write them up and submit them. The insight, lived experience, and future-looking thought processes humbled me with its breadth and depth. You reminded me why I love this ecosystem and the creativity within open source. We’ve all been through a tough couple of years, but we’re still here innovating, deploying, and doing work that improves the world. A huge shout out to everyone across every company, community, and project that made the job of choosing the final roster just so difficult.

Now onto the content itself. As you’ve probably heard, we’ve got 5 tracks: Industry 4.0, Security and Privacy, The New Networking Stack, Operationalizing Deployment, and Emerging Technologies and Business Models:

  • “Industry 4.0” looks at the confluence of edge and networking technologies that enable technology to uniquely improve our interactions with the physical world, whether that’s agriculture, manufacturing, robotics, or our homes. We’ve got a great line-up focused both on use cases and the technologies that enable them.
  • “Security and Privacy” are the most important issues with which we as global citizens and we as an ecosystem struggle. Far from being an afterthought, security is front and center as we look at zero-trust and vulnerability management, and which technologies and policies best serve enterprises and consumers.
  • Technology is always front and center for open source groups and our “New Networking Stack” track dives deep into the technologies and components we will all use as we build the infrastructure of the future. In this track we have a number of experts sharing their best practices, as well as ideas for forward-looking usages.
  • In our “Operationalizing Deployment” track, we learn from the lived experience of those taking ideas and turning them into workable reality. We ask questions like,  How do you bridge cultural divides? How do you introduce and truly leverage DevOps? How do you integrate compliance and reference architectures? How do you not only deploy but bring in Operations? How do you automate and how to you use tools to accomplish digital transformation in our ecosystem(s)?
  • Not just content focusing only on today’s challenges and success, we look ahead with “Emerging Technologies and Business Models.” Intent, Metaverse, MASE, Scaling today’s innovation to be tomorrow’s operations, new takes on APIs – these are the concepts that will shape us in the next 5-10 years; we  talk about how we start approaching and understanding them?

Every talk that made it into this program has unique and valuable insight, and I’m so proud to be part of the communities that proposed them. I’m also honored to have worked with one of the best Programming Committees in open source events ever. These folks took so much time and care to provide both quantitative and qualitative input that helped shape this agenda. Please be sure to thank them for their time because they worked hard to take the heart of this event to the next level. If you want to be in the room and in the hallway with these great speakers, there is only ONE place to be. Early bird registration ends soon, so don’t miss out and register now!

And please don’t forget to sponsor. Creating a space for all this content does cost money, and we can’t do it without our wonderful sponsors. If you’re still on the fence, please consider how amazing these sessions are and the attendee conservations they will spark. We may not be the biggest conference out there, but we are the most focused on decision makers and end users and the supply chains that enable them. You won’t find a more engaged and thoughtful audience anywhere else.

The post You want content? We’ve got your content right here! appeared first on Linux Foundation.

Is it time for an OSPO in your organization?

2 Settembre 2022 ore 16:11

Is your organization consuming open source software, or is it starting to contribute to open source projects? If so, perhaps it’s time for you to start an OSPO: an open source program office.

At the LF, we’re dedicating resources to improving your understanding of all things open source, such as our Guide to Enterprise Open Source and the Evolution of the Open Source Program Office, published the last year. 

In a new Linux Foundation Research report, A Deep Dive into Open Source Program Offices, published in partnership with the TODO Group, authored by Dr. Ibrahim Haddad, Ph.D, showcases the many forms of OSPOs, their maturity models, responsibilities, and challenges they face in open source enterprise adoption, and also their staffing requirements are discussed in detail. 

“The past two decades have accelerated open source software adoption and increased involvement in contributing to existing projects and creating new projects. Software is where a lot of value lies and the vast majority of software developed is open source software providing access to billions of dollars worth of external R&D. If your organization relies on open source software for products or services and does not have a formalized OSPO yet ​​to manage all aspects of working with open source, please consider this report a call to establish your OPSO and drive for leadership in the open source areas that are critical to your products and services.”Ibrahim Haddad, Ph.D., General Manager, LF AI & Data Foundation

Here are some of the report’s important lessons:

An OSPO can help you manage and track your company’s use of open source software and assist you when interacting with other stakeholders. It can also serve as a clearinghouse for information about open source software and its usage throughout your organization.

Your OSPO is the central nervous system for an organization’s open source strategy and provides governance, oversight, and support for all things related to open source.

OSPOs create and maintain an inventory of your open source software (OSS) assets and track and manage any associated risks. The OSPO also guides how to best use open source software within the organization and can help coordinate external contributions to open source projects.

To be effective, the OSPO needs to have a deep understanding of the business and the technical aspects of open source software. It also needs to work with all levels of the organization, from executives to engineers.

An OSPO is designed to:

  • Be the center of competency for an organization’s open source operations and structure,
  • Place a strategy and set of policies on top of an organization’s open source efforts.

This can include creating policies for code use, distribution, selection, auditing, and other areas; training developers; ensuring legal compliance, and promoting and building community engagement to benefit the organization strategically.

An organization’s OSPO can take many different forms, but typically it is a centralized team that reports to the company’s executive level. The size of the team will depend on the size and needs of the organization, and how it is adopted also will undergo different stages of maturity.

When starting, an OSPO might just be a single individual or a very small team. As the organization’s use of open source software grows, the OSPO can expand to include more people with different specialties. For example, there might be separate teams for compliance, legal, and community engagement.

This won’t be the last we have to say about the OSPO in 2022. There are further insights in development, including a qualitative study on the OSPO’s business value across different sectors, and the TODO group’s publication of the 2022 OSPO Survey results will take place during OSPOCon in just a few weeks. 

There is no board template to build an OSPO. Its creation and growth can vary depending on the organization’s size, culture, industry, or even its milestones.

That’s why I keep seeing more and more open source leaders finding critical value in building connections with other professionals in the industry. OSPOCon is an excellent networking and learning space where those working (or willing to work) in open source program offices that rely on open source technologies come together to learn and share best practices, experiences, and tools to overcome challenges they face.” Ana Jiménez, OSPO Program Manager at TODO Group

Join us there and be sure to read the report today to gain key insights into forming and running an OSPO in your organization. 

The post Is it time for an OSPO in your organization? appeared first on Linux Foundation.

Addressing Cybersecurity Challenges in Open Source Software: What you need to know

1 Settembre 2022 ore 19:16

by Ashwin Ramaswami

June 2022 saw the publication of Addressing Cybersecurity Challenges in Open Source Software, a joint research initiative launched by the Open Source Security Foundation in collaboration with Linux Foundation Research and Snyk. The research dives into security concerns in the open source ecosystem. If you haven’t read it, this article will give you the report’s who, what, and why, summarizing its key takeaways so that it can be relevant to you or your organization.

Who is the report for?

This report is for everyone whose work touches open source software. Whether you’re a user of open source, an OSS developer, or part of an OSS-related institution or foundation, you can benefit from a better understanding of the state of security in the ecosystem.

Open source consumers and users: It’s very likely that you rely on open source software as dependencies if you develop software. And if you do, one important consideration is the security of the software supply chain. Security incidents such as log4shell have shown how open source supply chain security touches nearly every industry. Even industries and organizations that have traditionally not focused on open source software now realize the importance of ensuring their OSS dependencies are secure. Understanding the state of OSS security can help you to manage your dependencies intelligently, choose them wisely, and keep them up to date.

Open source developers and maintainers: People and organizations that develop or maintain open source software need to ensure they use best practices and policies for security. For example, it can be valuable for large organizations to have open source security policies. Moreover, many OSS developers also use other open source software as dependencies, making understanding the OSS security landscape even more valuable. Developers have a unique role to play in leading the creation of high-quality code and the respective governance frameworks and best practices around it.

Institutions: Institutions such as open source foundations, funders, and policymaking groups can benefit from this report by understanding and implementing the key findings of the research and their respective roles in improving the current state of the OSS ecosystem. Funding and support can only go to the right areas if priorities are informed by the problems the community is facing now, which the research assists in identifying.

What are the major takeaways?

The data from this report was collected by conducting a worldwide survey of:

  • Individuals who contribute to, use, or administer OSS;
  • Maintainers, core contributors, and occasional contributors to OSS;
  • Developers of proprietary software who use OSS; and
  • Individuals with a strong focus on software supply chain security

The survey also included data collected from several major package ecosystems by using Snyk Open Source, a static code analysis (SCA) tool free to use for individuals and open source maintainers.

Here are the major takeaways and recommendations from the report:

  • Too many organizations are not prepared to address OSS security needs: At least 34% of organizations did not have an OSS security policy in place, suggesting these organizations may not be prepared to address OSS security needs.
  • Small organizations must prioritize developing an OSS security policy: Small organizations are significantly less likely to have an OSS security policy. Such organizations should prioritize developing this policy and having a CISO and OSPO (Open Source Program Office).
  • Using additional security tools is a leading way to improve OSS security: Security tooling is available for open source security across the software development lifecycle. Moreover, organizations with an OSS security policy have a higher frequency of security tool use than those without an OSS security policy.
  • Collaborate with vendors to create more intelligent security tools: Organizations consider that one of the most important ways to improve OSS security across the supply chain is adding greater intelligence to existing software security tools, making it easier to integrate OSS security into existing workflows and build systems.
  • Implementing best practices for secure software development is the other leading way to improve OSS security: Understanding best practices for secure software development, through courses such as the OpenSSF’s Secure Software Development Fundamentals Courses, has been identified repeatedly as a leading way to improve OSS supply chain security.
  • Use automation to reduce your attack surface: Infrastructure as Code (IaC) tools and scanners allow automating CI/CD activities to eliminate threat vectors around manual deployments.
  • Consumers of open source software should give back to the communities that support them: The use of open source software has often been a one-way street where users see significant benefits with minimal cost or investment. For larger open source projects to meet user expectations, organizations must give back and close the loop by financially supporting OSS projects they use.

Why is this important now?

Open source software is a boon: its collaborative and open nature has allowed society to benefit from various innovative, reliable, and free software tools. However, these benefits only last when users contribute back to open source software and when users and developers exercise due diligence around security. While the most successful open source projects have gotten such support, other projects have not – even as open source use has continued to be more ubiquitous.

Thus, it is more important than ever to be aware of the problems and issues everyone faces in the OSS ecosystem. Some organizations and open source maintainers have strong policies and procedures for handling these issues. But, as this report shows, other organizations are just facing these issues now.

Finally, we’ve seen the risks of not maintaining proper security practices around OSS dependencies. Failure to update open source dependencies has led to costs as high as $425 million. Given these risks, a little investment in strong security practices and awareness around open source – as outlined in the report’s recommendations – can go a long way.

We suggest you read the report – then see how you or your organization can take the next step to keep yourself secure!

The post Addressing Cybersecurity Challenges in Open Source Software: What you need to know appeared first on Linux Foundation.

❌