<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Team on Opera Omnia</title><link>https://mikael.barbero.tech/tags/team/</link><description>Recent content in Team on Opera Omnia</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>mikael.barbero@eclipse-foundation.org (Mikaël Barbero)</managingEditor><webMaster>mikael.barbero@eclipse-foundation.org (Mikaël Barbero)</webMaster><lastBuildDate>Thu, 13 Aug 2026 11:30:00 +0200</lastBuildDate><atom:link href="https://mikael.barbero.tech/tags/team/index.xml" rel="self" type="application/rss+xml"/><item><title>Growing the Eclipse Foundation Security Team to Meet the AI Moment</title><link>https://mikael.barbero.tech/blog/post/2026-08-13-growing-the-security-team-to-meet-ai/</link><pubDate>Thu, 13 Aug 2026 11:30:00 +0200</pubDate><author>mikael.barbero@eclipse-foundation.org (Mikaël Barbero)</author><guid>https://mikael.barbero.tech/blog/post/2026-08-13-growing-the-security-team-to-meet-ai/</guid><description>&lt;p&gt;For the last several years, the Eclipse Foundation Security Team has worked alongside our project communities to keep the software they produce trustworthy. We facilitate communication between security researchers and maintainers, help evaluate and assess the severity of reported issues, support coordinated disclosure, and advise on fixes and workarounds. As a CVE Numbering Authority for over ten years, we also assign CVE IDs and curate CVE records so the broader ecosystem can rely on accurate, complete vulnerability data.&lt;/p&gt;
&lt;p&gt;That work has always demanded careful judgment. But over the past two years, the ground has shifted under all of us.&lt;/p&gt;
&lt;h2 id="ai-has-changed-the-vulnerability-landscape--in-both-directions"&gt;AI has changed the vulnerability landscape — in both directions&lt;/h2&gt;
&lt;p&gt;New AI-assisted security tools are accelerating the discovery of real vulnerabilities in open source software. The Eclipse Foundation has participated in &lt;a href="https://www.anthropic.com/glasswing"&gt;Project Glasswing&lt;/a&gt; since day one, an initiative that puts frontier AI models in the hands of organizations maintaining critical software so that long-hidden vulnerabilities can be found and fixed before the same capabilities become accessible to bad actors. That firsthand experience has shown us both sides of the equation: these tools surface credible, actionable findings that would be difficult to uncover manually, but every one of those findings still needs expert validation, contextual prioritization, and a maintainer with the time and support to land a fix.&lt;/p&gt;
&lt;p&gt;At the same time, maintainers across the open source world are reporting a sharp increase in the &lt;em&gt;volume&lt;/em&gt; of vulnerability reports they receive. Many are duplicates, false positives, or low-signal submissions bearing the hallmarks of careless AI generation. Sorting genuine issues from the noise takes real expertise and real time, and it is exactly the kind of pressure that burns out maintainers.&lt;/p&gt;
&lt;p&gt;Both trends point in the same direction: open source ecosystems need more practical, hands-on security capacity, and they need it now.&lt;/p&gt;
&lt;h2 id="a-grant-from-alpha-omega"&gt;A grant from Alpha-Omega&lt;/h2&gt;
&lt;p&gt;Earlier this year, &lt;a href="https://alpha-omega.dev/blog/linux-foundation-announces-12-5-million-in-grant-funding-from-leading-organizations-to-advance-open-source-security/"&gt;Alpha-Omega&lt;/a&gt; announced new grant funding aimed at strengthening the security of the open source ecosystem by investing in projects and organizations working to improve security practices, tooling, and capacity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We&amp;rsquo;re pleased to announce that the Eclipse Foundation has been awarded sponsorship funding from Alpha-Omega to add dedicated AI security engineering capacity to the Eclipse Foundation Security Team.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This engagement, our &amp;ldquo;AI Security Engineer in Residence&amp;rdquo; effort, is designed to provide practical, trusted, and technically capable security support to Eclipse Foundation projects while contributing to a broader cross-ecosystem initiative to improve open source security practices in response to AI-enabled threats. We&amp;rsquo;re proud to be working alongside peer organizations such as the &lt;a href="https://rustfoundation.org/media/an-ai-security-engineer-in-residence-for-the-rust-ecosystem/"&gt;Rust Foundation&lt;/a&gt;, the &lt;a href="https://freebsdfoundation.org/blog/freebsd-ai-assisted-vulnerability-discovery-project-launch/"&gt;FreeBSD Foundation&lt;/a&gt; and &lt;a href="https://alpha-omega.dev/blog/announcing-the-node-js-ai-security-engineer-in-residence/"&gt;NodeJS&lt;/a&gt;, which have received similar grants, as part of a shared virtual team of practitioners exchanging lessons, methods, and tooling across ecosystems.&lt;/p&gt;
&lt;p&gt;Rather than creating a single position, we structured this capacity as two complementary roles. Today, we&amp;rsquo;re delighted to introduce the two people filling them.&lt;/p&gt;
&lt;h2 id="what-the-new-roles-will-do"&gt;What the new roles will do&lt;/h2&gt;
&lt;p&gt;Together, these two roles will help the Eclipse Foundation ecosystem:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Find and fix vulnerabilities that matter.&lt;/strong&gt; Conduct proactive, human-led and AI-assisted security reviews of selected Eclipse Foundation projects, with findings carefully validated before they ever reach a maintainer&amp;rsquo;s inbox.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Triage smarter and faster.&lt;/strong&gt; Develop scalable workflows that separate credible findings from noise, prioritize them by severity and exploitability, and turn reports into actionable guidance, including during surges in AI-generated report volume.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support remediation, not just reporting.&lt;/strong&gt; Work directly with maintainers to explain findings in context, propose fixes, submit pull requests where appropriate, and support coordinated disclosure and release planning.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Provide rapid response capacity.&lt;/strong&gt; Offer trusted technical support when urgent, high-risk security situations arise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Serve as a point of contact for inbound reports.&lt;/strong&gt; Handle reports arriving through Project Glasswing and related channels, with triage and coordination support for affected projects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leave durable improvements behind.&lt;/strong&gt; Develop reusable playbooks, tools, prompts, and workflows that strengthen the ecosystem well beyond the term of the engagement and that we&amp;rsquo;ll share with the broader cross-ecosystem effort.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Just as importantly, here is what these roles are &lt;em&gt;not&lt;/em&gt;: they are not an external audit or enforcement function, nor are they a replacement for maintainer ownership. Success will be measured by trust, accuracy, and practical risk reduction, never by vulnerability counts for their own sake.&lt;/p&gt;
&lt;h2 id="meet-alessia"&gt;Meet Alessia&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://accounts.eclipse.org/users/alenard"&gt;&lt;strong&gt;Alessia Nardotto&lt;/strong&gt;&lt;/a&gt; joins the team as &lt;strong&gt;Security Analyst, Incident Response &amp;amp; Vulnerability Management&lt;/strong&gt;. Alessia will help monitor, investigate, and respond to security issues affecting Eclipse Foundation systems, services, and projects. She will triage incoming reports, validate findings, coordinate remediation across teams, and keep our incident response playbooks sharp. She&amp;rsquo;ll be a key part of how we absorb the growing volume of vulnerability reports without losing the careful documentation and follow-through that responsible handling demands.&lt;/p&gt;
&lt;h2 id="meet-miruna"&gt;Meet Miruna&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://accounts.eclipse.org/users/mirunasandor"&gt;&lt;strong&gt;Miruna Sandor&lt;/strong&gt;&lt;/a&gt; joins the team as &lt;strong&gt;Application Security Engineer, AI-Assisted Vulnerability Management&lt;/strong&gt;. Miruna will design, build, and operate the AI-assisted vulnerability management pipelines at the heart of this effort. She will integrate large language models and traditional security tooling into discovery and triage workflows, critically evaluate AI-generated findings, drive down false positives, and work with maintainers to land verified fixes. She&amp;rsquo;ll also benchmark these new approaches against established SAST, DAST, and dependency-scanning tools so that what we adopt is what actually works.&lt;/p&gt;
&lt;h2 id="what-this-means-for-eclipse-foundation-projects"&gt;What this means for Eclipse Foundation projects&lt;/h2&gt;
&lt;p&gt;If you maintain an Eclipse Foundation project, here&amp;rsquo;s what to expect:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Nothing changes about how you report security issues — the &lt;a href="https://www.eclipse.org/security/"&gt;existing vulnerability reporting process&lt;/a&gt; remains the front door.&lt;/li&gt;
&lt;li&gt;Over the coming months, some projects will be invited to participate in proactive security reviews. Participation is collaborative, and findings will always be validated before they reach you.&lt;/li&gt;
&lt;li&gt;If your project has been struggling with a flood of low-quality AI-generated reports, we want to hear about it. Helping you manage that intake is squarely within this team&amp;rsquo;s mission.&lt;/li&gt;
&lt;li&gt;The methods, tools, and playbooks we develop will be documented and shared so every project in the ecosystem can benefit.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Please share your questions, concerns, and suggestions in the &lt;a href="https://github.com/orgs/eclipse-csi/discussions"&gt;Eclipse CSI GitHub Discussions&lt;/a&gt; area.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re grateful to &lt;strong&gt;Alpha-Omega&lt;/strong&gt; for their support, to our peers across the Rust, FreeBSD, NodeJS, and other open source ecosystems for the collaboration ahead, and to the Eclipse Foundation community for the trust you place in the Security Team. AI has raised the stakes for open source security, but it has also given defenders powerful new tools. With Alessia and Miruna on board, we intend to make the most of them.&lt;/p&gt;</description><category>Security</category><category>Eclipse-Foundation</category><category>Team</category><category>Alpha-Omega</category></item></channel></rss>