Non-profit org that connects open-source projects with security resources. We are the Open Source Technology Improvement Fund.

Chicago, IL
We published our 100th security audit earlier this year. Read more here: ostif.org/100th-audit-public…
1
3
904
Here’s a catch-up of @OSTIFofficial 2026 so far and our plans to cap out the year. ostif.org/2026-a-very-early-… #OSTIF
1
54
Take a look at @OSTIFofficial 's role in the Security Engineer in Residence (SEiR) program. #SEiR #V-LAT #OSTIF
1
68
Project V-LAT is a team of 6 researchers triaging and fixing vulnerabilities across underserved projects, currently working through a backlog of about 450 issues, plus how similar programs are being funded across Rust, Ruby, PHP, Node.js, FreeBSD, and Drupal.
1
1
36
We just published our AI Use in Security Research Policy, outlining how we and our contractors are expected to use AI responsibly in security engagements. Read the full policy to see our standards on transparency, data handling, and disclosure. #OSTIF #AI #POLICY
1
1
381
@OSTIFofficial is proud to share the results of our security audit of Scala, executed by a team of three auditors from Quarkslab. We want to thank our very own Derek Zimmer of OSTIF for advocating for this audit for a long time! #OSTIF #Quarkslab #SovereignTechAgency #Scala
1
3
11
1,951
During a security audit of vLLM managed by OSTIF.org, a bug was discovered through manual analysis by a senior security expert at X41 D-Sec. #OSTIF #BadHost #vLLM #X41DSec
3
2
6
461
A lack of input sanitization on host header paths in Starlette leads to bypassing auth with a single character across a huge swath of Python LLM infrastructure.
1
86
Update to Starlette 1.0.1 as soon as possible and read more about this vulnerability on badhost.org
1
43
In 2023, @DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC), a massive undertaking by dozens of organizations with the goal to safeguard open source software used in critical infrastructure throughout America. #OSTIF #DARPA #AI
1
2
111
The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”). ostif.org/defo-audit-complet… #OSTIF #DEfO #AdaLogics #7ASecurity #SovereignTechAgency
1
1
232
With the help of Ada Logics, 7ASecurity, and the Sovereign Tech Agency, this project received expert security review, testing, and custom documentation contributing to DEfO’s ongoing development and security.
81
We are proud to announce our top 3 bugs of the year on our blog: ostif.org/bug-of-the-year-aw… #OSTIF #BOTY #7ASecurity
1
118
While reflecting on our past 10 years, we revisited vulnerabilities discovered during OSTIF audits. As a result of our work, several hundred bugs a year are discovered on average.
1
1
57
With that in mind, our Executive Director Derek Zimmer proposed a new program: a Bug of the Year trophy, given to the individual who finds the best bug published by OSTIF in a calendar year.
1
52