I commented in my FOSDEM talk that FOSS is necessary but insufficient for security, and that we need an OCap/PoLA foundation; some recent malware examples like the event-stream takeover might be arguably still FOSS.

Well, here's more examples: malware appearing in FOSS browser extensions lwn.net/SubscriberLink/846272/

