Mehmet Ince - Omarcy Security Team
Sep 4, 2026 · 46m
Summary
Mehmed, a cybersecurity expert and co-founder of Product, joins the first Omarchy Stories podcast to discuss his background in vulnerability research and his recent discovery of a critical flaw in Omarchy. He explains how he found a remote code execution bug while testing the distro, leading to his invitation to join the volunteer-based Omarchy security team. The episode covers the team's rapid response to AI-generated vulnerability reports and the importance of understanding security impact. Mehmed also shares insights on entering cybersecurity, emphasizing the value of learning through so…
Topics discussed
Introduction and Mehmed's background in cybersecurity
Early Linux experiences and first vulnerabilities
Long-term Linux usage and transition to Arch
Discovering Arch Linux and open source curiosity
First Arch vulnerability: Calculator exploit
Joining the Arch security team
The value of open source and AI in research
How AI has changed vulnerability discovery
Managing AI-generated reports and learning from them
Guidance for reporting vulnerabilities to Arch
The importance of security impact in reports
Volunteer-based team structure and processes
Team dynamics and lack of formal onboarding
Arch releases and upstream vulnerability handling
Contributing to the broader Linux ecosystem
Small team size and fast decision making
Researching the PostgreSQL ecosystem
Upcoming blog post and ecosystem security gaps
Explosion in vulnerability numbers and defender stress
Arch's popularity and the 'too many eyes' effect
Advice for beginners entering cybersecurity
Using AI and case studies for learning
The value of rabbit holes and the journey
Brain patterns and learning through implementation
Arch on Apple Silicon and community support
Community excitement and newsletter updates
Closing thoughts on community and motivation
Nostalgia for IRC days and final sign-off
Listen ad-free on Castria