I happen to be doing a security assessment on some products (PuTTY etc) at the firm (Fortune Global 100) where I am interning.
It baffled me to read a directive from management that said that we should shy away from open-source projects - I must confess that I was somewhat frustrated at the sheer ignorance in the memo but your comment allows me to see a silver-lining. I hope that one day I can rise up to management and make decisions based on greater nuance than simply saying "OSS bad and insecure".