Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Josh Mason & Wade Wells and Simply Cyber Media Group. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Josh Mason & Wade Wells and Simply Cyber Media Group or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Coffee Is Your Top Supply Chain Risk: A Conversation with Kyle Kelly

28:56
 
Share
 

Manage episode 495674966 series 3604599
Content provided by Josh Mason & Wade Wells and Simply Cyber Media Group. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Josh Mason & Wade Wells and Simply Cyber Media Group or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

SOC analysts, detection engineers, and pentesters—you’re not imagining it: software supply chain security is a dumpster fire 🔥. In this episode of Simply Defensive, we sit down with Kyle Kelly, engineering manager at GitHub and author of Crime Hacks, to unpack the chaos.

We cover:
- Why malicious packages are sneaking past defenders
- The truth about SBOMs (and what most orgs are doing wrong)
- How to spot typo-squatting and backdoored build scripts
- What defenders can do—even if you're not building the code
- Why “just NPM install” is more dangerous than you think

From transitive dependencies to the hidden power of private package repositories, this episode is packed with practical insights, hilarious stories, and advice every blue teamer needs.

Episode Links:
🔗 Kyle’s blog: https://crimehacks.com
👨‍💻 Kyle on LinkedIn: https://www.linkedin.com/in/kyle-m-kelly
📰 Crime Hacks on LinkedIn: https://www.linkedin.com/company/crimehacks

=========================
Sponsored by ThreatLocker - Free 30-day trial of ThreatLocker https://www.threatlocker.com/simplydefensive
=========================
Connect with your hosts:
Josh Mason: https://www.linkedin.com/in/joshuacmason
Wade Wells: https://www.linkedin.com/in/wadingthrulogs
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
This podcast is presented by Simply Cyber Media Group

  continue reading

29 episodes

Artwork
iconShare
 
Manage episode 495674966 series 3604599
Content provided by Josh Mason & Wade Wells and Simply Cyber Media Group. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Josh Mason & Wade Wells and Simply Cyber Media Group or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

SOC analysts, detection engineers, and pentesters—you’re not imagining it: software supply chain security is a dumpster fire 🔥. In this episode of Simply Defensive, we sit down with Kyle Kelly, engineering manager at GitHub and author of Crime Hacks, to unpack the chaos.

We cover:
- Why malicious packages are sneaking past defenders
- The truth about SBOMs (and what most orgs are doing wrong)
- How to spot typo-squatting and backdoored build scripts
- What defenders can do—even if you're not building the code
- Why “just NPM install” is more dangerous than you think

From transitive dependencies to the hidden power of private package repositories, this episode is packed with practical insights, hilarious stories, and advice every blue teamer needs.

Episode Links:
🔗 Kyle’s blog: https://crimehacks.com
👨‍💻 Kyle on LinkedIn: https://www.linkedin.com/in/kyle-m-kelly
📰 Crime Hacks on LinkedIn: https://www.linkedin.com/company/crimehacks

=========================
Sponsored by ThreatLocker - Free 30-day trial of ThreatLocker https://www.threatlocker.com/simplydefensive
=========================
Connect with your hosts:
Josh Mason: https://www.linkedin.com/in/joshuacmason
Wade Wells: https://www.linkedin.com/in/wadingthrulogs
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
This podcast is presented by Simply Cyber Media Group

  continue reading

29 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play