
Sign up to save your podcasts
Or


SOC analysts, detection engineers, and pentesters—you’re not imagining it: software supply chain security is a dumpster fire 🔥. In this episode of Simply Defensive, we sit down with Kyle Kelly, engineering manager at GitHub and author of Crime Hacks, to unpack the chaos.
We cover:
- Why malicious packages are sneaking past defenders
- The truth about SBOMs (and what most orgs are doing wrong)
- How to spot typo-squatting and backdoored build scripts
- What defenders can do—even if you're not building the code
- Why “just NPM install” is more dangerous than you think
From transitive dependencies to the hidden power of private package repositories, this episode is packed with practical insights, hilarious stories, and advice every blue teamer needs.
Episode Links:
🔗 Kyle’s blog: https://crimehacks.com
👨💻 Kyle on LinkedIn: https://www.linkedin.com/in/kyle-m-kelly
📰 Crime Hacks on LinkedIn: https://www.linkedin.com/company/crimehacks
=========================
Sponsored by ThreatLocker - Free 30-day trial of ThreatLocker https://www.threatlocker.com/simplydefensive
=========================
Connect with your hosts:
Josh Mason: https://www.linkedin.com/in/joshuacmason
Wade Wells: https://www.linkedin.com/in/wadingthrulogs
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
This podcast is presented by Simply Cyber Media Group
By Simply Cyber Media Group5
22 ratings
SOC analysts, detection engineers, and pentesters—you’re not imagining it: software supply chain security is a dumpster fire 🔥. In this episode of Simply Defensive, we sit down with Kyle Kelly, engineering manager at GitHub and author of Crime Hacks, to unpack the chaos.
We cover:
- Why malicious packages are sneaking past defenders
- The truth about SBOMs (and what most orgs are doing wrong)
- How to spot typo-squatting and backdoored build scripts
- What defenders can do—even if you're not building the code
- Why “just NPM install” is more dangerous than you think
From transitive dependencies to the hidden power of private package repositories, this episode is packed with practical insights, hilarious stories, and advice every blue teamer needs.
Episode Links:
🔗 Kyle’s blog: https://crimehacks.com
👨💻 Kyle on LinkedIn: https://www.linkedin.com/in/kyle-m-kelly
📰 Crime Hacks on LinkedIn: https://www.linkedin.com/company/crimehacks
=========================
Sponsored by ThreatLocker - Free 30-day trial of ThreatLocker https://www.threatlocker.com/simplydefensive
=========================
Connect with your hosts:
Josh Mason: https://www.linkedin.com/in/joshuacmason
Wade Wells: https://www.linkedin.com/in/wadingthrulogs
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
This podcast is presented by Simply Cyber Media Group

184 Listeners

369 Listeners

638 Listeners

69 Listeners

322 Listeners

8,013 Listeners
![Talkin' About [Infosec] News, Powered by Black Hills Information Security by Black Hills Information Security](https://podcast-api-images.s3.amazonaws.com/corona/show/516141/logo_300x300.jpeg)
94 Listeners

60 Listeners

134 Listeners

169 Listeners

2 Listeners