Microsoft Threat Intelligence Podcast

Supply Chain Attacks: Open Source or Open Door?


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Allie Luhrs and Mario Samolis from Microsoft Security to explore the growing threat of open source software supply chain attacks. They discuss how malicious NPM packages, compromised developer ecosystems, AI-generated attacks, and software dependency risks are reshaping modern incident response, while sharing insights from their recent presentation at BlueHat IL 2025.  


In this episode you’ll learn:      

  • How attackers are targeting open source software ecosystems at scale 

    • Why AI is accelerating both cyberattacks and threat detection 

      • What was uncovered during their BlueHat presentation on modern software supply chain attacks 

        Some questions we ask:     

        • What patterns did you uncover in NPM attack campaigns? 

          • Should developers rely on dependencies or build everything themselves? 

            • Why should organizations pay closer attention to open source security risks? 

              Resources:  

              View Allie Luhrs on LinkedIn  

              View Mario Samolis on LinkedIn  

              View Sherrod DeGrippo on LinkedIn  

               

              Related Microsoft Podcasts:                   

              • Afternoon Cyber Tea with Ann Johnson 

                • The BlueHat Podcast 

                  • Uncovering Hidden Risks     

                     

                    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                     

                    Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                     

                    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                    ...more
                    View all episodesView all episodes
                    Download on the App Store

                    Microsoft Threat Intelligence PodcastBy Microsoft

                    • 5
                    • 5
                    • 5
                    • 5
                    • 5

                    5

                    22 ratings


                    More shows like Microsoft Threat Intelligence Podcast

                    View all
                    Hacked by Hacked

                    Hacked

                    190 Listeners

                    Security Now (Audio) by TWiT

                    Security Now (Audio)

                    2,007 Listeners

                    The Talk Show With John Gruber by Daring Fireball / John Gruber

                    The Talk Show With John Gruber

                    3,144 Listeners

                    Risky Business by Risky Business Media

                    Risky Business

                    376 Listeners

                    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                    649 Listeners

                    CyberWire Daily by N2K Networks

                    CyberWire Daily

                    1,027 Listeners

                    Smashing Security by Graham Cluley

                    Smashing Security

                    316 Listeners

                    Click Here by Recorded Future News

                    Click Here

                    422 Listeners

                    Darknet Diaries by Jack Rhysider

                    Darknet Diaries

                    8,052 Listeners

                    Cybersecurity Today by Jim Love

                    Cybersecurity Today

                    179 Listeners

                    Hacking Humans by N2K Networks

                    Hacking Humans

                    314 Listeners

                    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                    CISO Series Podcast

                    191 Listeners

                    Cybersecurity Headlines by CISO Series

                    Cybersecurity Headlines

                    136 Listeners

                    Cyber Hack by BBC World Service

                    Cyber Hack

                    1,598 Listeners

                    Risky Bulletin by Risky Business Media

                    Risky Bulletin

                    45 Listeners