
Sign up to save your podcasts
Or


A silent compromise, nearly a million developers affected, and no one at Amazon knew for six days. In this episode of Cyberside Chats, we’re diving into the Amazon Q AI Hack, a shocking example of how vulnerable our software development tools have become.
Join hosts Sherri Davidoff and Matt Durrin as they unpack how a misconfigured GitHub token allowed a hacker to inject destructive AI commands into a popular developer tool. We’ll walk through exactly what happened, how GitHub security missteps enabled the attack, and why this incident is a critical wake-up call for supply chain security and AI tool governance.
We’ll also spotlight other supply chain breaches like the SolarWinds Orion backdoor and XZ Utils compromise, plus AI tool mishaps where “helpful” assistants caused real-world damage. If your organization uses AI developer tools—or works with third-party software vendors—this episode is a must-listen.
Key Takeaways:
▪ Ask Your Software Vendors About Their Supply Chain Security
▪ Hold Vendors Accountable for Secure Development Practices
▪ Be Wary of Giving AI Assistants Too Much Access
▪ Prepare to Hear About Breaches From the Outside
▪ If You Develop Code Internally, Lock Down Your Build Pipeline
By Chatcyberside5
22 ratings
A silent compromise, nearly a million developers affected, and no one at Amazon knew for six days. In this episode of Cyberside Chats, we’re diving into the Amazon Q AI Hack, a shocking example of how vulnerable our software development tools have become.
Join hosts Sherri Davidoff and Matt Durrin as they unpack how a misconfigured GitHub token allowed a hacker to inject destructive AI commands into a popular developer tool. We’ll walk through exactly what happened, how GitHub security missteps enabled the attack, and why this incident is a critical wake-up call for supply chain security and AI tool governance.
We’ll also spotlight other supply chain breaches like the SolarWinds Orion backdoor and XZ Utils compromise, plus AI tool mishaps where “helpful” assistants caused real-world damage. If your organization uses AI developer tools—or works with third-party software vendors—this episode is a must-listen.
Key Takeaways:
▪ Ask Your Software Vendors About Their Supply Chain Security
▪ Hold Vendors Accountable for Secure Development Practices
▪ Be Wary of Giving AI Assistants Too Much Access
▪ Prepare to Hear About Breaches From the Outside
▪ If You Develop Code Internally, Lock Down Your Build Pipeline

5,948 Listeners

370 Listeners

1,782 Listeners

2,041 Listeners

63 Listeners