
Sign up to save your podcasts
Or


Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx
In this episode of the Security Repo Podcast, François Proulx, VP of Security Research at Boost Security, discusses the evolving threats in software supply chain security, particularly focusing on attacks targeting CI/CD pipelines. He explains how open source tools like "Poutine" are being used both defensively and offensively in the ongoing battle to secure build systems. François also shares his journey into security, lessons from working at Intel, and practical advice on dependency pinning, short-lived credentials, and password best practices.
https://www.linkedin.com/in/francoisp/
https://boostsecurity.io/blog/unveiling-poutine-an-open-source-build-pipelines-security-scanner
[https://nsec.io /](https://nsec.io/)
François is VP of Security Research at BoostSecurity, where he leads the Supply Chain research team. With over 10 years of experience in building AppSec programs for large corporations (such as Intel) and small startups he has been in the heat of the action as the DevSecOps movement took shape. François is one of founders of NorthSec and was a challenge designer for the NorthSec CTF.
In this episode of the Security Repo Podcast, we welcome Srajan Gupta, a security engineer exploring the evolving security implications of Model Context Protocol (MCP) servers. Shrojan breaks down how MCPs act as AI connectors to external systems and the alarming rise in attack surfaces, including tool squatting and indirect prompt injections. The conversation dives into emerging threats, authorization challenges, and how securing MCPs mirrors early API and cloud security lessons.
Srajan Gupta is a security engineer and builder focused on uncovering how systems fail — not just through vulnerabilities, but through the architecture itself. With a background in application security, platform engineering, and threat modeling, Srajan works at the intersection of usability and risk, helping teams identify and address design-level security flaws before they become incidents.
Srajan is passionate about building practical security tools, automating guardrails, and making threat modeling an everyday engineering skill.
Blog - https://srajangupta.substack.com/
BSides LV talk - https://www.youtube.com/watch?v=Wld0VVRMN4c&t=21977s
https://www.linkedin.com/in/srajan-gupta/
Their research often explores trust boundaries, secure defaults, and the hidden assumptions baked into the applications and infrastructure. They are especially interested in how attackers exploit the gray areas between platforms, automation, and access controls — and how defenders can close those gaps without slowing down delivery.
In this episode of the Security Repo Podcast, we sit down with Matt Torbin to explore his inspiring journey from jazz musician to cybersecurity advocate and leader. We dive deep into the origins and impact of Day of Shecurity, a one-day conference aimed at increasing representation and mentorship for women and non-binary individuals in infosec. Matt also shares innovative ideas around fixing the broken technical interview process, mentorship, and his passion for building inclusive, opportunity-rich communities in cybersecurity.Day of Shecurity:https://securediversity.org/dos/Matt's talk from BSidesLV: “Your Interview Game is Weak: Gamifying Technical Interviews through Role-Playing” https://www.youtube.com/watch?v=3Ih-ul9qe3E&t=14985sLearn more about Fabric: https://github.com/danielmiessler/fabricMatt Torbin has been a driving force in secure software development for over 20 years, influencing all aspects of the software development lifecycle. He began his career as a full-stack engineer with a focus on UI/UX, creating user experiences for renowned brands including the Philadelphia Inquirer, Anthropologie, and VEVO, engaging millions of users.In the last several years, Matt has shifted his focus to information security. In his current role as the Manager of Application Security at Quanata, he collaborates closely with product and engineering teams to advance product security best practices and deliver comprehensive security training. His industry contributions span public speaking, authorship, and community involvement. He has presented at conferences such as DEF CON, BSidesLV, and Day of Shecurity (DoS), authored privacy articles for 2600 Magazine: The Hacker Quarterly, and held key volunteer roles in initiatives including the Packet Hacking Village, Day of Shecurity, and BSidesSF. Among his achievements, he co-founded the DoS conference, realizing his vision for a more inclusive event.Outside of work, Matt mentors emerging professionals in the DoS community. A passionate skateboarder and longboarder, he often spends time with his son at skate parks throughout the San Francisco Bay Area.
In this episode of the Security Repo Podcast, we chat with Alyssa Miles, a product marketing leader at CyberArk, about building authentic developer communities in the security space. She shares her journey from agency marketing to driving developer engagement, along with insights from Hacker Summer Camp and strategies for enabling community-driven identity tooling. Alyssa also discusses how to shift from traditional marketing to true enablement and why "thinking like a hacker" is key to building impactful security communities.https://lp.cyberark.com/20251110-cyberark-workload-identity-day-zero-atlanta-registration.htmlhttps://www.linkedin.com/in/alyssanoellemiles/https://infocondb.org/con/def-con/def-con-33/thinking-like-a-hacker-in-the-age-of-aiAlyssa is a product marketing leader passionate about making security easy for developers. At CyberArk, she drives developer experience initiatives that help platform engineers, DevOps teams, and cloud security pros adopt identity tools that fit naturally into their workflows. She also leads efforts to grow and engage CyberArk’s developer community. When she's not working, she's probably driving her ten-year-old daughter to ballet or hanging out at a brewery.
In this episode of the Security Repo Podcast, Aria Langer returns to share deep insights from her work in privileged access management and the challenges of implementing security controls without alienating coworkers. She and Dwayne dive into the often-overlooked importance of empathy in cybersecurity, exploring how human connection can make security efforts more effective. The conversation touches on the cultural shifts needed in security teams, how storytelling can foster understanding, and the risks of relying too heavily on tools like AI without understanding their underlying mechanics.
What you need to know about AriaDear is that she’s a Security Engineer by day, DuckBurg resident by night!
Been working in SecOps for almost 5 years, specializing in Privilege Access Management
Have spoken at BlueTeamCon, ChibrrCon and the Defcon Furs village on that topic.
In this episode of the Security Repo Podcast, we chat with Jake Hildreth, Principal Security Consultant at Semperis, about the enduring challenges of securing Active Directory in a hybrid cloud world. Jake shares war stories from the field, including dangerously misconfigured environments and the real-world impacts of legacy systems. We also explore practical advice for defenders, including the critical importance of identifying and protecting Tier Zero assets.https://linktr.ee/jakehildrethhttps://www.linkedin.com/in/jakehildreth/Jake Hildreth is a dedicated husband, fun-loving father, and seasoned IT professional with nearly 25 years of experience. As Principal Security Consultant at Semperis, Jake helps organizations fortify their digital defenses against Active Directory incursions. His open-source tools (Locksmith, BlueTuxedo, and PowerPUG!) are designed to lighten the load for overworked AD administrators by making security more accessible and manageable. Jake’s expertise is further underscored by his CISSP certification and Microsoft MVP status, which serve as testaments to his wide base of knowledge and commitment to cybersecurity excellence.
In this episode of the Security Repo Podcast, Andre Van Klaveren talks about his decades-long journey through IT, software development, and application security, culminating in the reboot of the OWASP St. Louis chapter. They discuss the history and importance of OWASP, community building in a post-pandemic world, and how risk-based thinking and strong fundamentals drive effective security practices. Andre also shares practical advice for anyone curious about joining a security meetup and the significance of influencing positive change within teams.https://owasp.org/www-chapter-saint-louis/We organize our meetups on Meetup.com:https://www.meetup.com/owasp-saint-louis-chapter/https://www.linkedin.com/in/andrevanklaveren/Andre is a seasoned technologist who has spent more than 30 years in the trenches of IT, software development, and architecture. For the past 15 years, he's been laser-focused on application security - finding and fixing the vulnerabilities before they become problems. He’s passionate about building secure software and loves connecting with others in the security community to share ideas.Outside of work, Andre has what his wife calls 'way too many hobbies,' but you can usually find him either tinkering with a new IoT project, talking on his ham radio, or getting lost in the great outdoors.
In this episode of the Security Repo Podcast, Jenn Gile shares insights from her hands-on security education at DEF CON's AppSec Village, where she ran a wildly successful lottery-style dependency upgrade game. She discusses the challenges developers face with remediation, the importance of empathy in AppSec, and how gamified, tangible learning experiences can bridge gaps between dev and security teams. The episode also explores how community engagement and inclusive learning can strengthen security culture.https://www.linkedin.com/in/jenngile/Jenn Gile is a tech educator and community builder with experience in AppSec, DevOps, and national security spaces. She’s a frequent speaker at security meetups and conferences, a prolific writer, and is the host of LeanAppSec - a free educational program that helps AppSec professionals be more effective without getting bigger budgets. Jenn is currently Head of Community at Endor Labs, and previously worked at F5, NGINX, and the U.S. Department of State. Outside of work, Jenn is deeply involved in the cycling community as a board member for 2nd Cycle.
In this episode of the Security Repo Podcast, Narayan Ram Narayanan shares his journey into cybersecurity, sparked by a personal data breach and fueled by a passion for privacy and secure development. He discusses his upcoming talk on threat modeling OpenSSL applications using STRIDE and other threat models, and highlights the value of volunteering and networking at events like BSides. The conversation also explores lessons from past mistakes, favorite security tools, and advice for newcomers in the field.Links mentioned in this episodehttps://nixos.org/guides/nix-pills/10-developing-with-nix-shell.htmlhttps://asciinema.org/https://www.linkedin.com/in/n2r/Narayan Ram Narayanan is passionate about Linux, cryptography, and secure SDLC. He loves digging into code, threat modeling, and breaking things (responsibly). Whether it’s hardening apps or decoding exploits. He’s all about making software safer - one commit at a time.
In this episode of the Security Repo Podcast, Sean Juroviesky joins us to share their journey through cybersecurity, from finding community in BurbSec to giving talks at major conferences like DEF CON and BlueTeamCon. Sean dives deep into the realities of risk management, executive sign-off processes, and the critical importance of understanding business impact. The conversation also touches on the necessity of building cross-functional relationships and documenting everything to make informed, actionable security decisions.https://burbsec.com/Sean Juroviesky is a dedicated cybersecurity, risk management, and privacy advocate, speaking on those topics at conferences across the world, including DEF CON, CypherCon, CornCon, BSides Rochester, SecretCon, Sec-T, and more. Sean also acts as a cybersecurity architect for a large music streaming provider. Beyond their professional pursuits, Sean finds joy in backpacking through the mountains with their adventurous Australian Shepherd, partner, and twins, embracing the serenity of nature and the thrill of exploration.
From the publisher's feed