Only Malware in the Building

Trusting the wrong package.


Listen Later

Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠.

Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves.

Sources: 

Shai-Hulud worm returns stronger and more automated than ever before

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing

Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

...more
View all episodesView all episodes
Download on the App Store

Only Malware in the BuildingBy DISCARDED | N2K Networks

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

9 ratings


More shows like Only Malware in the Building

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

228,224 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,876 Listeners

Hacked by Hacked

Hacked

188 Listeners

BSD Now by JT Pennington

BSD Now

91 Listeners

Grumpy Old Geeks by Jason DeFillippo & Brian Schulmeister with Dave Bittner

Grumpy Old Geeks

6,030 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,026 Listeners

Smashing Security by Graham Cluley

Smashing Security

316 Listeners

The Daily by The New York Times

The Daily

112,191 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,542 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,049 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Hard Fork by The New York Times

Hard Fork

5,544 Listeners

DISCARDED: Tales From the Threat Research Trenches by Proofpoint

DISCARDED: Tales From the Threat Research Trenches

55 Listeners