Skip to content

Podcasts/Best episodes

Best podcast episodes on supply chain attacks

From NotPetya and SolarWinds to XZ Utils, npm worms and poisoned GitHub Actions: the episodes that explain how attackers get in through the software and services you trust.

10 episodes from 9 shows. Dates and lengths are from each show's own feed.

  1. 01

    Malicious Life

    NotPetya Part 1

    · 33 min · Beginner

    The classic case: a poisoned accounting-software update that became the costliest cyberattack yet.

  2. 02

    Crying Out Cloud

    CROC News - XZ Utils backdoor explained

    · 13 min · Beginner

    A 13-minute breakdown of the XZ Utils backdoor, the defining open source social engineering case.

  3. 03

    Open Source Security

    Detecting XZ in Debian with Otto Kekäläinen

    · 32 min · Practitioner

    A Debian packager explains why the XZ backdoor was nearly impossible to detect from the distribution side.

  4. 04

    Open Source Security

    tj-actions with Endor Lab's Dimitri Stiliadis

    · 33 min · Practitioner

    A clear walk through the tj-actions GitHub Action compromise and why CI/CD secrets are the target.

  5. 05

    CISO Tradecraft

    #246 - Tim Brown on SolarWinds: What Every CISO Should Know

    · 44 min · Practitioner

    SolarWinds' own CISO on the SVR intrusion timeline and the SEC case that followed.

  6. 06

    Cloud Security Podcast by Google

    EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security

    · 27 min · Practitioner

    Chainguard's Dan Lorenc on the Trivy to LiteLLM chain and why version pinning still gets skipped.

  7. 07

    Risky Business

    Risky Business #805 -- On the Salesloft Drift breach and OAuth soup

    · 62 min · Practitioner

    The Salesloft Drift breach and why connected OAuth apps became a supply chain problem.

  8. 08

    The Defender's Advantage Podcast

    The New Frontline of Supply Chain Attacks

    · 33 min · Practitioner

    Google threat intelligence on how supply chain compromise is shifting, from responders who work the cases.

  9. 09

    Research Saturday

    A subtle flaw, a massive blast radius.

    · 17 min · Expert

    Wiz on CodeBreach, a CI/CD flaw that put AWS's own GitHub repositories at risk.

  10. 10

    Three Buddy Problem

    Lazarus ByBit $1.4B heist was supply chain attack on developer

    · 113 min · Expert

    The largest crypto theft on record began with a compromised developer machine; the panel unpacks how.