Best podcast episodes on supply chain attacks
From NotPetya and SolarWinds to XZ Utils, npm worms and poisoned GitHub Actions: the episodes that explain how attackers get in through the software and services you trust.
10 episodes from 9 shows. Dates and lengths are from each show's own feed.
- 01
· 33 min · Beginner
The classic case: a poisoned accounting-software update that became the costliest cyberattack yet.
- 02
CROC News - XZ Utils backdoor explained
· 13 min · Beginner
A 13-minute breakdown of the XZ Utils backdoor, the defining open source social engineering case.
- 03
Detecting XZ in Debian with Otto Kekäläinen
· 32 min · Practitioner
A Debian packager explains why the XZ backdoor was nearly impossible to detect from the distribution side.
- 04
tj-actions with Endor Lab's Dimitri Stiliadis
· 33 min · Practitioner
A clear walk through the tj-actions GitHub Action compromise and why CI/CD secrets are the target.
- 05
#246 - Tim Brown on SolarWinds: What Every CISO Should Know
· 44 min · Practitioner
SolarWinds' own CISO on the SVR intrusion timeline and the SEC case that followed.
- 06
Cloud Security Podcast by Google
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security
· 27 min · Practitioner
Chainguard's Dan Lorenc on the Trivy to LiteLLM chain and why version pinning still gets skipped.
- 07
Risky Business #805 -- On the Salesloft Drift breach and OAuth soup
· 62 min · Practitioner
The Salesloft Drift breach and why connected OAuth apps became a supply chain problem.
- 08
The Defender's Advantage Podcast
The New Frontline of Supply Chain Attacks
· 33 min · Practitioner
Google threat intelligence on how supply chain compromise is shifting, from responders who work the cases.
- 09
A subtle flaw, a massive blast radius.
· 17 min · Expert
Wiz on CodeBreach, a CI/CD flaw that put AWS's own GitHub repositories at risk.
- 10
Lazarus ByBit $1.4B heist was supply chain attack on developer
· 113 min · Expert
The largest crypto theft on record began with a compromised developer machine; the panel unpacks how.