🎙️ Coffee, Chaos and ProdSec, Ep 52

A CISO told Cameron security is feelings-oriented. Somewhere a nation state is quietly living inside your dependency tree and does not want you to notice.

This week Cameron and Kurt mark a full year of podcasting with Jenn Gile and Paul McCarty, co-founders of OpenSourceMalware, for a wide open conversation on the state of open source malware. It starts with a real fight over whether security runs on facts or feelings, then moves into the AppSec and SecOps divide, why npm's new install script defaults will get flipped back on by the same teams they were built to protect, and the actual mechanics behind PolinRider, the persistence campaign North Korea is running across GitHub and npm right now.

From Cameron and Paul going head to head on whether SBOMs are worth anything, to the reason most new malware is showing up written in Rust, to the open question of who is actually supposed to own malicious package response when it lands in your build, this episode covers the full stack of open source risk with zero vendor sympathy and one real on air disagreement.

If you work in Product Security, Application Security, DevSecOps, or Security Architecture and you have ever been handed an SBOM and asked what you are supposed to do with it, this one is for you.

☕ New episodes every Wednesday.

Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.

Podden och tillhörande omslagsbild på den här sidan tillhör Cameron Walters and Kurt Hendle. Innehållet i podden är skapat av Cameron Walters and Kurt Hendle och inte av, eller tillsammans med, Poddtoppen.