The Hidden Risk in Your Stack

The Hidden Risk in Your Stack

In this episode of Data Security Decoded, host Caleb Tolin sits down with Hayden Smith, CEO of Hunted Labs, as he breaks down how software supply chain attacks really work, why open source dependencies create unseen exposure, and what modern threat actors are doing to exploit trust at scale. Caleb and Hayden dive deep into real-world attacks, emerging TTPs, AI-powered threat hunting, and what organizations must do today to keep pace. Listeners walk away with a clear picture of the problem—and a practical blueprint for reducing supply chain risk. What You’ll Learn How modern attackers infiltrate open source ecosystems through fake accounts and counterfeit package contributions. Why dependency chains dramatically amplify both exposure and attacker leverage. How to use threat intelligence and threat hunting to proactively evaluate upstream packages before adoption. Where AI-powered code analysis is changing the ability to discover hidden vulnerabilities and suspicious patterns. Why dependency pinning, SBOM discipline, and continuous monitoring now define a strong supply chain posture. Episode Highlights 00:00 — Welcome + Why Software Supply Chain Risk Matters 02:00 — Hayden’s Non-Cyber Passion + Framing Today’s Topic 03:00 — Why Open Source Powers Everything—and Why That Creates Exposure 06:00 — The Real Attack Vector: Contribution as Initial Access 08:00 — Inside the Indonesian “Fake Package” Campaign 10:30 — How to Evaluate Code + Contributor Identity Together 12:00 — Threat Hunting and AI-Enabled Code Interrogation 15:00 — The Challenge of Undisclosed Vulnerabilities in Widely Used Components 16:30 — How Recovery Works When Malware Is Already in Your Stack 19:00 — Continuous Monitoring as the Foundation of Modern Supply Chain Security 22:00 — Pinning, Maintainer Analysis, and Code Interrogation Best Practices 24:00 — Where to Learn More About Hunted Labs Episode Resources Hunted Labs — https://huntedlabs.com Hunted Labs Entercept Hunted Labs “Hunting Ground” research blog Open Source Malware (Paul McCarty)

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(65)

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

Please enjoy this encore of Data Security Decoded. In this episode, host⁠⁠ ⁠Caleb Tolin⁠⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous cri...

15 Sep 29min

Agentic AI and Identity Sprawl

Agentic AI and Identity Sprawl

Please enjoy this encore of Data Security Decoded. In this episode of ⁠Data Security Decoded⁠, join host ⁠Caleb Tolin⁠ as he welcomes back ⁠Joe Hladik⁠, Head of Rubrik Zero Labs, to unpack the findi...

8 Sep 24min

AI Moves Fast. Privacy Has to Move Faster.

AI Moves Fast. Privacy Has to Move Faster.

Enjoy this encore of Data Security Decoded. AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, ⁠Caleb Tolin⁠...

25 Aug 25min

The Real Risks of Agentic AI in the Enterprise

The Real Risks of Agentic AI in the Enterprise

Please enjoy this encore of Data Security Decoded. As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, ho...

18 Aug 27min

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Please enjoy this encore of Data Security Decoded. Welcome to ⁠Data Security Decoded⁠. Join host ⁠Caleb Tolin⁠ in conversation with ⁠Morgan Adamski⁠ who leads Cyber, Data, and Tech Risk at PwC and i...

11 Aug 23min

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The disc...

28 Jul 17min

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of tec...

21 Jul 29min

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

This episode provides a technical exploration of security engineering within highly scrutinized life sciences environments, drawing on Andy Hillis' decades of operational history at The Almac Group. T...

14 Jul 34min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
rss-pa-konto
rss-skravla-gar
pengepodden-2
livet-pa-veien-med-jan-erik-larssen
lederpodden
finansredaksjonen
tid-er-penger-en-podcast-med-peter-warren
stormkast-med-valebrokk-stordalen
rss-orjasater
pengesnakk
morgenkaffen-med-finansavisen
liberal-halvtime
utbytte
okonomiamatorene
rss-markedspuls-2