Explore every episode of the podcast DevSec Station
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Emergency DevSec Station drop: NPM Worm in the Wild | 22 Apr 2026 | 00:02:29 | |
🚨 Emergency DevSec Station drop. | |||
| The Anatomy of a Modern Supply Chain Attack | 14 Apr 2026 | 00:10:14 | |
What if a supply chain attack didn’t start with a sophisticated exploit… but with something totally normal? A typo. In this episode, Tanya Janca walks through how modern supply chain attacks actually happen, and why they’re less about “elite hackers” and more about everyday developer workflows. You’ll learn why these attacks are not a single event, but a sequence of small, reasonable decisions that quietly introduce risk into our systems. What You’ll Learn
A Realistic Attack, Step by Step This episode walks through a common pattern seen in real-world incidents:
Bad / Better / Best: Managing Supply Chain Risk Bad: Ignore supply chain risk or abandon tools due to noise If You Do Just One Thing This Week Run an SCA tool with reachability enabled, and take action on one issue.
You don’t need to fix everything. But you do need to start. 🚉 About DevSec Station DevSec Station is a security-focused podcast for developers. Please like and subscribe. Hosted by Tanya Janca | SheHacksPurple | |||
| Developers Are Targets Now | 21 Mar 2026 | 00:06:01 | |
Welcome to DevSec Station! I’m Tanya Janca (AKA SheHacksPurple), and this podcast is a series of short, practical security lessons for software developers. In this episode we will learn how supply chain attacks unfold in the wild, how to spot potential problems in your own workflows, and what you can do to protect yourself without slowing down too much. | |||