
Hosted by Richard Campbell
Listed under Technology, Business › Careers
★4.0on Apple Podcasts · 9 recent reviews
RunAs Radio is a weekly Internet Audio Talk Show for IT Professionals working with Microsoft products.
1049 episodes · publishes weekly · latest 2026-08-12 · ~38 min/episode
Rank
#65
Substance
81.5
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#65 of 1566
Substance
Top 4%
outscores 96% of the index
RunAs Radio ranks #65 on The B2B Podcast Index with a substance score of 81.5 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and insight density. Mackenzie Jackson is an active practitioner at an operational appsec company that detects thousands of malicious packages monthly and ships real tooling (Safe Chain), giving him genuine ground-level authority; he is not a pure thought-leader, though his role is more field evangelist than deeply technical researcher at scale.
Averaged across 2 recently scored episodes, with cited evidence.
The episode contains several genuinely non-obvious technical insights - mutable GitHub Actions tags as a retroactive attack vector, Shahlud worms leveraging on-device LLMs for reconnaissance, and Claw Hub skill poisoning - but is diluted by stretches of general security culture commentary and arms-race platitudes.
“the first version of that actually compromised uh, the package called nx. Uh, this is last year. And uh, how the malware operated, uh, is that when the malware ran, it actually looked for an LLM on the victim's machine and used it to do the reconnaissance”
“in GitHub Actions there's something called immutable tags...I can't go back and release version 1.9 again...GitHub Actions. You can. Oh, you can change the tag”
The framing of 'malicious intent is the only remaining barrier' and the 48-hour cooldown as a concrete, free mitigation are fresh and useful; the fog-of-war theory around publishing stolen credentials is genuinely interesting, but the episode also leans on standard 'arms race' and 'assume breach' framing that is well-worn in security podcasts.
“The resources and the technical ability are basically zero now. And you just are left with malicious intent”
“enforce a 48 hour cooldown period before installing any new package...If you do that, 99% of malware won't touch you”
Mackenzie Jackson is an active practitioner at an operational appsec company that detects thousands of malicious packages monthly and ships real tooling (Safe Chain), giving him genuine ground-level authority; he is not a pure thought-leader, though his role is more field evangelist than deeply technical researcher at scale.
“at Akita, we obviously have a big research team where we detect a lot of malware. We find thousands of packages every month”
“we still use rule based detection to find indicators of malware...and then use an LLM to make a final classification”
The episode is well-stocked with named artifacts, specific timelines, and concrete mechanisms - the Trivy breach, Shahlud worm variants, Josh Junon's 2.6 billion weekly downloads, the sub-30-minute VS Code extension window, and Claw Hub's top-10 contamination rate - though a few quantitative claims like '99%' are asserted without sourcing.
“he is the maintainer of, uh, several massive projects collectively downloaded 2.6 billion times a week”
“it was compromised for less than half an hour. But just in that time...one, in that window someone from GitHub installed it and then all of their code was stolen”
Richard Campbell is a capable host who steers toward actionable advice and makes useful analogical connections (conditional access scoring paralleling malware heuristics), but he rarely challenges the guest's assertions, sometimes talks at equal length to the guest, and the conversation stays collegial rather than probing.
“I'm hoping we get to a place here, McKenzie, where it's like, here's some things you can do. Because so far we've outlined all the things you should be afraid of”
“That Sounds like something GitHub could fix or at least set a parameter around. Like this is all exotic behavior”
2 periods tracked.
2 scored on substance · 66 tracked in total.
Always enjoy listening to Richard talk about the more nuanced areas of Windows in detail - the guests are always the best. I was a bit surprised to see him taking flack in an 8-year-old review concerning use of “corporate gal” in a sentence…iirc, that’s the “Corporate Global Address List,” not gender slang :-)
- ^Drag0n^
RunAs radio is full of great high quality content for mainly Windows admins and engineers. I also greatly appreciate the fantastic audio quality.
- Josh Duffney
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/runas-radio" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/runas-radio/badge.svg" alt="Ranked #5 on The B2B Podcast Index" width="360" height="136" />
</a>Track RunAs Radio's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.