The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Simply Defensive
Simply Defensive artwork

Coffee Is Your Top Supply Chain Risk: A Conversation with Kyle Kelly

Simply Defensive · 2025-07-21 · 29 min

0:00--:--

Topics in this episode

Cybersecurityblue teamInformation security

Episode notes

SOC analysts, detection engineers, and pentesters - you’re not imagining it: software supply chain security is a dumpster fire . In this episode of Simply Defensive, we sit down with Kyle Kelly, engineering manager at GitHub and author of Crime Hacks, to unpack the chaos. We cover: - Why malicious packages are sneaking past defenders - The truth about SBOMs (and what most orgs are doing wrong) - How to spot typo-squatting and backdoored build scripts - What defenders can do - even if you're not building the code - Why “just NPM install” is more dangerous than you think From transitive dependencies to the hidden power of private package repositories, this episode is packed with practical insights, hilarious stories, and advice every blue teamer needs. Episode Links: Kyle’s blog: ‍ Kyle on LinkedIn: Crime Hacks on LinkedIn: ========================= Sponsored by ThreatLocker - Free 30-day trial of ThreatLocker =========================

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on Cybersecurity89 / 100
  • Mastercard CEO: AI Shopping Agents, Machine-to-Machine Payments, and the New Infrastructure of CommerceMotley Fool Hidden Gems Investing · on Cybersecurity88 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on Cybersecurity79 / 100
  • Moving from Product Partnerships to Revenue: Jira Cooley on Owning the NumberBetween Product and Partnerships · on Cybersecurity76 / 100
  • Pipeline Gives Permission to Invest Big on Brand with Jennifer JohnsonThe B2B CMO Podcast with Jon Miller and Sydney Sloan · on Cybersecurity74 / 100
  • S5E4: Authenticity Over 'Fake It': Lessons in Leadership and Life with Reese GiffordProductly Speaking: Real Stories for Product Managers · on Cybersecurity65 / 100

More from Simply Defensive

All episodes →
  • S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career Growth51 / 100
  • S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hired in Cybersecurity75 / 100
  • From Blue Team Challenges to AI Innovations: A Conversation with Jason Haddix91 / 100
  • From Pre-Law to FLARE: How Josh Stroschein Became Google's Malware Analyst86 / 100
  • Building Zero Trust Tools: Inside ThreatLocker with Product Manager Yuriy Tsibere
Explore the best B2B Engineering & DevTools podcasts →
All Simply Defensive episodes →