Coffee, Chaos and ProdSec
🎙️ Coffee, Chaos and ProdSec [https://linktr.ee/coffeechaosprodsec], Ep 40 Less than 5% of CVEs are actually exploitable. One hundred percent of malicious packages are bad by design. So why is your entire AppSec budget chasing the first problem? This week Cameron [https://www.linkedin.com/in/cameronww7]and Kurt [https://www.linkedin.com/in/kurthendle] bring on Paul McCarty and Jenn Gile, co-founders of OpenSourceMalware, to break down why the open source malware problem is structurally different from vulnerability management, why your EDR and SCA tooling weren't built for it, and why 78% of what OSM tracks has zero attribution because most threat actors aren't TeamPCP screaming for clout. They're quiet, they're patient, and they're already on your developer machines. From AI slop squatting and four to five net new info stealers per day, to credential-stuffed dev machines, non-deterministic agents bypassing guardrails, and DPRK making $2 billion while everyone watches TeamPCP, this one covers the threat class that most programs still don't have a budget line for. If you work in AppSec, DevSecOps, or Product Security and your malware response plan is "covered by SCA," this episode is going to be uncomfortable. ☕ New episodes every Wednesday. Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
41 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Coffee, Chaos and ProdSec!