DevSec Station

DevSec Station

Tanya Janca | SheHacksPurple
Страна США
Язык EN-US
Эпизодов 5
Последний 29.07.2026

DevSec Station is a security focused podcast for software developers who want to create amazing applications. Hosted by Tanya Janca, also known as SheHacksPurple, these short lessons will help you level up.

Эпизоды

  • Secure Defaults Beat Secure Training 29.07.2026 6мин
    Security training has its place. But if training alone solved security problems, we wouldn't keep seeing the same vulnerabilities appear over and over again. The real problem usually isn't that developers don't know what to do; it's that the easiest path is often an insecure one. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why secure defaults are one of the most effective security controls you can implement, why relying on memory and willpower ra...
  • Why Current Security Tools Fail Developers 15.07.2026 6мин
    Security tools are supposed to help developers build safer software. But sometimes it seems like they create more frustration than security. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why many security tools overwhelm developers with alerts, how alert fatigue erodes trust, and why "more findings" doesn't mean "more security." You'll learn how to tune your classic AppSec tools so they surface meaningful issues instead of creating noise that every...
  • Vibe Coding, Copilots, and Security Drift 01.07.2026 7мин
    AI coding assistants can help developers move incredibly fast. But this new speed comes with a new challenge: security drift. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explores how tools like GitHub Copilot, ChatGPT, Cursor, and other AI coding assistants can unintentionally change the security assumptions your software was built on. You'll learn what security drift is, why it happens so quietly, and how to keep the benefits of AI-assisted development w...
  • Secrets Management: Stop Playing Whack-a-Mole 17.06.2026 7мин
    If you've ever committed an API key, password, token, certificate, or other secret to a repository, you're not alone. Most secret leaks don't happen because developers don't care about security. They happen because the easiest place to put a secret is inside the code that uses it. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why secrets leak, why "just be careful" isn't an effective security strategy, and how developers can stop playing whack-a-mo...
  • Supply Chain Is More Than Just Dependencies 04.06.2026 7мин
    Most developers think software supply chain security starts and ends with dependencies. But modern supply chain attacks don't stop there. Attackers look for paths into your software, and those paths often run through developers, CI/CD systems, build tools, deployment pipelines, and other trusted parts of the software delivery process. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why the software supply chain is much bigger than libraries and pac...
  • Malicious Dependencies Aren’t an Accident 20.05.2026 7мин
    Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials. This episode is sponsored by Maze. You’ll learn: • how malicious packages trick developers • why dependency attacks work...
  • NPM Supply Chain Attack: Active Worm Stealing Tokens, SSH Keys, and Credentials 22.04.2026 2мин
    🚨 Emergency DevSec Station update. There’s an active npm supply chain attack happening right now. Malicious npm packages are running install scripts that quietly steal: • SSH keys • AWS credentials • GitHub tokens • Browser passwords • Crypto wallets From there, the attack uses your npm publish token to spread into every package you maintain. That’s how this turns into a worm across the npm ecosystem. This is not theoretical. It’s already in the wild. 👉 Immediate...
  • How Modern Supply Chain Attacks Really Happen (Step-by-Step Breakdown for Developers) 14.04.2026 10мин
    What if a supply chain attack didn’t start with a complex exploit… but something completely normal? A typo. A copy-paste. Even an AI suggestion. In this episode, Tanya Janca breaks down how modern supply chain attacks actually happen inside everyday developer workflows. These attacks aren’t one big moment. They’re a series of small, reasonable decisions that quietly introduce risk. You’ll learn: • Why supply chain attacks are a process, not a single event • How attacke...
  • Developers Are Now Targets: How Supply Chain Attacks Actually Reach You 21.03.2026 6мин
    Developers are no longer just building software. They’re being targeted directly. In this episode, Tanya Janca explains how supply chain attacks reach developers through everyday tools, packages, and workflows. These attacks don’t feel like attacks at first. They look like normal development work until it’s too late. You’ll learn: • How supply chain attacks reach individual developers • Why developer environments are now high-value targets • Where risk shows up in dail...

Популярен в

Этот подкаст также попадал в подкаст-чарты этих стран.