DevSec Station

DevSec Station

DevSec Station is a security focused podcast for software developers who want to create amazing applications. Hosted by Tanya Janca, also known as SheHacksPurple, these short lessons will help you level up.

Episodes

September 9, 2026 7 mins

Threat modeling has a reputation for being complicated, full of diagrams, and requiring long meetings. In reality, most developers already do it, they just don't realize it. The difference is that doing it intentionally helps you catch security problems before they become security incidents.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca breaks threat modeling down into a simple five-step process th...

Listen
Watch
Mark as Played

Secure code review isn't about finding obscure vulnerabilities or thinking like an elite hacker. It's about verifying that the security controls your application depends on are actually present, in the right place, and correctly implemented.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explains how developers can perform effective secure code reviews without being security experts. You'll learn wh...

Listen
Watch
Mark as Played

Security bugs aren't usually caused by 'bad developers'. More often, they're the result of good developers making rational decisions under deadlines, competing priorities, and imperfect systems.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explores why common secure coding mistakes are often incentive problems rather than knowledge problems. You'll learn why insecure patterns emerge, why simply te...

Listen
Watch
Mark as Played
July 29, 2026 6 mins

Security training has its place. But if training alone solved security problems, we wouldn't keep seeing the same vulnerabilities appear over and over again. The real problem usually isn't that developers don't know what to do; it's that the easiest path is often an insecure one.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explains why secure defaults are one of the most effective security contro...

Listen
Watch
Mark as Played

Security tools are supposed to help developers build safer software. But sometimes it seems like they create more frustration than security.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explains why many security tools overwhelm developers with alerts, how alert fatigue erodes trust, and why "more findings" doesn't mean "more security." You'll learn how to tune your classic AppSec tools so they su...

Listen
Watch
Mark as Played

AI coding assistants can help developers move incredibly fast. But this new speed comes with a new challenge: security drift.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explores how tools like GitHub Copilot, ChatGPT, Cursor, and other AI coding assistants can unintentionally change the security assumptions your software was built on. You'll learn what security drift is, why it happens so quietl...

Listen
Watch
Mark as Played

If you've ever committed an API key, password, token, certificate, or other secret to a repository, you're not alone. Most secret leaks don't happen because developers don't care about security. They happen because the easiest place to put a secret is inside the code that uses it.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca explains why secrets leak, why "just be careful" isn't an effective secur...

Listen
Watch
Mark as Played

Most developers think software supply chain security starts and ends with dependencies. But modern supply chain attacks don't stop there. Attackers look for paths into your software, and those paths often run through developers, CI/CD systems, build tools, deployment pipelines, and other trusted parts of the software delivery process.

This episode is sponsored by Maze.

In this episode of DevSec Station, Tanya Janca ex...

Listen
Watch
Mark as Played

Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials. 

This episode is sponsored by Maze.

You’ll learn:
• ...

Listen
Watch
Mark as Played

🚨 Emergency DevSec Station update.

There’s an active npm supply chain attack happening right now.

Malicious npm packages are running install scripts that quietly steal:
 • SSH keys
 • AWS credentials
 • GitHub tokens
 • Browser passwords
 • Crypto wallets

From there, the attack uses your npm publish token to spread into every package you maintain. That’s how this turns into a worm a...

Listen
Watch
Mark as Played

What if a supply chain attack didn’t start with a complex exploit… but something completely normal?

A typo.
 A copy-paste.
 Even an AI suggestion.

In this episode, Tanya Janca breaks down how modern supply chain attacks actually happen inside everyday developer workflows.

These attacks aren’t one big moment. They’re a series of small, reasonable decisions that quietly introduce risk.

You’l...

Listen
Watch
Mark as Played

Developers are no longer just building software.
 They’re being targeted directly.

In this episode, Tanya Janca explains how supply chain attacks reach developers through everyday tools, packages, and workflows.

These attacks don’t feel like attacks at first. They look like normal development work until it’s too late.

You’ll learn:
 • How supply chain attacks reach individual developers
 ...

Listen
Watch
Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Crime Junkie

    Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by Audiochuck Media Company.

    NFL Daily with Gregg Rosenthal

    Gregg Rosenthal and a rotating crew of elite NFL Media co-hosts, including Patrick Claybon, Colleen Wolfe, Steve Wyche, Nick Shook and Jourdan Rodrigue of The Athletic get you caught up daily on all the NFL news and analysis you need to be smarter and funnier than your friends.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

    The Clay Travis and Buck Sexton Show

    The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices