DevSec Station is a security focused podcast for software developers who want to create amazing applications. Hosted by Tanya Janca, also known as SheHacksPurple, these short lessons will help you level up.
Security training has its place. But if training alone solved security problems, we wouldn't keep seeing the same vulnerabilities appear over and over again. The real problem usually isn't that developers don't know what to do; it's that the easiest path is often an insecure one.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca explains why secure defaults are one of the most effective security contro...
Security tools are supposed to help developers build safer software. But sometimes it seems like they create more frustration than security.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca explains why many security tools overwhelm developers with alerts, how alert fatigue erodes trust, and why "more findings" doesn't mean "more security." You'll learn how to tune your classic AppSec tools so they su...
AI coding assistants can help developers move incredibly fast. But this new speed comes with a new challenge: security drift.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca explores how tools like GitHub Copilot, ChatGPT, Cursor, and other AI coding assistants can unintentionally change the security assumptions your software was built on. You'll learn what security drift is, why it happens so quietl...
If you've ever committed an API key, password, token, certificate, or other secret to a repository, you're not alone. Most secret leaks don't happen because developers don't care about security. They happen because the easiest place to put a secret is inside the code that uses it.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca explains why secrets leak, why "just be careful" isn't an effective secur...
Most developers think software supply chain security starts and ends with dependencies. But modern supply chain attacks don't stop there. Attackers look for paths into your software, and those paths often run through developers, CI/CD systems, build tools, deployment pipelines, and other trusted parts of the software delivery process.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca ex...
Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials.
This episode is sponsored by Maze.
You’ll learn:
• ...
🚨 Emergency DevSec Station update.
There’s an active npm supply chain attack happening right now.
Malicious npm packages are running install scripts that quietly steal:
• SSH keys
• AWS credentials
• GitHub tokens
• Browser passwords
• Crypto wallets
From there, the attack uses your npm publish token to spread into every package you maintain. That’s how this turns into a worm a...
What if a supply chain attack didn’t start with a complex exploit… but something completely normal?
A typo.
A copy-paste.
Even an AI suggestion.
In this episode, Tanya Janca breaks down how modern supply chain attacks actually happen inside everyday developer workflows.
These attacks aren’t one big moment. They’re a series of small, reasonable decisions that quietly introduce risk.
You’l...
Developers are no longer just building software.
They’re being targeted directly.
In this episode, Tanya Janca explains how supply chain attacks reach developers through everyday tools, packages, and workflows.
These attacks don’t feel like attacks at first. They look like normal development work until it’s too late.
You’ll learn:
• How supply chain attacks reach individual developers
 ...
Hey Jonas! The official Jonas Brothers podcast. Hosted by Kevin, Joe, and Nick Jonas. It’s the Jonas Brothers you know... musicians, actors, and well, yes, brothers. Now, they’re sharing another side of themselves in the playful, intimate, and irreverent way only they can. Spend time with the Jonas Brothers here and stay a little bit longer for deep conversations like never before.
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com
Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.
The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!