Episode 298 - Shai Hulud, Layered Security, New Commandments of Security Teams

16/09/2025
Episode 298 - Shai Hulud, Layered Security, New Commandments of Security Teams

Listen "Episode 298 - Shai Hulud, Layered Security, New Commandments of Security Teams"

Episode Synopsis

In what is (sadly) becoming a weekly segment, this episode starts with talk of the latest installment of npm package takeovers, dubbed Shai Hulud as discussed in Slack and analyzed by Paul McCarty and team. Strategies discussed for monitoring packages and preventing malware from entering into organization's products. This is followed by an article referencing security via intentional redundancy when designing sensitive application functionality. Finally, analysis of a recent article from Frankly Speaking that lists a series of new commandments for security teams, which are mostly agreed to by both Seth and Ken, with some caveats.