Page de couverture de Bad Dependencies Episode 3: Malware, Bug Bounties, and the Ethics of Offense

Bad Dependencies Episode 3: Malware, Bug Bounties, and the Ethics of Offense

Bad Dependencies Episode 3: Malware, Bug Bounties, and the Ethics of Offense

Écouter gratuitement

Voir les détails du balado

À propos de cet audio

In this episode of Bad Dependencies, we explore the gray zone of offensive security with researcher Raphael Silva from Checkmarx. Hosts Mackenzie and Charlie break down June’s 4,000+ flagged malicious packages, then chat with Raphael about his real-world experiments planting “malicious-but-not” packages in places like npm and the VS Code Marketplace. From unicode deception to malware hidden in PNGs, this episode unpacks the ethics of bug bounties, the dangers of going too far, and how easy it is to slip past marketplace defenses—until a random security guy in Poland catches you first.00:00 – Intro & Weather Woes00:50 – Malware Madness: 4,000+ Packages Flagged02:00 – Offensive Security 10104:00 – The Ethics of Fake Malware06:00 – Where Researchers Cross the Line10:00 – Common Pitfalls & Accidental Exposure12:05 – Guest Joins: Raphael Silva from Checkmarx13:50 – Malicious-but-Not: ExpressJS-Session Deep Dive17:30 – Why Target VS Code Extensions?22:20 – Unicode Tricks, Copycats & What’s Next

Ce que les auditeurs disent de Bad Dependencies Episode 3: Malware, Bug Bounties, and the Ethics of Offense

Moyenne des évaluations de clients

Évaluations – Cliquez sur les onglets pour changer la source des évaluations.