<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Wed, 22 Apr 2026 05:06:17 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Sbom”</title>
    <link>https://securityconversations.fireside.fm/tags/sbom</link>
    <pubDate>Wed, 02 Aug 2023 07:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>GitHub security chief Mike Hanley on secure coding, AI and SBOMs</title>
  <link>http://securityconversations.fireside.fm/mike-hanley-github</link>
  <guid isPermaLink="false">7532f1bd-4ebc-404a-9553-2f3339cc005f</guid>
  <pubDate>Wed, 02 Aug 2023 07:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7532f1bd-4ebc-404a-9553-2f3339cc005f.mp3" length="43779417" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly (https://binarly.io)
- FwHunt (https://fwhunt.run)

GitHub security chief Mike Hanley joins the show to discuss merging the CSO and SVP/Engineering roles, securing data and code in an organization under constant attack, the thrilling promise of AI to the future of secure code, the dangers of equating SBOMs to supply chain security, and new SEC reporting rules for CISOs.</itunes:subtitle>
  <itunes:duration>40:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7532f1bd-4ebc-404a-9553-2f3339cc005f/cover.jpg?v=3"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
GitHub security chief Mike Hanley joins the show to discuss merging the CSO and SVP/Engineering roles, securing data and code in an organization under constant attack, the thrilling promise of AI to the future of secure code, the dangers of equating SBOMs to supply chain security, and new SEC reporting rules for CISOs. 
</description>
  <itunes:keywords>supply chain, open source software, sbom, log4j, codecov, solarwinds, sunburst, apt, credential theft, npm, typosquatting, code quality, shift-left</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>GitHub security chief Mike Hanley joins the show to discuss merging the CSO and SVP/Engineering roles, securing data and code in an organization under constant attack, the thrilling promise of AI to the future of secure code, the dangers of equating SBOMs to supply chain security, and new SEC reporting rules for CISOs.</p><p>Links:</p><ul><li><a title="Michael Hanley on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/michael-hanley-b6508913/">Michael Hanley on LinkedIn</a></li><li><a title="GitHub Security" rel="nofollow" href="https://github.com/security">GitHub Security</a></li><li><a title="GitHub Copilot AI pair programmer" rel="nofollow" href="https://github.com/features/copilot">GitHub Copilot AI pair programmer</a></li><li><a title="Big Tech Vendors Object to US Gov SBOM Mandate" rel="nofollow" href="https://www.securityweek.com/big-tech-vendors-object-us-gov-sbom-mandate/">Big Tech Vendors Object to US Gov SBOM Mandate</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>GitHub security chief Mike Hanley joins the show to discuss merging the CSO and SVP/Engineering roles, securing data and code in an organization under constant attack, the thrilling promise of AI to the future of secure code, the dangers of equating SBOMs to supply chain security, and new SEC reporting rules for CISOs.</p><p>Links:</p><ul><li><a title="Michael Hanley on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/michael-hanley-b6508913/">Michael Hanley on LinkedIn</a></li><li><a title="GitHub Security" rel="nofollow" href="https://github.com/security">GitHub Security</a></li><li><a title="GitHub Copilot AI pair programmer" rel="nofollow" href="https://github.com/features/copilot">GitHub Copilot AI pair programmer</a></li><li><a title="Big Tech Vendors Object to US Gov SBOM Mandate" rel="nofollow" href="https://www.securityweek.com/big-tech-vendors-object-us-gov-sbom-mandate/">Big Tech Vendors Object to US Gov SBOM Mandate</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Sounil Yu on SBOMs, software supply chain security</title>
  <link>http://securityconversations.fireside.fm/sounil-yu-sboms-supply-chain-security</link>
  <guid isPermaLink="false">ca890116-c6d7-4107-8c9d-b4b64ed28927</guid>
  <pubDate>Tue, 13 Jul 2021 08:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/ca890116-c6d7-4107-8c9d-b4b64ed28927.mp3" length="58362999" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsored by SecurityWeek.com

JupiterOne CISO Sounil Yu joins the show to sift through the noise and explain the value of SBOMs (software bill of materials), the U.S. government's response to software supply chain security gaps, and what every buyer and seller should be doing to prepare for major changes in the ecosystem.</itunes:subtitle>
  <itunes:duration>48:26</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/ca890116-c6d7-4107-8c9d-b4b64ed28927/cover.jpg?v=1"/>
  <description>Episode sponsored by SecurityWeek.com
JupiterOne CISO Sounil Yu joins the show to sift through the noise and explain the value of SBOMs (software bill of materials), the U.S. government's response to software supply chain security gaps, and what every buyer and seller should be doing to prepare for major changes in the ecosystem. 
</description>
  <itunes:keywords>sbom, supply chain, open-source</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Episode sponsored by SecurityWeek.com</p>

<p>JupiterOne CISO Sounil Yu joins the show to sift through the noise and explain the value of SBOMs (software bill of materials), the U.S. government&#39;s response to software supply chain security gaps, and what every buyer and seller should be doing to prepare for major changes in the ecosystem.</p>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Episode sponsored by SecurityWeek.com</p>

<p>JupiterOne CISO Sounil Yu joins the show to sift through the noise and explain the value of SBOMs (software bill of materials), the U.S. government&#39;s response to software supply chain security gaps, and what every buyer and seller should be doing to prepare for major changes in the ecosystem.</p>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
