Security at Scale with Liran Tal - Director of Developer Advocacy at Snyk episode artwork

EPISODE · Nov 16, 2025 · 57 MIN

Security at Scale with Liran Tal - Director of Developer Advocacy at Snyk

from Señors at Scale - Software Engineering & Tech Leadership · host Dan Neciu

In this episode of Señors @ Scale, Dan sits down with Liran Tal, Director of Developer Advocacy at Snyk, GitHub Star, and one of the most influential voices in modern application security. Liran has spent decades at the intersection of open-source ecosystems, Node.js, supply chain security, and now AI agent security, helping developers ship fast without exposing themselves to silent, catastrophic risks.He breaks down the real stories behind today’s security landscape — from NPM malware and maintainer compromises to MCP attacks, toxic flows, and the hidden vulnerabilities emerging from AI-driven development.We dig into what “security at scale” actually means: how attackers compromise maintainers and publish worm-style malware, how invisible Unicode payloads bypass human review, why AI-generated code is statistically insecure, and how developers can build guardrails directly into their workflows with tools like Snyk, NPQ, and MCP scanning.Liran also reveals the problems teams consistently underestimate — developer ergonomics, dependency trust, package governance, CI risk, and why blindly upgrading dependencies is one of the most dangerous patterns in modern engineering.The conversation goes far beyond theory — into secure coding, package hygiene, NPM ecosystem fragility, MCP prompt injection, SQL and command injection patterns, and what real-world breaches teach us about resilience.If you build software, install dependencies, or use AI coding agents, this episode is a masterclass in defensive engineering, supply chain awareness, and the new security realities shaping our industry.Chapters00:00 Security at Scale – Why It Matters Now02:14 How Liran Got Into Security05:12 The Shift Toward Developer-Led Security08:33 How Snyk Changed the Developer Security Workflow11:07 The Story Behind NPQ and Safer Dependency Installation14:02 The Rise of NPM Malware and Maintainer Compromise16:48 Why Blind Upgrade Everything Pipelines Are Dangerous19:15 Is Node the Problem or Is It NPM21:10 The Hidden Risk of MCPs and AI Agent Vulnerabilities24:18 Toxic Flows, Shadowed Tools, and Prompt Injection27:22 AI Browsers, Extensions, and Real Prompt Injection Attacks30:04 Why Prompt Injection Has No True Fix33:01 AI-Generated Code Is Statistically Insecure35:12 How Snyk Plus MCP Creates a Secure Coding Loop37:40 The Most Common MCP Vulnerabilities40:55 How AI Agents Turn Mild Bugs Into Critical RCE43:11 The Glassworm Invisible Unicode Attack Vector44:51 EventStream, XZ Utils, and Supply Chain Horror Stories48:03 Liran’s Personal Security Incidents51:10 UX vs Security and Real World Tension53:04 Liran’s Book Recommendations55:37 Final Thoughts and Protecting Yourself as AI EvolvesSound Bites"Security at scale is a complex challenge.""AI-generated code is not always secure.""Security and UX must work together."Follow & Subscribe:Instagram: https://www.instagram.com/senorsatscale/Instagram: https://www.instagram.com/neciudevPodcast URL: https://neciudan.dev/senors-at-scaleNewsletter: https://neciudan.dev/subscribeLinkedIn: https://www.linkedin.com/in/neciudanLinkedIn: https://www.linkedin.com/company/señors-scale/Additional ResourcesSnyk – developer-first security toolsServerless Security (O’Reilly) – co-authored by LiranLiran’s GitHub: https://github.com/lirantalNPQ package checker: https://github.com/lirantal/npqMCP Scan (Snyk) – securing MCP servers#security #softwaresecurity #supplychainsecurity #npm Don’t forget to like, comment, and subscribe for more engineering stories from the front lines.How are you protecting your stack from supply chain attacks? Share below 👇

NOW PLAYING

Security at Scale with Liran Tal - Director of Developer Advocacy at Snyk

0:00 57:56

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? XXX Tech by SOVRYN Dr. Brian Sovryn The crossroads between technology, sensuality, and metaphysics - and the longest running anarchist podcast in the world! Brought to you by Dr. Brian Sovryn. PodQuesting Dwight J Randolph- WolfShield Media PodQuesting: -By WolfShield Media and Dwight J RandolphJoin us on an exciting journey to master the world of fiction podcasting! At PodQuesting, we document our quest to improve and innovate, sharing valuable insights, strategies, and behind-the-scenes tips along the way. Whether you're an experienced podcaster or just starting your first show, our podcast is your go-to resource for everything podcasting.Discover practical advice, creative techniques, and lessons from our own experiences as we explore the ever-evolving podcasting landscape. Ready to level up your skills and embark on this adventure with us? Tune in and join the quest!Have questions or feedback? Reach out to us at [email protected] and visit our website:WolfShield.Media She’s a Hazard to Herself She’s a Hazard Hi there, I’m Mallory, and I’d like to invite you into our world with “She’s a Hazard to Herself!” Join us as we navigate life with Multiple Sclerosis from the seat of my power wheelchair. Discover stories of resilience, family, and the community we’ve built around chronic illness. Whether you’re impacted by MS or want to learn from our journey, there’s something here for you. So why wait? Subscribe to “She’s a Hazard to Herself” on your favorite podcast app and be part of our journey today. Let’s lift each other up, one episode at a time!

Frequently Asked Questions

How long is this episode of Señors at Scale - Software Engineering & Tech Leadership?

This episode is 57 minutes long.

When was this Señors at Scale - Software Engineering & Tech Leadership episode published?

This episode was published on November 16, 2025.

What is this episode about?

In this episode of Señors @ Scale, Dan sits down with Liran Tal, Director of Developer Advocacy at Snyk, GitHub Star, and one of the most influential voices in modern application security. Liran has spent decades at the intersection of open-source...

Can I download this Señors at Scale - Software Engineering & Tech Leadership episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!