Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialPAUL ROBERTS
You're doing endpoint protection. Is there a meaningful difference between the types of things, types of threats and attacks you're seeing on iOS, macOS, endpoints and what we're used to seeing in the Windows world? Is it pretty much the same threat actors, same types of attacks?
DEVIN BYRD
It's a very similar kind of attack field that's there. What we're seeing more and more is 10 years ago, a Mac malware may only be adware. And maybe just be something that's just potentially unwanted, like a kind of junkware. With the move to see more people, especially, specifically, developers and executive teams that are really big around having their macOS devices, we're starting to see a lot more things of backdoors.
Things like the 3CX that you had mentioned a moment ago, where it can attack that same kind of vector and expand that out to the people that normally would feel completely safe. If we look back, it wasn't too long ago, Apple made the claim that Mac doesn't get viruses.
And as we continue to grow, we're seeing that not only do we get them, they're becoming more and more complex and more difficult to detect.
PAUL ROBERTS
And again, we talked about Patrick Wardle, who's one of the renowned experts in macOS, doing a whole thing just on the role that attacks on macOS endpoints had in the 3CX supply chain compromise.
DEVIN BYRD
Absolutely.
PAUL ROBERTS
Yeah, it's really true. And I think even back when you were having those conversations, Mac as a security issue, I think everybody recognized there's nothing inherent with macOS, that makes it not a security risk. It's just that there aren't as many of those endpoints as there are Windows endpoints. So fish where the fish are.
DEVIN BYRD
For the longest time, it was just one of those things was like, why would I create malware that only affects 3% of the population where I can create something that's going to hit 97% and have that bigger net to cast.
PAUL ROBERTS
Right. Okay, so you guys are in EDR space like what obviously with the shift to remote work, hybrid work... really big changes in the way that companies are managing their IT infrastructure what that looks like. You know the whole notion of a perimeter is long since dead.... what are you seeing right now in the EDR space? What are the big trends and what are you hearing from your customers in terms of what they're looking for in terms of protection?
DEVIN BYRD
Yeah the biggest thing is, the shift to remote work, it took out a lot of security measures that a lot of places had in place. People were used to going into the office and they had firewalls and they had all these different kind of layers of security that was put in place.
The shift to being remote, it changed all of that because you may have a Meraki router or Palo Alto firewalls or something in your office that the normal home user doesn't have. And then the normal home user, they're like, Oh, I want, remote light bulbs that came from China for $5. You don't know that may have a backdoor in it.
So you're just opening up a lot more security vulnerabilities, a lot more risk. So it's been something where you really have to maintain and monitor, not only the stuff that you know are going to happen, but watching for processes, watching for things that are going to be completely different or off key from what people are used to doing.
PAUL ROBERTS
Okay, final question. You brought it up, which is the supply chain threat, right? The MoveIT hack, the Office 365 compromise, like we are seeing threat actors targeting suppliers, major suppliers to major organizations as a way to circumvent security protections.
As an EDR vendor what's your take on that? Does that change the requirements for a company like Kandji or is it just, keep doing what you're doing?
DEVIN BYRD
It changes things, but it doesn't. We always know that those kind of things happen. It's not the first time we've seen the supply chain kind of attack happen, but it's getting more prevalent.
What it makes us do is become more aware that even though traditionally this software may be safe, we still only let our guard down. We can't just trust and not verify. We need to trust and verify everything that we're going through and looking at. So being able to not only validate, hey, this software is good, but what is that software doing? Monitoring its behavior, it's gonna still see things regardless.
PAUL ROBERTS
Okay, if our listeners, our viewers, who want to find you online, where can they find you?
DEVIN BYRD
So I'm on LinkedIn. And then if you ever need to get in contact with me as far as anything else, I'm also available through Kandji stuff. You can email us through there. And our threat team's happy to answer any kind of questions or do anything from that side too.
PAUL ROBERTS
Hey man, thanks so much for coming in.
DEVIN BYRD
Yeah, absolutely, Paul. Thank you.

Saša Zdjelar discusses the recent Notebook++ hack and what he thinks software supply chain security will look like in 2026.

Paul Roberts chats with OWASP GenAI Security Project co-chair Steve Wilson about how AI is transforming cybersecurity and software development.