AllTheTalks.online | The threat is real: software supply chain vulnerabilities

Software supply chain threats are real! As more developers and companies rely on open-source code - that anyone can contribute to, including attacks - this open the door to a new vector of attack. There are increasing supply chain compromises which successfully sneak in new backdoored packages, use typosquatting, or even compromise build tooling and signing keys. What’s actually happening in the wild, how do you determine your dependencies, and properly secure yourself?

We’ll cover common kinds of supply chain attacks, and when they’re likely to happen. We’ll dive into specific examples that have occurred in the last few years, to understand how and why these attacks happen, as well as summarize overall trends in the industry. We’ll close up by discussing what developers can do to determine your dependencies, and be notified of new security patches you should apply, including best practices to make this easier on your dev team. We’ll also cover what you can do to contribute back - like how you should report vulnerabilities you discover in open-source.

You’ll come away with a better understanding of what you can do for supply chain security for your organization.

Watch the recording Get the slides