Software supply chain
73
MENTIONS
19
EPISODES
18
PODCASTS
Search complete. 73 mentions across 19 episodes found for "Software supply chain".
Oct 5, 2026
Dependency attacks in 2026 with James Matchett
J
3:11James MatchettGUEST
100%.
J
3:12James MatchettGUEST
And I think part of the confusion comes from people misunderstanding what SBOMs and these big, lovely lists of packages that you've installed actually do.
J
3:20James MatchettGUEST
And people think, well, I've got an SBOM, I can see what's installed, and therefore I'm safe from this type of attack.
J
3:25James MatchettGUEST
But what we're really seeing over the past five years is this transition from supply chain attacks that have to be all the way promoted and productionized and deployed for you to be vulnerable versus these type of attacks where you just have to install the package, not even use it.
9 MINS LATER
J
13:10James MatchettGUEST
Exactly.
J
13:11James MatchettGUEST
And it's actually becoming a part of the Cyber Resilience Act as well.
J
13:13James MatchettGUEST
You've got to include your SBOMs.
J
13:15James MatchettGUEST
And if you can include that information about provenance or attestation, you're golden.
Daily Cyber & AI Briefing — 2026-10-02
M
5:19Michael HouschHOST
Supply chain risks are also front and center.
M
5:22Michael HouschHOST
with attackers increasingly targeting trusted software update mechanisms to deliver credential-stealing malware.
M
5:28Michael HouschHOST
This trend highlights a persistent weakness in software supply chains, namely the trust placed in update channels.
M
5:35Michael HouschHOST
When attackers compromise these mechanisms, they can distribute malicious payloads under the guise of legitimate updates, often bypassing traditional security controls, Organizations should rigorously validate updates, enforce code signing, and maintain strong endpoint monitoring.
M
5:53Michael HouschHOST
Just as importantly, user awareness needs to be elevated so that employees are alert to unusual prompts or update requests.
Fifteen Million Amps
B
17:22BenjaminHOST
And then also show the, um, the reports not only on the command line, but eventually in the, um, HTML dashboard as well.
B
17:30BenjaminHOST
Make that, uh, maybe part of the, um, capture the data into SBOM as well, 'cause this is useful information.
B
17:36BenjaminHOST
Um, yep.
B
17:37BenjaminHOST
So, um, ha- have a look.
Hacking Without Boundaries - Michael Jenkins - PSW #946
L
36:57Larry PescePANELIST
It's about S- we're gonna do SBOMs.
P
36:59Paul AsadoorianHOST
I think, uh, uh, yeah, I think, well, I think the headline that caught people's attention, and it's a very sensational headline, your SBOM is fan fiction.
P
37:06Paul AsadoorianHOST
And I know Josh is already, and Alan Friedman, if you're listening, I know it's a very sensational headline.
P
37:13Paul AsadoorianHOST
Um, [clears throat] it came from this project called Yeet, yeet.cx. Have you guys ever heard of this?
P
38:13Paul AsadoorianHOST
I've not tested it, uh, yet.
P
38:16Paul AsadoorianHOST
Um, but it looks like you can kinda build, like, these little apps that pull from these pockets of information, um, like /proc, uh, is a goldmine, we call it, uh, at, at our day job, goldmine of information.
P
38:29Paul AsadoorianHOST
Um, [clears throat] and what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software's gonna run somewhere and have runtime dependencies, and those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily [clears throat] in the SBOM.
P
38:56Paul AsadoorianHOST
So for example, like, if you really wanna dig into Linux, um, you can look in /proc/ the PID, process ID-
Hacking Without Boundaries - Michael Jenkins - PSW #946
P
31:51Paul AsadoorianHOST
Hey, let's talk S-bombs.
P
31:54Paul AsadoorianHOST
I knew that SBOM story was going to fire you up.
P
31:56Paul AsadoorianHOST
Me too.
P
31:57Paul AsadoorianHOST
Me too.
6 MINS LATER
P
38:13Paul AsadoorianHOST
I've not tested it yet, but it looks like you can kind of build like these little apps that pull from these pockets of information, like slash proc is a goldmine.
P
38:25Paul AsadoorianHOST
We call it at our day job, goldmine of information.
P
38:31Paul AsadoorianHOST
And what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software is gonna run somewhere and have runtime dependencies.
P
38:46Paul AsadoorianHOST
And those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily in the SBOM.
Hacking Without Boundaries - Michael Jenkins - PSW #946
P
31:51Paul AsadoorianHOST
Hey, let's talk S-bombs.
P
31:54Paul AsadoorianHOST
I knew that SBOM story was going to fire you up.
P
31:56Paul AsadoorianHOST
Me too.
P
31:57Paul AsadoorianHOST
Me too.
6 MINS LATER
P
38:13Paul AsadoorianHOST
I've not tested it yet, but it looks like you can kind of build like these little apps that pull from these pockets of information, like slash proc is a goldmine.
P
38:25Paul AsadoorianHOST
We call it at our day job, goldmine of information.
P
38:31Paul AsadoorianHOST
And what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software is gonna run somewhere and have runtime dependencies.
P
38:46Paul AsadoorianHOST
And those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily in the SBOM.
1549. #TFCP - Defending Critical Infrastructure from Nation-State Cyber Threats | NMFTA Cybersecurity Conference 2026
V
9:00VishalGUEST
Now, here's an interesting thought.
V
9:01VishalGUEST
When you talk about software supply chain or when you talk about supply chain and I talk about software supply chain, where does fraud live? Well, it's really easy to look at fraud in two different spots in your industry.
V
9:13VishalGUEST
Number one, it's where everyone probably sees it.
C
9:16Chris JollyHOST
Mm-hmm.
Controlling your Digital Legacy with Mattias Karlsson
C
29:28Carl FranklinHOST
Are we talking about a digital will?
M
29:31Mattias KarlssonGUEST
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
M
29:46Mattias KarlssonGUEST
I think it's good.
M
29:48Mattias KarlssonGUEST
I think that's something you could use AI for now.
Controlling your Digital Legacy with Mattias Karlsson
C
29:28Carl FranklinHOST
Are we talking about a digital will?
M
29:31Mattias KarlssonGUEST
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
M
29:46Mattias KarlssonGUEST
I think it's good.
M
29:48Mattias KarlssonGUEST
I think that's something you could use AI for now.
Controlling your Digital Legacy with Mattias Karlsson
C
29:28Carl FranklinHOST
Are we talking about a digital will?
M
29:31Mattias KarlssonGUEST
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
M
29:46Mattias KarlssonGUEST
I think it's good.
M
29:48Mattias KarlssonGUEST
I think that's something you could use AI for now.
9 more episodes mention Software supply chain.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.