Skip to main content
Software supply chain

Software supply chain

Search complete. 73 mentions across 19 episodes found for "Software supply chain".

Oct 5, 2026

James MatchettGUEST
3:11
100%.
James MatchettGUEST
3:12
And I think part of the confusion comes from people misunderstanding what SBOMs and these big, lovely lists of packages that you've installed actually do.
James MatchettGUEST
3:20
And people think, well, I've got an SBOM, I can see what's installed, and therefore I'm safe from this type of attack.
James MatchettGUEST
3:25
But what we're really seeing over the past five years is this transition from supply chain attacks that have to be all the way promoted and productionized and deployed for you to be vulnerable versus these type of attacks where you just have to install the package, not even use it.

9 MINS LATER

James MatchettGUEST
13:10
Exactly.
James MatchettGUEST
13:11
And it's actually becoming a part of the Cyber Resilience Act as well.
James MatchettGUEST
13:13
You've got to include your SBOMs.
James MatchettGUEST
13:15
And if you can include that information about provenance or attestation, you're golden.
Michael HouschHOST
5:19
Supply chain risks are also front and center.
Michael HouschHOST
5:22
with attackers increasingly targeting trusted software update mechanisms to deliver credential-stealing malware.
Michael HouschHOST
5:28
This trend highlights a persistent weakness in software supply chains, namely the trust placed in update channels.
Michael HouschHOST
5:35
When attackers compromise these mechanisms, they can distribute malicious payloads under the guise of legitimate updates, often bypassing traditional security controls, Organizations should rigorously validate updates, enforce code signing, and maintain strong endpoint monitoring.
Michael HouschHOST
5:53
Just as importantly, user awareness needs to be elevated so that employees are alert to unusual prompts or update requests.
BenjaminHOST
17:22
And then also show the, um, the reports not only on the command line, but eventually in the, um, HTML dashboard as well.
BenjaminHOST
17:30
Make that, uh, maybe part of the, um, capture the data into SBOM as well, 'cause this is useful information.
BenjaminHOST
17:36
Um, yep.
BenjaminHOST
17:37
So, um, ha- have a look.
Larry PescePANELIST
36:57
It's about S- we're gonna do SBOMs.
Paul AsadoorianHOST
36:59
I think, uh, uh, yeah, I think, well, I think the headline that caught people's attention, and it's a very sensational headline, your SBOM is fan fiction.
Paul AsadoorianHOST
37:06
And I know Josh is already, and Alan Friedman, if you're listening, I know it's a very sensational headline.
Paul AsadoorianHOST
37:13
Um, [clears throat] it came from this project called Yeet, yeet.cx. Have you guys ever heard of this?
Paul AsadoorianHOST
38:13
I've not tested it, uh, yet.
Paul AsadoorianHOST
38:16
Um, but it looks like you can kinda build, like, these little apps that pull from these pockets of information, um, like /proc, uh, is a goldmine, we call it, uh, at, at our day job, goldmine of information.
Paul AsadoorianHOST
38:29
Um, [clears throat] and what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software's gonna run somewhere and have runtime dependencies, and those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily [clears throat] in the SBOM.
Paul AsadoorianHOST
38:56
So for example, like, if you really wanna dig into Linux, um, you can look in /proc/ the PID, process ID-
Paul AsadoorianHOST
31:51
Hey, let's talk S-bombs.
Paul AsadoorianHOST
31:54
I knew that SBOM story was going to fire you up.
Paul AsadoorianHOST
31:56
Me too.
Paul AsadoorianHOST
31:57
Me too.

6 MINS LATER

Paul AsadoorianHOST
38:13
I've not tested it yet, but it looks like you can kind of build like these little apps that pull from these pockets of information, like slash proc is a goldmine.
Paul AsadoorianHOST
38:25
We call it at our day job, goldmine of information.
Paul AsadoorianHOST
38:31
And what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software is gonna run somewhere and have runtime dependencies.
Paul AsadoorianHOST
38:46
And those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily in the SBOM.
Paul AsadoorianHOST
31:51
Hey, let's talk S-bombs.
Paul AsadoorianHOST
31:54
I knew that SBOM story was going to fire you up.
Paul AsadoorianHOST
31:56
Me too.
Paul AsadoorianHOST
31:57
Me too.

6 MINS LATER

Paul AsadoorianHOST
38:13
I've not tested it yet, but it looks like you can kind of build like these little apps that pull from these pockets of information, like slash proc is a goldmine.
Paul AsadoorianHOST
38:25
We call it at our day job, goldmine of information.
Paul AsadoorianHOST
38:31
And what the gist of the article is, is that you can build software, you can generate an SBOM for that software, but that software is gonna run somewhere and have runtime dependencies.
Paul AsadoorianHOST
38:46
And those runtime dependencies could contain vulnerabilities or supply chain attacks that is not covered necessarily in the SBOM.
VishalGUEST
9:00
Now, here's an interesting thought.
VishalGUEST
9:01
When you talk about software supply chain or when you talk about supply chain and I talk about software supply chain, where does fraud live? Well, it's really easy to look at fraud in two different spots in your industry.
VishalGUEST
9:13
Number one, it's where everyone probably sees it.
Chris JollyHOST
9:16
Mm-hmm.
Carl FranklinHOST
29:28
Are we talking about a digital will?
Mattias KarlssonGUEST
29:31
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
Mattias KarlssonGUEST
29:46
I think it's good.
Mattias KarlssonGUEST
29:48
I think that's something you could use AI for now.
Carl FranklinHOST
29:28
Are we talking about a digital will?
Mattias KarlssonGUEST
29:31
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
Mattias KarlssonGUEST
29:46
I think it's good.
Mattias KarlssonGUEST
29:48
I think that's something you could use AI for now.
Carl FranklinHOST
29:28
Are we talking about a digital will?
Mattias KarlssonGUEST
29:31
Yeah, it's actually like, well, think like we have like the SBOM for software building materials, but almost like have a digital building materials or your life's like, what are the things to have an inventory for things like services domains? Yeah.
Mattias KarlssonGUEST
29:46
I think it's good.
Mattias KarlssonGUEST
29:48
I think that's something you could use AI for now.

9 more episodes mention Software supply chain.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.