
The Elephant in the Pipeline: Securing the Wild, Untamed Software Supply Chain - Pete Morgan - ESW #348
About this episode
We've seen general users targeted with phishing, financial employees targeted for BEC scams, and engineers targeted for access to infrastructure. The truly scary attacks, however, are the indirect ones that are automated. The threats that come in via software updates, or trusted connections with third parties.
The software supply chain is both absolutely essential, and fragile. A single developer pulling a tiny library out of NPM can cause chaos. A popular open source project changing hands could instantly give access to millions of systems. Every day, a new app store or component repository pops up and becomes critical to maintaining infrastructure.
In this interview, we'll chat with Pete Morgan about how these risks can be managed and mitigated.
Segment Resources:
- https://blog.phylum.io/q3-2023-evolution-of-software-supply-chain-security-report/
- https://blog.phylum.io/software-supply-chain-security-research-report-q2-2023/
- https://blog.phylum.io/q1-2023-evolution-of-software-supply-chain-security/
Show Notes: https://securityweekly.com/esw-348
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Video)
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. -...
Enterprise Security Weekly (Video)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, &...
Enterprise Security Weekly (Video)
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interview...
Enterprise Security Weekly (Video)
Can employees safely use AI agents? AI pentesting agent liabilities, and the new...
Enterprise Security Weekly (Video)