DevSec Station
What if a supply chain attack didn’t start with a complex exploit… but something completely normal? A typo. A copy-paste. Even an AI suggestion. In this episode, Tanya Janca breaks down how modern supply chain attacks actually happen inside everyday developer workflows. These attacks aren’t one big moment. They’re a series of small, reasonable decisions that quietly introduce risk. You’ll learn: • Why supply chain attacks are a process, not a single event • How attackers exploit normal developer behavior • A simple, step-by-step example of a real attack path • Why traditional SCA tools often miss real risk • How to focus on what actually matters 👉 If you do one thing this week: Run your SCA tool with reachability enabled and fix one real issue. That’s how you start reducing risk. If you work in DevSecOps, application security, or software development, you need to understand this. #SupplyChainSecurity #DevSecOps #AppSec #SecureCoding #SoftwareSecurity #CyberSecurity
4 Episoder
Kommentarer
0Vær den første til å kommentere
Registrer deg nå og bli medlem av DevSec Station sitt community!