
ISC StormCast for Tuesday, October 4th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
A Supply Chain Attack on COM100 Software Development Process
Kaspersky reported on a vulnerability that Kaspersky now reported on and wrote up. A fix has been available for a while and it's called an application password mechanism, but it's something that you have to specifically enable. Let me got another supply chain attack to talk about and I think this is actually legitimately to call this a supply chain attack. COM100 does produce sort of support software, video chat software for enterprises.
Play episode from 02:50
Transcript


