
Episode 535: Dan Lorenc on Supply Chain Attacks
Software Engineering Radio - the podcast for professional software developers
00:00
Code Cache Attacks - What Are They?
The original attack was on the vendor that was used to inject the back door into the supply chain further downstream of their customers. These attacks, if they take a little bit more patience, you can't quite be as targeted in them, but they have much broader range and consequences. The root cause for this one was found a secret to an S3 bucket or something like that for code cup. And anybody in CI systems using code cup during this breach had to evaluate the impact of having all of their other secrets and data from that CI job actually traded into some organization.
Transcript
Play full episode