Critical Thinking - Bug Bounty Podcast cover image

Episode 74: Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin)

Critical Thinking - Bug Bounty Podcast

00:00

Software Supply Chain Security in Tech Companies

The chapter delves into the process of developers writing code in VS Code, committing it to a GitHub repo, and managing source code in tech environments. It explains the distinction between an artifactory and a registry for storing private and public packages, emphasizing the advantages of a centralized supply chain. The discussion also focuses on vulnerabilities in CI builds, exploring techniques for identifying and attacking different parts of the software development flow.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app