Critical Thinking - Bug Bounty Podcast cover image

Episode 74: Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin)

Critical Thinking - Bug Bounty Podcast

00:00

Software Supply Chain Security in Tech Companies

The chapter delves into the process of developers writing code in VS Code, committing it to a GitHub repo, and managing source code in tech environments. It explains the distinction between an artifactory and a registry for storing private and public packages, emphasizing the advantages of a centralized supply chain. The discussion also focuses on vulnerabilities in CI builds, exploring techniques for identifying and attacking different parts of the software development flow.

Play episode from 09:21
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app