
DEVSECOPS Talks #53 - Open Software Supply Chain Attack Reference Framework with Neatsun
The DevSecOps Talks Podcast
00:00
The Role of Open Source in Software Supply Chain Attacks
There's a great framework called Oscar framework. We took over 300 software supply chain attacks that happened over the past five years. And we broke them down to the TTPs, the techniques, tactics and procedures used by bad guys. It is fully open source on GitHub but I think always go back to the way I installed packages on my Linux server. But it's mind-blowing right to see how easy it's becoming to get all this.
Transcript
Play full episode