Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the dark world of supply chain attacks in this comprehensive conference talk that reveals how malicious actors target and exploit software supply chains. Delve into the SLSA framework to understand supply chain fundamentals before examining the economics driving cybercriminal activities and why supply chain attacks have revolutionized traditional hacker business models. Learn about four primary attack vectors: CI/CD pipeline compromises, version control system breaches, open-source dependency poisoning, and AI LLM abuse. Analyze real-world case studies of high-profile successful attacks, tracing the complete attack lifecycle from initial access through privilege escalation to final objectives. Discover effective defense strategies including inside-out security approaches, breach detection methodologies, and containment techniques to protect your organization's software supply chain against sophisticated adversaries.
Syllabus
Attacking the supply chain - The miscreant's field manual • Mackenzie Jackson • Devoxx Poland 2024
Taught by
Devoxx Poland