Subscribe to the CyberThreatPOV Podcast

OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding | Episode 189

In this episode, the conversation focuses on software supply chain failures, now a top concern in the OWASP Top 10. Real-world examples and practical strategies are discussed to help organizations manage the risks of using third-party components and vendors.

  • The increased prevalence and risk of software supply chain vulnerabilities, including why this is now such a serious concern 
  • How reliance on third-party libraries and components like jQuery introduces persistent security challenges 
  • The impact of infamous attacks like SolarWinds and lessons learned for vendor management and application security 
  • The crucial role of an SBOM (Software Bill of Materials) and continuous monitoring in identifying vulnerabilities early 
  • Best practices for holding vendors accountable, integrating pen testing, and contract strategies to ensure remediation of critical issues

The takeaway: whether you’re writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.

Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaY

Part 2 — Security Misconfigurations: https://youtu.be/Po8H140BijE

Need a web app pen test? SecurIT360 | Cybersecurity From Every Angle

More content: https://offsec.blog