In this episode, the conversation focuses on software supply chain failures, now a top concern in the OWASP Top 10. Real-world examples and practical strategies are discussed to help organizations manage the risks of using third-party components and vendors.
- The increased prevalence and risk of software supply chain vulnerabilities, including why this is now such a serious concern
- How reliance on third-party libraries and components like jQuery introduces persistent security challenges
- The impact of infamous attacks like SolarWinds and lessons learned for vendor management and application security
- The crucial role of an SBOM (Software Bill of Materials) and continuous monitoring in identifying vulnerabilities early
- Best practices for holding vendors accountable, integrating pen testing, and contract strategies to ensure remediation of critical issues
The takeaway: whether you’re writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.
Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaY
Part 2 — Security Misconfigurations: https://youtu.be/Po8H140BijE
Need a web app pen test? SecurIT360 | Cybersecurity From Every Angle
More content: https://offsec.blog
