{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security","description":"Guest:  Dan Lorenc, Founder \/ CEO, Chainguard  Topics:  We just saw a security tool (Trivy) get used to pop an AI infrastructure tool (LiteLLM) to eventually pop end users. Have we reached the point where our security tooling is actually our largest unmanaged attack surface?&amp;nbsp; Why now? Software supply chain security had the perennial vibe of \u201cnot top concern\u201d for most organizations, right? TeamPCP pushed malicious code to existing GitHub tags. We\u2019ve been screaming about pinning versions to SHAs for years, but clearly, nobody is listening. Is it time to admit that 'convenience' is the primary enemy of supply chain security? The Axios incident showed a victim compromised in under two minutes. In a world of auto-updating dependencies, is the concept of a human-in-the-loop for software updates officially dead, or do we need to look very hard at version pinning and such? With XZ Utils case, we saw a long-game social engineering attack. Beyond just 'watching npm closely,' what are the realistic architectural safeguards for an org that knows they can't audit every line of an update? We\u2019ve spent the last three years talking about SBOMs (Software Bill of Materials) like they were a pill for supply chain health. But if the scanner producing the SBOM is the one that's compromised, isn't the SBOM just a signed receipt for your own house being on fire?&amp;nbsp; What is the one practical thing they can do to ensure their CI\/CD isn't a credential-exfiltration-as-a-service platform?  Resources:  Video version  North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack  EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security  EP116 SBOMs: A Step Towards a More Secure Software Supply Chain  EP226 AI Supply Chain Security: Old Lessons, New Poisons, and Agentic Dreams  EP24 Linking Up The Pieces: Software Supply Chain Security at Google and Beyond Matt Levine blog  ","author_name":"Cloud Security Podcast by Google","author_url":"https:\/\/cloud.withgoogle.com\/cloudsecurity\/podcast\/","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/40726175\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/40726175"}