Главная
Study mode:
on
1
Introduction
2
Context
3
Supply Chain
4
Edward Reever
5
Chevy Cobalt
6
Boeing 787
7
Lettuce
8
Old School Vulnerabilities
9
First Vulnerabilities
10
Shell Shock Heartbleed
11
Commons Collection
12
Log for Shell
13
China
14
National Security Agency
15
New Rise of Open Source
16
typo squatting attacks
17
evolution of attacks
18
attacks on developers
19
Jenkins
20
Vercata
21
Code Cub
22
Inversion
23
White Hat Research
24
Bug Bounties
25
The attackers are still focused
26
Global drug trade 2016
27
VC funds investing in attackers
28
Theyre looking for the easy way
29
For the attackers right now
30
This rise is not a coincidence
31
Credit card fraud detection
32
What do we do about it
33
They were freaking out
34
Theyre amateurs
35
Fix Open Source
36
Takata Airbag
37
JYear on View
38
Vulnerability Analysis
39
Solving 4 of the Problem
40
The Good News
41
The Point
42
You have a supply chain
43
How to avoid the next malicious release
44
Factory Deming principles
45
Security is most important
46
People are faster and more secure
47
Conclusion
Description:
Explore the evolving landscape of open source supply chain threats in this 31-minute conference talk by Brian Fox from Sonatype. Gain insights into the growing number of organized attackers exploiting vulnerabilities in open source ecosystems and their tactics to make malware appear legitimate. Learn about the cascading impacts of these exploitations and the importance of implementing developer-first security tools. Trace the evolution of attacks over the past 15 years, from old school vulnerabilities to modern sophisticated techniques targeting developers. Understand the economic motivations behind these attacks, including VC funding for attackers and the comparison to the global drug trade. Discover strategies to counter the latest types of attacks, including the importance of fixing open source vulnerabilities, implementing proper vulnerability analysis, and adopting factory Deming principles for security. Recognize the critical role of understanding your supply chain and empowering people to enhance security measures. Read more

Open Source Supply Chain Threat Landscape - A Moving Target

Linux Foundation
Add to list