Overview
Syllabus
Intro
The Rise of Software Supply Chain Attacks
Agenda
Hacking History
Code Red & SQL Slammer
Bill Gates - Email to all MS FTE
Changes in Software Architecture
What is a Supply Chain?
Hacking Hardware
Octopus Scanner - NetBeans
Visual Studio Code
Development Machine
Canonical GitHub Account
Microsoft GitHub Account
Use MFA on source-repository
GIT Commit Signing
Build / Deployment
Twilio SDK
Webmin Backdoor
SolarWinds Sunspot
Reproducable/Deterministic Builds
Automotive Industry
Car Supply Chain
DataDog & In-Toto
Azure Pipelines Artifact Policy
Conclusion
Taught by
NDC Conferences