Sveriges mest populära poddar
The Cyber Threat Perspective
The Cyber Threat Perspective

Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

28 min24 juli 2026

Om avsnittet

Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you.

Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple.

From there it gets practical:

  • What a Software Bill of Materials (SBOM) is and why you need one
  • Transitive dependencies — the packages hiding beneath your packages
  • Building security checks into your CI/CD pipeline and shifting left
  • Why a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+
  • Why a pen test should validate your controls, not be your first line of defense
  • How SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilities
  • A playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findings

The takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.

Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaY

Part 2 — Security Misconfigurations: https://youtu.be/Po8H140BijE

Need a web app pen test? SecurIT360 | Cybersecurity From Every Angle 

More content: https://offsec.blog

Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov

Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com

Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

The Cyber Threat Perspective med SecurIT360 finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.