Broken links - Behind the scenes of Supply Chain breaches

François Proulx

BSides NYC 2023 (0x04) · Day 1 · Talk - Blue

In this comprehensive talk, François Proulx, Senior Product Security Engineer at Boost Security, dissects the rapidly escalating threat landscape of **software supply chain security**. The presentation provides a chilling timeline of publicly disclosed supply chain breaches, emphasizing their acceleration in recent years and the likelihood of many more undisclosed incidents. Proulx argues that as traditional application security measures improve, threat actors increasingly shift their focus to the inherently complex and often less-secured software supply chain, targeting its "weakest links."

AI review

Competent supply chain survey talk anchored by a genuinely interesting Terraform module zero-day, but the zero-day aside, this is mostly a well-organized tour of breaches you've already read about. The SLSA framing is useful scaffolding but not original thinking, and the defensive recommendations are standard-issue hardening advice. Worth the slot at BSides NYC; would drown at DEF CON main stage.

Watch on YouTube