<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I don&#x27;t think people are quite grasping the issue with software supply chain attacks.]]></title><description><![CDATA[<p>I don't think people are quite grasping the issue with software supply chain attacks. It's not just a case of compromised built software, it's also the build time. One popular package being compromised means every other package that depends on it is also now potential compromised or soon to be. And the targets can often move across other repos in the same org or account </p><p>Basically a slow moving worm today is rapidly accelerating to collapse. Kessler syndrome of software packages.</p>]]></description><link>https://board.circlewithadot.net/topic/adf0edcf-e585-488d-ad8e-a67f074a281e/i-don-t-think-people-are-quite-grasping-the-issue-with-software-supply-chain-attacks.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:42:30 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/adf0edcf-e585-488d-ad8e-a67f074a281e.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 02 May 2026 02:21:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I don&#x27;t think people are quite grasping the issue with software supply chain attacks. on Sat, 02 May 2026 02:48:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/krishean%40tech.lgbt" rel="nofollow noopener">@<span>krishean</span></a></span> <span><a href="/user/xssfox%40cloudisland.nz" rel="nofollow noopener">@<span>xssfox</span></a></span> <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/186/002/original/40d1828bd1caad62.gif" title=":dumpster_fire_gif:" /></p>

<div class="row mt-3"><div class="col-12 mt-3"><div class="ratio ratio-16x9">
<video controls width="498" height="498">
<source src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/502/693/019/890/888/original/a43d07c3e7a536da.mp4" type="video/mp4"></source>
</video>
</div></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/itgrrl/statuses/116502699115471409</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/itgrrl/statuses/116502699115471409</guid><dc:creator><![CDATA[itgrrl@infosec.exchange]]></dc:creator><pubDate>Sat, 02 May 2026 02:48:31 GMT</pubDate></item><item><title><![CDATA[Reply to I don&#x27;t think people are quite grasping the issue with software supply chain attacks. on Sat, 02 May 2026 02:46:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/krishean%40tech.lgbt">@<span>krishean</span></a></span> </p><p>pros: vendor responsibility<br />cons: vendor responsibility</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502690453531890</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502690453531890</guid><dc:creator><![CDATA[xssfox@cloudisland.nz]]></dc:creator><pubDate>Sat, 02 May 2026 02:46:18 GMT</pubDate></item><item><title><![CDATA[Reply to I don&#x27;t think people are quite grasping the issue with software supply chain attacks. on Sat, 02 May 2026 02:46:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz" rel="nofollow noopener">@<span>xssfox</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4af.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--100" style="height:23px;width:auto;vertical-align:middle" title="💯" alt="💯" /> </p><p>but also… <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f447.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--point_down" style="height:23px;width:auto;vertical-align:middle" title="👇" alt="👇" />  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2728.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sparkles" style="height:23px;width:auto;vertical-align:middle" title="✨" alt="✨" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61c.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--stuck_out_tongue_winking_eye" style="height:23px;width:auto;vertical-align:middle" title="😜" alt="😜" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2728.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sparkles" style="height:23px;width:auto;vertical-align:middle" title="✨" alt="✨" /></p>

<div class="row mt-3"><div class="col-12 mt-3"><div class="ratio ratio-16x9">
<video controls width="328" height="240">
<source src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/502/683/348/557/720/original/b0d77f61d90fd9fd.mp4" type="video/mp4"></source>
</video>
</div></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/itgrrl/statuses/116502689443201308</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/itgrrl/statuses/116502689443201308</guid><dc:creator><![CDATA[itgrrl@infosec.exchange]]></dc:creator><pubDate>Sat, 02 May 2026 02:46:03 GMT</pubDate></item><item><title><![CDATA[Reply to I don&#x27;t think people are quite grasping the issue with software supply chain attacks. on Sat, 02 May 2026 02:36:28 GMT]]></title><description><![CDATA[<p>(btw, most vulnerability scanning software isn't magic, it requires lock files, dpkg files or other data to work out what's installed. If you are using cut down builds, distroless and what not, most of these tools will not work and you cannot truly rely on them)</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502651748573470</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502651748573470</guid><dc:creator><![CDATA[xssfox@cloudisland.nz]]></dc:creator><pubDate>Sat, 02 May 2026 02:36:28 GMT</pubDate></item><item><title><![CDATA[Reply to I don&#x27;t think people are quite grasping the issue with software supply chain attacks. on Sat, 02 May 2026 02:31:41 GMT]]></title><description><![CDATA[<p>Even if you ci/cd is version pinned/locked to not get owned, did any of your developers pull down the new version while trying to fix an unrelated dependency issue?</p><p>What about third party software that vendors in packages?</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502632931993774</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116502632931993774</guid><dc:creator><![CDATA[xssfox@cloudisland.nz]]></dc:creator><pubDate>Sat, 02 May 2026 02:31:41 GMT</pubDate></item></channel></rss>