<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously.]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://infosec.exchange/@ifin/116605052950779161" rel="nofollow noopener"><span>https://</span><span>infosec.exchange/@ifin/1166050</span><span>52950779161</span></a></p><p>I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.</p>]]></description><link>https://board.circlewithadot.net/topic/b8855fef-cf6b-49e0-bdf3-f92c7dcf3067/i-m-really-hoping-this-and-the-last-few-weeks-are-a-tipping-point-toward-taking-supply-chain-security-seriously.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 07:56:26 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/b8855fef-cf6b-49e0-bdf3-f92c7dcf3067.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 04:40:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 15:14:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> Not that we know which one and can check our own extensions to make sure we aren't compromised. That would be too much to ask!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Epic_Null/statuses/116607555676238409</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Epic_Null/statuses/116607555676238409</guid><dc:creator><![CDATA[epic_null@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 15:14:55 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 12:56:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/bovaz%40misskey.social" rel="nofollow noopener">@<span>bovaz</span></a></span> You know, I think the constant compromise of their repositories and credentials is something of a bother in and of itself</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/mttaggart/statuses/116607012354023295</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/mttaggart/statuses/116607012354023295</guid><dc:creator><![CDATA[mttaggart@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 12:56:44 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 09:49:03 GMT]]></title><description><![CDATA[<a href="/user/mttaggart%40infosec.exchange">@mttaggart@infosec.exchange</a> my fear is it's going to lead to more expensive and annoying policies from companies, bothering developers, so that compromised stuff is immediately deployed at company-scale.]]></description><link>https://board.circlewithadot.net/post/https://misskey.social/notes/amhg1zkkf2</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://misskey.social/notes/amhg1zkkf2</guid><dc:creator><![CDATA[bovaz@misskey.social]]></dc:creator><pubDate>Wed, 20 May 2026 09:49:03 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 09:19:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> <span><a href="/user/peter%40thepit.social">@<span>peter</span></a></span> that github news seems bad! <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f633.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--flushed" style="height:23px;width:auto;vertical-align:middle" title="😳" alt="😳" /></p>]]></description><link>https://board.circlewithadot.net/post/https://tilde.zone/users/mk30/statuses/116606156759182704</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tilde.zone/users/mk30/statuses/116606156759182704</guid><dc:creator><![CDATA[mk30@tilde.zone]]></dc:creator><pubDate>Wed, 20 May 2026 09:19:09 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 07:00:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><p>“Taking supply chain security seriously” involves laying off the productivity obsession and allowing programmers to remain calm, focused, and vigilant.</p><p>I don't think we're anywhere near that tipping point, unfortunately. Companies and politicians still think we can solve this problem with audits, regulations, and hoop jumping.</p><p>I discussed this in another thread earlier today: <a href="https://mastodon.sdf.org/@argv_minus_one/116602229559669722" rel="nofollow noopener noreferrer"><span>https://</span><span>mastodon.sdf.org/@argv_minus_o</span><span>ne/116602229559669722</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.sdf.org/users/argv_minus_one/statuses/116605610175097926</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.sdf.org/users/argv_minus_one/statuses/116605610175097926</guid><dc:creator><![CDATA[argv_minus_one@mastodon.sdf.org]]></dc:creator><pubDate>Wed, 20 May 2026 07:00:09 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 05:22:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange" rel="nofollow noopener">@<span>mttaggart</span></a></span> I'm sure vibe coding will make securing the supply chain easier and not harder /s</p>]]></description><link>https://board.circlewithadot.net/post/https://critter.cafe/users/luxliquida/statuses/116605227226243359</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://critter.cafe/users/luxliquida/statuses/116605227226243359</guid><dc:creator><![CDATA[luxliquida@critter.cafe]]></dc:creator><pubDate>Wed, 20 May 2026 05:22:45 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;m really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. on Wed, 20 May 2026 04:45:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> Gives me the chills. As a solo dev, my entire livelihood is tied to the integrity of my toolchain, and there's only so much I can realistically audit myself.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116535831720048152/statuses/116605082261737233</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116535831720048152/statuses/116605082261737233</guid><dc:creator><![CDATA[shadowfetchai@mastodon.social]]></dc:creator><pubDate>Wed, 20 May 2026 04:45:53 GMT</pubDate></item></channel></rss>