Jul 19, 2024
Unmasking the Biggest Supply Chain Attack: Insights from JFrog’s Security Expert
In this weekend edition of Hashtag Trending, host Jim Love dives deep into the world of supply chain attacks with Brian Moussalli, Security Research Team Lead at JFrog. They discuss some of the most notorious supply chain attacks in history, including SolarWinds and Kaseya, and shed light on a recent potentially massive Python security leak. Learn about the mechanisms behind these attacks, the importance of inspecting binary files, and the role JFrog plays in securing the open source community. Tune in for an insightful discussion on building more secure software and safeguarding the supply chain.
00:00 Introduction and Host Welcome
00:05 Understanding Supply Chain Attacks
00:54 Notable Supply Chain Attacks
02:20 Introduction to Guest Brian Moussalli, Security Research Team
Lead at JFrog
03:40 JFrog's Role and Mission
05:48 Discovery of the Python Token Leak
11:09 Implications of the Leak
16:39 Lessons Learned and Security Recommendations
18:29 Optimism and Challenges in Open Source Security
22:39 Conclusion and Farewell