Listen "Supply Chain Security"
Episode Synopsis
Send us a textDespite the media coverage afforded to the SolarWinds and Kaseya breaches, Palo Alto Networks, Unit 42 threat research indicates supply chain security in the cloud continues its growth as an emerging threat. Much remains misunderstood about both the nature of these attacks and the most effective means of defending against them. To better understand how supply chain attacks occur in the cloud, Unit 42 researchers analyzed data from a variety of public data sources around the world and, at the request of a large SaaS provider, executed a red team exercise against their software development environment. As you'll hear in the podcast, overall, the findings indicate that many organizations may still be lulled into a false sense of supply chain security in the cloud. Case in point: Even with limited access to the customer’s development environment, it took a single Unit 42 researcher only three days to discover several critical software development flaws that could have exposed the customer to an attack similar to that of SolarWinds and Kaseya. In the podcast, Unit 42 researchers Nathaniel "Q" Quist and Dr. Jay Chen, draw on Unit 42’s analysis of past supply chain attacks. The Cloud Threat Report explains the full scope of supply chain attacks, discusses poorly understood details about how they occur, and recommends actionable best practices that organizations can adopt today to help protect their supply chains in the cloud. The future of cloud security.Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
More episodes of the podcast Cloud Security Today
From GTA to MFA
08/11/2025
CISO burnout and boardroom truths
01/09/2025
Iron Maiden and cloud security
14/07/2025
Navigating identity security
29/05/2025
The human side of cyber
22/04/2025
Principles in cyber leadership
23/03/2025
Rethinking security awareness
23/02/2025
Dr. Zero Trust on zero trust
20/01/2025
Cybersecurity compensation 2025
20/12/2024
LLMs: risks, rewards, and realities
20/11/2024
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.