Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding episode artwork

EPISODE · Jul 24, 2026 · 27 MIN

Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

from The Cyber Threat Perspective · host SecurIT360

Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you.Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple.From there it gets practical:What a Software Bill of Materials (SBOM) is and why you need oneTransitive dependencies — the packages hiding beneath your packagesBuilding security checks into your CI/CD pipeline and shifting leftWhy a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+Why a pen test should validate your controls, not be your first line of defenseHow SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilitiesA playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findingsThe takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaYPart 2 — Security Misconfigurations: https://youtu.be/Po8H140BijENeed a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blogBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Episode metadata supplied by the publisher feed · Published Jul 24, 2026

Embed this episode

Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you. Brad and Jordan cover both sides of supply chai...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

0:00 27:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cyber Threat Perspective?

This episode is 27 minutes long.

When was this The Cyber Threat Perspective episode published?

This episode was published on July 24, 2026.

Can I download this The Cyber Threat Perspective episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!