Supply Chain Security [Tech Ops] episode artwork

EPISODE · Sep 20, 2024 · 17 MIN

Supply Chain Security [Tech Ops]

from cloud2030 · host the2030.cloud Podcast

In this episode, we dive deep into a recent and highly sophisticated SSH intrusion attack that was discovered in the Linux kernel. We'll discuss how the attackers were able to inject a backdoor into a critical compression library, leveraging social engineering tactics to become a trusted maintainer over several years. The attack was designed to bypass security checks and evade detection, even from advanced techniques like eBPF monitoring. We'll explore the technical details of how the backdoor was triggered, the potential impact on various Linux distributions, and the broader implications for software supply chain security. This incident highlights the challenges of maintaining trust in open-source projects and the need for robust security measures to protect critical infrastructure. Join us as we unpack this fascinating case and consider the lessons it holds for the future of secure software development.

Episode metadata supplied by the publisher feed · Published Sep 20, 2024

Embed this episode

Ready to play

Supply Chain Security [Tech Ops]

0:00 17:17

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of cloud2030?

This episode is 17 minutes long.

When was this cloud2030 episode published?

This episode was published on September 20, 2024.

Can I download this cloud2030 episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!