Can We Actually Fix Software Supply Chain Security? 6 AppSec Leaders Debate

August 27
53 mins

Episode Description

Software supply chain attacks have gone parabolic over the past year, turning open-source packages, CI/CD pipelines, and developer laptops into prime targets for state-sponsored threat actors and AI-augmented attacks.In this special roundtable panel, security leaders from Aikido Security, Socket, OX Security, Step Security, and open source malware.com come together for an unfiltered conversation on the supply chain security crisis. The panel dives into the real catalysts behind the rise of malware—from North Korean crypto-theft campaigns and weaponized GitHub Actions to the hidden dangers of prioritizing developer velocity over security checks and balances.You'll also learn the critical difference between standard CVE vulnerabilities and active malicious software, why package registries like npm face systemic security challenges, and practical steps engineering teams must take to protect their developer environments against upstream compromises.

See all episodes