The Cyber Archive
Security domain
S

Supply Chain Security

All Deep Dives For Infosec Conference Talks Covering Supply Chain Security. Talks analyzed in full.

7 deep dives
5 conferences

Latest deep dives

Zeal of the Convert: Taming Shai-Hulud with AI | [un]prompted 2026
Unprompted 2026

Zeal of the Convert: Taming Shai-Hulud with AI | [un]prompted 2026

Learn how AI workflows, reasoning models, and feedback loops turned a two-week manual investigation into a two-day operation that identified 2,400 supply chain attack victims.

Rami Mccarthy 11 April 2026
Code Is Free: Securing Software | [un]prompted 2026
Unprompted 2026

Code Is Free: Securing Software | [un]prompted 2026

Learn how OpenAI engineers built LLM-powered security reviewers, living threat models, and a daily dependency scanner using ~40 lines of GitHub Actions YAML and checked-in Markdown files.

Paul Mcmillan Ryan Lopopolo 4 April 2026
The SCA Balancing Act
Owasp global appsec usa 2025

The SCA Balancing Act

Learn the three hidden costs of software composition analysis and how to match SCA tools to your AppSec program maturity.

Jamie Scott 29 March 2026
Plugins Gone Rogue: Attacking Developer Environments
Owasp global appsec usa 2025

Plugins Gone Rogue: Attacking Developer Environments

Learn how malicious VS Code extensions bypass Microsoft's safeguards to steal credentials and execute code on developer machines — and the only defense that actually works.

Raphael Silva 26 March 2026
AI Code Generation - Benefits, Risks and Mitigation Controls
Owasp global appsec usa 2024

AI Code Generation - Benefits, Risks and Mitigation Controls

Learn to assess AI code generation security risks—from package hallucination to IP liability—and apply governance controls that protect your SDLC.

Aruneesh Salhotra 19 February 2026
Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions
Owasp global appsec usa 2024

Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions

Learn how Snapchat uncovered three chained, high-impact bug bounty findings—supply chain RCE, Android deep link abuse, and Jupyter XSS-to-RCE—and the program capabilities each forced them to build.

Vinay Prabhushankar Murali Vadakke Puthanveetil 18 February 2026
Threat Modeling in the Age of AI
Owasp global appsec usa 2024

Threat Modeling in the Age of AI

Learn how to apply structured threat modeling to AI/ML systems using the ML SecOps framework, three diagnostic questions, and OWASP AI Exchange controls.

Susanna Cox 16 February 2026