Open cardosec

Case A90C60 · Famous breaches · L4 Advanced

Supply-chain attacks compared

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SolarWinds: compromised vendor build system, signed malicious update pushed to ~18,000 customers
  2. NotPetya: hijacked M.E.Doc update server delivered a destructive wiper
  3. xz-utils: social-engineered open-source maintainership, backdoor hidden in release tarballs
  4. MOVEit: not a build compromise but one product zero-day mass-exploited across thousands of orgs
  5. Common defenses: SBOM, build provenance (SLSA), vendor risk tiers, least privilege and egress control for vendor software

If the interviewer pushes back

  • Which of these would SBOMs have helped with, and which not at all?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.