Case A90C60 · Famous breaches · L4 Advanced
Supply-chain attacks compared
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- SolarWinds: compromised vendor build system, signed malicious update pushed to ~18,000 customers
- NotPetya: hijacked M.E.Doc update server delivered a destructive wiper
- xz-utils: social-engineered open-source maintainership, backdoor hidden in release tarballs
- MOVEit: not a build compromise but one product zero-day mass-exploited across thousands of orgs
- Common defenses: SBOM, build provenance (SLSA), vendor risk tiers, least privilege and egress control for vendor software
If the interviewer pushes back
- Which of these would SBOMs have helped with, and which not at all?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.