CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do
41 minutes Posted Jun 8, 2026 at 11:00 am.
Welcome And CISSP Mission
NCSC Warning On Supply Chains
Common Package Attacks Explained
Why Automation Makes It Worse
Five Actions To Reduce Risk
How Supply Chain Attacks Work
CI/CD Pipeline As Attack Multiplier
Building Secure SDLC And SBOM
Final Tips And Resources
0:00
41:38
Download MP3
Show notes
Send us Fan Mail Your software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines. I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We ...