CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know
43 minutes Posted Jun 29, 2026 at 11:00 am.
Welcome And Today’s Focus
Shiny Hunters Hit Oracle PeopleSoft
The Real Lesson: Vendor Oversight
Training Roadmap For CISSP Domains
What Supply Chain Security Really Means
Four Supply Chain Attack Vectors
How Supply Chain Maps To CISSP
Controls Before During After Vendors
SBOM Basics Plus Tools To Know
OAuth Token Abuse And Governance
Three Practice Questions Walkthrough
Manager Mindset And Final Takeaways
Where To Get More Help
0:00
43:08
Download MP3
Show notes
Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident. We walk through what supply chain security really means for modern cybersec...