CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)
33 minutes Posted Aug 17, 2026 at 11:00 am.
Welcome And Domain 8 Setup
ChainDrop Hits The NPM Ecosystem
Why Supply Chain Is Perimeter
Four Pillars To Assess Risk
Turning Pillars Into Daily Practice
ChainDrop Steps And How It Spreads
SolarWinds And Log4Shell Parallels
Exam Focus On Lifecycle Thinking
Practice Questions And Common Traps
CISSP Sprint Cohort Invitation
Reviews YouTube And Free Questions
0:00
33:04
Download MP3
Show notes
Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t b...