The Cyber Threat Perspective
The Cyber Threat Perspective
SecurIT360
Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding
27 minutes Posted Jul 24, 2026 at 10:00 am.
Part 3: Software Supply Chain Failures (A03)
Why supply chain topped the OWASP survey
Why almost no one writes code from scratch anymore
Two kinds of supply chain risk: whole apps vs. components
The SolarWinds breach
How AI and vibe coding make it worse
What is an SBOM?
Security checks in your CI/CD pipeline
Shift-left: why a flaw found late costs 100x more
The cake analogy
Transitive dependencies
Project Lantern & ChainGarde
Pen testing as validation, not discovery
Testing third-party apps and going straight to the vendor
Be the hammer you beat your vendor with
Vetting vendors: who ran the pen test matters
Holding vendors accountable to fix findings
Contracts, SLAs, and tools you already own
Risks you can't fix — and why awareness still matters
0:00
27:41
Download MP3
Show notes
Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you. Brad and Jordan cover both sides of supply chai...