<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Supply Chain on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/supply-chain/</link>
    <description>Recent content in Supply Chain on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 22 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/supply-chain/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Heads-up: TROOPERS Roundtable – Supply Chain Security</title>
      <link>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</guid>
      <description>&lt;h2 id=&#34;how-to-strengthen-supply-chain-security-practical-exchange-and-roadmap&#34;&gt;How to strengthen Supply Chain Security: Practical Exchange and Roadmap&lt;/h2&gt;&#xA;&lt;p&gt;Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.&lt;/p&gt;&#xA;&lt;p&gt;We will examine:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;How SBOM, CSAF and VEX relate and why version-level detail matters.&lt;/li&gt;&#xA;&lt;li&gt;The practical value of an SBOM and why it’s increasingly required by law and IT procurement.&lt;/li&gt;&#xA;&lt;li&gt;How to create and consume SBOMs?&lt;/li&gt;&#xA;&lt;li&gt;Methods to identify dependencies in the context of vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Approaches to triage: not all vulnerabilities affect every stakeholder equally.&lt;/li&gt;&#xA;&lt;li&gt;Techniques to analyze vulnerabilities and identify affected products and product families.&lt;/li&gt;&#xA;&lt;li&gt;Sources of vulnerability information and how to map data unambiguously to products and specific software versions.&lt;/li&gt;&#xA;&lt;li&gt;Reporting obligations: where and how to disclose vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Tools and automation that help manage information volume and complexity.&lt;/li&gt;&#xA;&lt;li&gt;Technical, organizational and personnel challenges to achieving end-to-end supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;The role of AI in supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;How do we protect ourselves from malicious actors / infected dependencies?&lt;/li&gt;&#xA;&lt;li&gt;The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.&lt;/li&gt;&#xA;&lt;li&gt;We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Smart (and Scary) Supply Chain Attack</title>
      <link>https://insinuator.net/2011/08/smart-and-scary-supply-chain-attack/</link>
      <pubDate>Thu, 04 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/08/smart-and-scary-supply-chain-attack/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.cisco.com/en/US/products/csr/cisco-sr-20110803-cd.html&#34;&gt;This advisory&lt;/a&gt; describes an interesting attack vector:&lt;/p&gt;&#xA;&lt;p&gt;“In the period of December 2010 until August 2011, Cisco shipped warranty CDs that contain a reference to a third-party website known to be a malware repository. When the CD is opened with a web browser, it automatically and without warning accesses this third-party website. Additionally, on computers where the operating system is configured to automatically open inserted media, the computer’s default web browser will access the third-party site when the CD is inserted, without requiring any further action by the user.”&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
