Below the Surface (Audio) - The Supply Chain Security Podcast

← Below the Surface (Audio) - The Supply Chain Security Podcast19 May · 55 min

YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74

YellowKey, CVE Enrichment, Chipmaker Breach - BTS #7419 May55 min

In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats.

Topics https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

https://github.com/Nightmare-Eclipse/YellowKey

https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack

https://x.com/AlvieriD/status/2053835732658143416

Chapters

00:00 Introduction to Vulnerability Research and AI

03:42 NIST and CVE Growth Challenges

06:46 Building Tools for CVE Analysis

10:58 The Complexity of CVSS Scoring

15:08 CISA's Role in Vulnerability Enrichment

18:06 Challenges in CWE and CPE Data