
← Below the Surface (Audio) - The Supply Chain Security Podcast19 May · 55 min
YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74
In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats.
Topics https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth
https://github.com/Nightmare-Eclipse/YellowKey
https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack
https://x.com/AlvieriD/status/2053835732658143416
Chapters
00:00 Introduction to Vulnerability Research and AI
03:42 NIST and CVE Growth Challenges
06:46 Building Tools for CVE Analysis
10:58 The Complexity of CVSS Scoring
15:08 CISA's Role in Vulnerability Enrichment
18:06 Challenges in CWE and CPE Data