The Elephant in AppSec

← The Elephant in AppSec26 Nov 2025 · 41 min

The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed

The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed26 Nov 202541 min

<p>Today, I’m joined by Aamiruddin Syed, Senior Product Security Engineer at AGCO Corporation. </p><p>Aamiruddin is the author of “Supply Chain Software Security book focusing on AI, IoT, and AppSec” and a recognized advocate for secure development. He’s a frequent speaker at major conferences, including RSA, DEFCON, and Black Hat.</p><p>Fun facts: he was once ranked in the top 1% of all TryHackMe penetration testers, and a memorable milestone in his career was delivering a Cybersecurity Awareness talk to officer trainees of the Indian Army.</p><p>He’s also a fellow podcaster, co-hosting the CyberGPT Pulse Podcast.</p><p>In this episode, we dive into the complexities of software supply chain security, especially the risks introduced by third-party extensions, and how generative AI can strengthen defenses across the supply chain.</p><p>We also explore the challenges of data quality when training AI models and discuss why strong governance is essential for secure developer practices.</p><p>Dive right in!</p>