4 ms·
Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is wh
by robshippr 6mo ago
Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.
- yieldcrv 6mo ago> SOC2 won't catch this Cybersecurity professionals and their certification treadmill crack me up because of this They get paid less, require more certifications to be marketable, all to simply show actual “computer wizards” where all the blind spots are
- fancy_pantser 6mo agoI am not disagreeing with your main point, but want to clarify that SOC2 is not an individual certification that a person achieves.
- jeremie_strand 6mo ago[dead]