← Back to feed
PhishingEmerging1 sourceAug 31, 2026 · 20:31via Socket Security Blog

6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat

Brief

Socket CTO Ahmad Nassri recently sat down with five other AppSec leaders on The Secure Disclosure podcast for an unfiltered discussion on the state of software supply chain security.

Hosting six competing CTOs and security researchers in one room provided a candid look at how upstream threats are evolving, the operational limits of package registries, and why commercial threat intelligence siloing leaves engineering teams exposed. A few of the highlights:

Vulnerabilities vs. Active Malicious Intent AppSec still suffers from a fundamental confusion between vulnerable software (CVEs) and active malware. Threat actors aren't waiting around to exploit a known bug in your code. They are poisoning dependency trees, hijacking maintainer credentials, and executing malicious payloads during package installation.

Read more on Socket Security Blog