
Defending Against Software Supply Chain Attacks - Cyfinoid Research - DCTAC2025
Name of Training: Defending Against Software Supply Chain AttacksTrainer(s): Anant ShrivastavaDates: November 3-4, 2025Time: 8:00 am to 5:00 pm Venue: TBDCost: $2,200 Course Description: Software development is a collaborative effort. We do not build software alone; most of the time we depend on many moving parts. These moving parts form the software supply chain. Attackers succeed by linking small weaknesses across the entire chain. People and their workstations, source repositories, dependency ecosystems, remote and central package registries, third party SaaS, build and release workflows, containers, cloud infrastructure and runtime environments are all in scope. This two day hands on class focuses on defenders. We start by bringing everyone to the same base level of knowledge and shared terminology, then walk through a set of handpicked case studies. Each case study is a faithful replication of a real world attack. Our aims: Understand how the attack flow worked Identify which co