The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/CISSP Cyber Training Podcast
CISSP Cyber Training Podcast artwork

CCT 359: ShinyHunters vs. Oracle - Supply Chain Risk Every CISSP Must Know

CISSP Cyber Training Podcast · 2026-06-29 · 43 min

0:00--:--

Key moments - from our scoring

Substance score

32 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality6 / 20
Guest Caliber5 / 20
Specificity & Evidence9 / 20
Conversational Craft4 / 20

ShinyHunters' compromise of Oracle PeopleSoft exposed over 100 organizations and hundreds of thousands of student records - but without malware or zero-days. Host Sean Gerber breaks down this supply chain attack as a textbook example of implicit vendor trust becoming an attack surface. The episode examines how threat actors like ShinyHunters (also active against Salesforce, Snowflake, and others) bypass firewalls entirely by compromising trusted platforms, then pivot using stolen OAuth tokens and credentials. CISSPs and security leaders will learn the four primary supply chain attack vectors, third-party risk management imperatives, and how the vulnerability maps to CISSP domains one, three, five, and eight. The training covers SBOMs, OAuth token abuse mechanics, and FERPA-regulated data exposure in higher education - critical knowledge for exam preparation and operational security programs focused on vendor oversight, access inventory, and implicit trust elimination.

Key takeaways

  • →Supply chain attacks exploit implicit trust in vendors rather than requiring malware or zero-days, with attackers gaining access through third-party credentials and OAuth tokens to reach target environments.
  • →Vendor management and third-party risk assessment programs are mandatory security controls to identify what access vendors have, what data they can reach, and potential blast radius if they're compromised.
  • →The ShinyHunters represent a strategic pattern of targeting widely-deployed enterprise platforms like Oracle PeopleSoft, Salesforce, and Snowflake to compromise hundreds of organizations simultaneously through a single vulnerability.
  • →Supply chain risk spans six external dependency categories: hardware vendors, software vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access.
  • →The CISSP exam tests supply chain security mechanics across domains one, three, five, and eight, particularly focusing on risk identification, vendor access controls, and authentication token management.

In this episode

  1. 1ShinyHunters Oracle PeopleSoft Attack and Supply Chain Risks
  2. 2Understanding Supply Chain Security and External Dependencies
  3. 3Implicit Trust in Vendors as Attack Surface
  4. 4Supply Chain Attack Vectors: Credentials, Tokens, and Malicious Code Injection
  5. 5CISSP Domain Mapping and Third-Party Risk Management

Mentioned

ShinyHuntersOraclePeopleSoftSalesforceSnowflakeSolarWindsVerizonSean GerberCISSP Cyber TrainingMythosGitHubOAuth

Topics in this episode

SalesforceSnowflakeThird party risk managementSolarWindssupply chain attacksShinyHunters threat groupOracle PeopleSoftOAuth tokensFERPA regulated dataVerizon 2026 Data Breach Investigation Report

Questions this episode answers

How did ShinyHunters compromise over 100 organizations without using malware or zero-days?

ShinyHunters exploited implicit trust in Oracle PeopleSoft by compromising the vendor platform itself, then used stolen OAuth tokens and credentials to pivot into customer environments. They didn't need to attack firewalls directly - they accessed organizations through the trusted third-party vendor they all relied on.

What types of student data were exposed in the Oracle PeopleSoft breach?

The compromised data included student names, home addresses, phone numbers, emails, dates of birth, and GPAs. This constitutes FERPA-regulated data that can be used for identity theft, targeted phishing, and financial fraud.

What is the key vulnerability that ShinyHunters and other supply chain attackers exploit?

Implicit trust in vendors is the vulnerability attackers exploit. Organizations trust their vendors are secure without verifying vendor access levels, credentials, or what data those vendors can reach - creating an attack surface threat actors actively target.

What are the four primary supply chain attack vectors that will appear on the CISSP exam?

The four vectors are: (1) compromised credentials and OAuth tokens, (2) malicious code injection into software build pipelines, (3) open source library vulnerabilities, and (4) direct vendor platform compromise - all of which bypass direct perimeter attacks.

What must organizations implement to defend against supply chain attacks like the ShinyHunters Oracle campaign?

Organizations must build vendor management and third-party risk management programs that inventory what vendors have access to, their privilege level, and what specific data they can reach - gaps that most organizations cannot quickly answer, according to the episode.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode covers a real breach with supply chain mechanics (OAuth token abuse, SBOM tooling, offboarding failures) at a useful level of clarity, but the B2B operator value is diluted by heavy exam-prep framing, repeated domain reminders, and several commercial plugs for a CISSP cohort. Actionable ideas appear, but the signal-to-noise ratio is moderate.

You do not need malware or zero days to cause massive damage. All you need is access, right?
a stale bus SBOM is almost as dangerous as no SBOM at all

Originality

6 / 20

All content is standard vendor risk management and CISSP curriculum repackaged around a timely breach news hook. The valet-key and nutrition-label analogies are well-worn, and every recommendation (least privilege, right to audit, token rotation) is orthodox industry doctrine with no contrarian or first-principles angle offered.

Think of it as the nutrition label for your software.
Think of it like a valet key.

Guest Caliber

5 / 20

This is a solo-host episode with no guest. Sean Gerber presents as a CISSP trainer with a claimed red team background, but he is operating primarily as a certification educator rather than an active practitioner at scale, which limits the practitioner depth that would raise this score.

Hi, my name is Sean Gerber. I'm your host of the Active Active Formative Podcast.
When I did this as a red team, we looked for credentials because we wanted to get lost in the noise.

Specificity & Evidence

9 / 20

The episode names concrete breach details (100+ orgs, June 10th Oracle advisory, FERPA-regulated student data types), a specific SBOM tool stack (Syft, Grype, Snyk, OWASP Dependency-Check, Black Duck), and a government executive order. Points deducted for apparent errors (EO cited as '414028' vs. 14028; 'Verizon 2026 DBIR') and frequent vague qualifiers like 'most organizations I talk to.'

Over 100 organizations have been compromised and hundreds of thousands of student records have been stolen.
Oracle published a security advisory on June 10th, the same day the attacks were reported

Conversational Craft

4 / 20

This is an entirely solo monologue with scripted, self-answered practice exam questions - there is no guest, no follow-up, no intellectual friction, and no productive disagreement. Rhetorical questions are immediately resolved by the host, producing no conversational tension or depth.

So again, you need to think like a manager. You don't need to be a technician, you need to be a manager.
We don't want to fail. Do not fail. Failing is bad.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

vendor54access49cissp35exam33security30oauth24audit24token24supply23tokens23chain22attack22data21risk20domain20software19

Episode notes

Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident. We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it’s not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician. Then we go deeper on two concepts that keep showing up in both real breaches and exam questions.

Full transcript

43 min

Transcribed and scored by The B2B Podcast Index.

1 - > SPEAKER_00: Welcome to the CISSP Cyber Training Podcast. 2 - > Where we provide you the training and tools you need to 3 - > pass the CISSP exam first. 4 - > Hi, my name is Sean Gerber. 5 - > I'm your host of the Active Active Formative Podcast.

6 - > Join me each week as I provide the information you need to pass 7 - > the CISSP exam and grow your cyber sector in knowledge. 8 - > Alright, let's get started. 9 - > SPEAKER_01: Good morning, everybody. 10 - > It's Sean Gerber with CISSP Cyber Training and hope you all 11 - > are having a beautifully blessed day today.

12 - > Today is Monday, and Monday we typically go over all the 13 - > aspects related to the CISSP to include training as well as some 14 - > CISSP questions. 15 - > So it's going to be a great episode today. 16 - > I'm pretty excited about this. 17 - > We are going to be getting into supply chain risks.

18 - > We're going to be talking about the Shiny Hunters exploits on 19 - > Oracle's PeopleSoft, and then we're going to roll into some 20 - > basic supply chain risks that are tied to the various domains 21 - > that are out there. 22 - > This is all part of the CISSP cyber training's ability to help 23 - > you get and study for the CISSP exam. 24 - > So before we get into that, one thing I actually want to bring 25 - > up to you all if you've all seen it or not is related to the 26 - > mythos release.

27 - > I saw this maybe just yesterday, where Mythos is now going to be 28 - > released to the US government for critical infrastructure 29 - > protection. 30 - > So it'll be interesting to see when this actually hits the 31 - > streets for the rest of us, but uh it's it's looking pretty 32 - > awesome. 33 - > So I'm pretty excited about that and then how that can be 34 - > implemented within the various security tools and practices 35 - > that are out there. 36 - > So pretty cool, pretty awesome.

37 - > But let's get into the article I'm going to talk about today 38 - > that I thought was very interesting uh related to the 39 - > Shiny Hunters exploits, Oracle's People Soft Zero Day to breach 40 - > universities. 41 - > Okay, so this hits close to home because it's a lot of first for 42 - > a lot of different organizations where this could be a problem. 43 - > So we're talking about the Shiny Hunters Group and their latest 44 - > campaign targeting Oracle's People Soft servers and colleges 45 - > and universities across the country.

46 - > Over 100 organizations have been compromised and hundreds of 47 - > thousands of student records have been stolen. 48 - > So what's the worst part about all this? 49 - > Well, it wasn't a zero-day exploit. 50 - > This was a supply chain attack.

51 - > If you don't know the Shiny Hunters, well, you need to. 52 - > This group has been one of the most active and destructive 53 - > threat actors for the last several years. 54 - > They've gone through Salesforce, Sales Soft, Snowflake, 55 - > Infrastructure Canvas, and now they're on to Oracle's 56 - > PeopleSoft. 57 - > So what makes them so dangerous?

58 - > Isn't that they're not using exotic malware, it's that they 59 - > don't need to. 60 - > The Shiny Hunters are proving something that every security 61 - > manager needs to hear. 62 - > You do not need malware or zero days to cause massive damage. 63 - > All you need is access, right?

64 - > We've talked about this over and over again at CISSP Cyber 65 - > Training. 66 - > It's the access. 67 - > And that access, they're getting through to from everything to 68 - > your vendors. 69 - > And that's where we talk about how you need to have a 70 - > third-party risk management program in place at any of your 71 - > companies that you're working with.

72 - > So here's how it went down. 73 - > Shiny Hunters claimed to have compromised Oracle's PeopleSoft 74 - > servers across more than 100 different organizations. 75 - > So with the bulk of the victims being colleges and universities. 76 - > The group contacted one of the affected schools directly and 77 - > shared a sample of the data that they stole to prove that they 78 - > actually had it.

79 - > So what was in that data? 80 - > Student names, home addresses, phone numbers, emails, data 81 - > births, you name it, it keeps going on, right? 82 - > GPAs, all of those aspects. 83 - > So this isn't just embarrassing, it's a FERPA regulated data.

84 - > And this data can be used for identity theft, targeted 85 - > phishing, and financial fraud. 86 - > So depending on what else they pulled, it could potentially be 87 - > even more damaging. 88 - > So Oracle published a security advisory on June 10th, the same 89 - > day the attacks were reported, urging immediate mitigations and 90 - > noting that only supported versions of the people tools 91 - > were tested for the flaw. 92 - > So unsupported versions out there, you can assume they will 93 - > be as vulnerable as well.

94 - > So this is a big deal, right? 95 - > This is something that you all have to be aware of related to 96 - > supply chain risks. 97 - > So here's what I really want you to understand. 98 - > This attack isn't just about Oracle or PeopleSoft.

99 - > This is part of a year-long campaign from Shiny Hunters, 100 - > hunting for shared vulnerabilities in widely 101 - > deployed enterprise solutions. 102 - > Think about that for just a minute. 103 - > So when an attacker compromises a platform that thousands of 104 - > organizations use, they don't have to attack you directly, 105 - > right? 106 - > That's all done through these third parties.

107 - > They get access to your vendors. 108 - > And through that vendor, they walk right into your 109 - > environment. 110 - > And this is the exact pattern we saw with Salesoft and with 111 - > Drift, right? 112 - > Where the attackers use compromised OAuth tokens to 113 - > access Salesforce customer environments.

114 - > And we talk about OAuth tokens a lot in CISP Cyber Training. 115 - > And I'm also going to get into just a little bit about OAuth 116 - > tokens later on in this episode. 117 - > So it's the same playbook. 118 - > Trusted vendor gets hit, OAuth tokens or credentials get 119 - > stolen, attacker then pivots your organization without you 120 - > ever touching your perimeter.

121 - > So Verizon's 2026 data breach investigation report continues 122 - > to call out the vendor-mitigated intrusions as the leading attack 123 - > pattern. 124 - > So why is this the case? 125 - > Well, why would I go attack somebody from the front when I 126 - > can attack all the people from the rear? 127 - > That is it's just it's a really great attack tactic, but it is 128 - > something that you all are vulnerable.

129 - > We all are vulnerable to this. 130 - > So this is not a fluke, this is a strategy. 131 - > So what is the takeaway in all of this? 132 - > So what does it mean for you?

133 - > Whether you're studying for the CISSP or you're already a 134 - > security leader, the lesson here is the same. 135 - > Build a veteran management and third-party oversight program 136 - > into your security program and make sure this is not an option 137 - > anymore. 138 - > You have to do it. 139 - > You need to make sure that you have a third-party risk 140 - > management program, you have a vendor management program, all 141 - > of those are in place within your organization.

142 - > You need to build this. 143 - > You need to build it. 144 - > It's not you you think about it, you really must build it. 145 - > So you have to know what vendors have access to in your 146 - > environment.

147 - > If you don't know that, that's a gap. 148 - > That's a true gap. 149 - > What level of access do they actually have? 150 - > And what data can they specifically reach?

151 - > This is what happens to your organization if they get 152 - > breached. 153 - > Most orgs I talk to cannot answer those questions quickly, 154 - > and that's the gap. 155 - > These threat actors are exploiting. 156 - > If you don't know this information, you do have a 157 - > problem and you need to address it quickly.

158 - > The great news though is that you can. 159 - > It's not a problem to do so. 160 - > You just need to have a structured, coordinated effort 161 - > in doing that. 162 - > So, as someone who's studying for the CISSP, this maps 163 - > directly domain ones and domain three, risk management and 164 - > security architecture.

165 - > And we're going to go deep into that in the next section here 166 - > related to the training piece of this coming up next. 167 - > All right, so a quick recap before we move on. 168 - > So Shiny Hunters hit Oracle's PeopleSoft, 100 plus 169 - > organizations, student data is involved, thousands of records, 170 - > hundreds of thousands of records, supply chains attacked 171 - > through trusted vendors, and no malware needed, just access, 172 - > right? 173 - > So this is part of a larger campaign that you all need to be 174 - > aware of.

175 - > All right, so if you are studying for the CISSP and you 176 - > want structured help across the getting across the finished 177 - > land, go to CISSP Cybertraining.com and check out 178 - > what I've got. 179 - > Uh, just a quick shout out. 180 - > I am almost full with my Sprint CISSP cohort.

181 - > Eight weeks for you to complete the CISSP exam. 182 - > All the training you need to be ready to take the exam at the 183 - > end of that eight-week course. 184 - > So yeah, I've only got two slots left. 185 - > That was my first cohort that we've been doing to try to 186 - > figure this out and to go, how is this a need?

187 - > And it has definitely proven there is a substantial need 188 - > there. 189 - > So we're excited about that. 190 - > Having the first cohort will begin July 7th. 191 - > So if you are interested, two more slots left.

192 - > That's all I have, and they will be taken here soon. 193 - > I know it. 194 - > Uh so again, go check out CISSP Cyber Training and look at the 195 - > cohort that's available so that you can be ready to take the 196 - > exam the end of August, first part of September. 197 - > Okay, so let's move on to our training for today.

198 - > So, what we're gonna be covering today, what supply chain 199 - > security risks actually means and why it's the biggest, bigger 200 - > than you think, how attackers are exploiting it right now, how 201 - > the CICP exam maps it across all four domains that are there, 202 - > one, three, five, and eight, and then the controls that stop 203 - > these attacks before, during, and after the vendor 204 - > relationships. 205 - > There'll also be a deep dive into S bombs and how what they 206 - > are, how to store them and what tools you need to know, and then 207 - > on OAuth tokens, how they work, how they get abused, and the 208 - > controls the exam will test you on specifically.

209 - > And then I'm gonna throw you three practice tech question 210 - > exam practice exam questions with a multiple choice 211 - > walkthrough, right? 212 - > So you're gonna kind of get into those pieces related to the 213 - > CISSP and the exam questions you can potentially expect. 214 - > So let's get into what is supply chain security. 215 - > So let's start with the fundamentals.

216 - > What is supply chain in cybersecurity? 217 - > And I want you to think much bigger than that it's the vendor 218 - > we buy our software from, right? 219 - > That's what a lot of us think. 220 - > But if you look at this slide, your supply chain includes six 221 - > different categories with external dependencies.

222 - > So those that are listening, we'll just go through it. 223 - > But if you're watching it, you'll be able to see the six 224 - > dependencies as well. 225 - > So hardware vendors, the companies that are making your 226 - > servers, your routers, and your chips. 227 - > Your software vendors, the companies whose code is actively 228 - > running on your systems in your system right now.

229 - > So all of that code, whether it's stuff that you've created 230 - > with using dependencies and libraries or stuff from third 231 - > parties. 232 - > Cloud service providers, the platforms where your data lives 233 - > and where it operates. 234 - > And then managed service providers, the companies that 235 - > have admin-level access to your environments and your 236 - > infrastructure. 237 - > These MSPs can be a huge way into your company.

238 - > Open source libraries, the code your developers pulled from 239 - > GitHub or NPN or PY, PI, and your baked-in applications. 240 - > And then the contractors and consultants, the humans with 241 - > privileged access who are not on your payroll. 242 - > And that is where I run, right? 243 - > You run as a consultant.

244 - > I deal with this all the time. 245 - > So every single one of those is a link into your supply chain, 246 - > and every single one of them can specifically be compromised. 247 - > It's not just a matter of if, it's a matter of when. 248 - > So now here's a key concept from the bottom of the slide that I 249 - > want you to keep in mind.

250 - > And I want you to lock this in before we go any further. 251 - > Implicit trust in vendors is the vulnerabilities attackers 252 - > exploit. 253 - > So again, implicit trust in vendors is the vulnerability 254 - > attackers will exploit. 255 - > So if you trust the Oracle PeopleSoft is secure, and you 256 - > trust that your open source library, your dev team pulled 257 - > last week is clean, which we've talked about multiple times, 258 - > your trust you're in that MSP is protecting their admin 259 - > credentials, that is implicit trust.

260 - > That is an attack surface. 261 - > That's what they're going to come after. 262 - > So Shiny Hunters didn't attack your firewall. 263 - > They exploited the implicit trust that universities have 264 - > placed in their PeopleSoft environment.

265 - > So from a CISSP domain one standpoint, this is a risk 266 - > management problem. 267 - > Before anything else, that's it. 268 - > You cannot manage risk you haven't identified. 269 - > And in most organizations, they have not done a thorough job of 270 - > mapping their supply chain risk exposure.

271 - > And that's going to be on the exam. 272 - > It truly will, because it's becoming one of the number one 273 - > ways that people are getting access into the various 274 - > different types of companies. 275 - > So it's going to show up in your career and it's going to be on 276 - > the exam. 277 - > So let's start planning for it right now.

278 - > All right, so let's talk about how these attackers, attacks, 279 - > actually work. 280 - > So because the CISSP is going to test you on the mechanics, not 281 - > just whether you know that a supply chain attack exists, 282 - > there are four primary attack vectors that you need to know 283 - > stone cold, right? 284 - > Number one, compromised credentials and OAuth tokens. 285 - > This is the Shiny Hunters playbook.

286 - > They did not hack your firewall. 287 - > They compromised a trusted vendor that already had OAuth 288 - > tokens connected into your or their environment. 289 - > And they use these tokens to walk right in. 290 - > So there's your tokens.

291 - > These are shared secrets that are stored. 292 - > No malware, no brute force, no alerts triggered. 293 - > Why? 294 - > Because they're expected.

295 - > Because the access looked completely legitimate. 296 - > This is a tape textbook thing of what we did as a hacker. 297 - > When I did this as a red team, we looked for credentials 298 - > because we wanted to get lost in the noise. 299 - > But I want you to understand right now that this is the 300 - > number one supply chain vector active in the real world today.

301 - > So number two, malicious code injection. 302 - > Now this is the SolarWinds model. 303 - > This is where the attacker doesn't target you directly. 304 - > They compromise a software vendor's build pipeline, right?

305 - > So they're over CI CD pipeline, they actually compromise that. 306 - > They insert malicious code into legitimate software updates. 307 - > You download the update date, you run it, and you just install 308 - > the attacker's backdoor. 309 - > It wasn't somebody else doing it, you did it to you.

310 - > So the CISSP exam will test you on the controls that catch this 311 - > code signing, software bill of materials, or also known as the 312 - > SBOM, and secure software development practices. 313 - > We'll be covering the SBOM in detail on the next slide as we 314 - > go into this after the domain mapping and control sections. 315 - > But you're going to get into an SBOM and kind of give you a 316 - > little bit more of a heads up on that. 317 - > Number three, open source package attacks.

318 - > So developers are using open source packaging constantly. 319 - > All of your developers are using it. 320 - > If you have developers in your team, they are using it. 321 - > No question about it.

322 - > So NPM, PYPY, Maven, all of these are repositories that our 323 - > modern software is built on. 324 - > And attackers compromise these packages through typosquatting. 325 - > So this is registering a package name one character off from a 326 - > legitimate library and waiting for the developer to fat finger 327 - > the install command. 328 - > They're also doing it through expired domain takeovers, buying 329 - > up a domain of a dead package and pushing malicious updates to 330 - > anyone still using it.

331 - > And maintainer account compromise. 332 - > This is taking over an account of a legitimate package 333 - > maintainer and pushing malicious code through a trusted channel. 334 - > So this is domain eight territory, software development 335 - > security. 336 - > And as we talk about the CISSP, you can see just in this 337 - > situation, there are multiple domains being covered at any one 338 - > point in time.

339 - > And your software development piece, this is growing super 340 - > fast. 341 - > I mean, we talk about it almost every episode. 342 - > There's some level of development work that's being 343 - > compromised. 344 - > So number four, hardware implants and tampering.

345 - > This is one is more common in government and defense 346 - > environments, but it's absolutely on the CISSP exam. 347 - > Nation state actors have tampered with hardware during 348 - > manufacturing or shipping processes. 349 - > These controls are trusted supply chain programs and the 350 - > hardware verification processes that are baked all into this. 351 - > NSA and CISA both have guidance on this.

352 - > So you need to know those four vectors cold. 353 - > Compromised credentials and OAuth tokens, malicious code 354 - > injection, open source of package attacks, and hardware 355 - > tampering. 356 - > Every one of these is going to show up in some form or fashion 357 - > on the CISSP exam. 358 - > So you need to be prepared to understand those.

359 - > Again, this is all based on the fact vectors that we're talking 360 - > about. 361 - > This is for hardware verification process. 362 - > And the four that you need to understand are compromised 363 - > credentials and OAuth tokens, malicious code injection, open 364 - > source package attacks, and hardware tampering. 365 - > Okay, so now let's map all of these to the CISP domains 366 - > because this is where a lot of candidates get tripped up on the 367 - > exam.

368 - > Supply chain shows up across multiple domains. 369 - > It's not just one domain. 370 - > And the test is going to put in situations where you have to 371 - > think across boundaries of the domains. 372 - > So domain one, security and risk management.

373 - > This is a primary domain for supply chain and third-party 374 - > risk management, vendor due diligence, contractual security 375 - > requirements, and risk assessments for vendors. 376 - > This is a key piece that you will we will talk about at CISSP 377 - > Cyber Training, as well as in my Sprint cohorts. 378 - > So the classic exam questions here you put you in a manager's 379 - > seat and ask you what should you do first? 380 - > When onboarding a new vendor, the answers almost always start 381 - > with a risk assessment.

382 - > Yes, do not sign the contract, not connect them to your 383 - > network, not trust their security attestations, because 384 - > they will put those out there. 385 - > It's no, you need to do a risk assessment. 386 - > So you really need to assess the risk first. 387 - > Then get your security requirements into the contract 388 - > as well.

389 - > Now, if they don't want to let you do that, you're gonna want 390 - > to then see if they have done any other security assessments 391 - > that are they're certified for and kind of go down that path. 392 - > But try to get the security assessment done of them before 393 - > you sign any contract, especially a long-term, 394 - > long-term contract. 395 - > Domain three, security architecture and engineering. 396 - > Defense in depth applies to the supply chain.

397 - > You should not assume a vendor's code is clean. 398 - > No, do not. 399 - > It's full of lice. 400 - > I guarantee you it's gonna have some challenges.

401 - > You definitely should test it. 402 - > Network segmentation does matter. 403 - > If a vendor has access to your network, that access should be 404 - > scoped to only what they need. 405 - > And you're gonna need to do that.

406 - > It's it's so easy just to go, you know what, we'll give you a 407 - > VPN and let you run on in here and have a good time. 408 - > Don't do that, please don't. 409 - > They need to have their own segmentation within their 410 - > network. 411 - > This needs to be principles of leave privilege, applies to 412 - > vendors exactly as much as it applies to employees.

413 - > Domain five, that's identity and access management. 414 - > This is where OAuth tokens live. 415 - > This is where the vendor privileges access live. 416 - > So, questions here will focus on how do you control what a vendor 417 - > can access?

418 - > How do you revoke that access when your relationship ends? 419 - > And it will end. 420 - > It ends with everybody. 421 - > How do you audit that vendor activity?

422 - > This would be just in time access, privilege access 423 - > workstations, session recording for vendor remote access. 424 - > These are the controls the exam loves. 425 - > Now, domain eight, software development security. 426 - > SBOM, software bill of materials.

427 - > The SBOM is cool. 428 - > It's the BOM. 429 - > So that's really dated me. 430 - > Security, uh secure SDLC practices, code signing, and 431 - > integrity verification, and as well as defendency scanning.

432 - > So as you read at the bottom of the slide, I call out I put out 433 - > there for a reason. 434 - > The CISSP is not testing whether you can react to a supply chain 435 - > attack, it is testing whether you can build a program that 436 - > prevents and detects them. 437 - > Again, build the program. 438 - > Think program.

439 - > It's not just an incident. 440 - > This is the think like a manager manager mindset that separates 441 - > the candidates who pass from the candidates who do not pass, or 442 - > should I say fail. 443 - > We don't want to fail. 444 - > Do not fail.

445 - > Failing is bad. 446 - > Okay, so let's get into the supply chain controls. 447 - > So I want you to think about this in three different phases. 448 - > So before you bring a vendor in, while the vendor relationship is 449 - > active, and after the relationship terminates, you no 450 - > longer are dating, you're no longer engaged, you have been 451 - > divorced.

452 - > Okay, so before due diligence, do a security questionnaire, 453 - > review the SOC2 type 2 report or equivalent third-party audit. 454 - > Those are a big factor. 455 - > And I would use those audits in many cases when I was uh part of 456 - > a larger organization. 457 - > We would use those audits as a way of allowing them into the 458 - > environment.

459 - > Because if you can pass a SOC 2 type 2 audit, you are in a much 460 - > better position to have your lease security controls in 461 - > place. 462 - > That doesn't always mean that that's correct, but in many 463 - > cases, having that audit completed gives a really big 464 - > step forward. 465 - > So get your security requirements in the contract and 466 - > make sure that the contract includes the right to audit. 467 - > Without the right to audit, every other requirement is just 468 - > words on paper.

469 - > And again, we're really good at putting words on paper, but 470 - > following through is a key factor. 471 - > You cannot verify compliance if you cannot audit. 472 - > Ongoing monitoring during this situation, there's the most 473 - > organizations fall short. 474 - > They do the upfront due diligence, but then they never 475 - > again look at it.

476 - > They wait until something breaks and then they address it at that 477 - > point. 478 - > So it's continuous vendor risk monitoring, it is an important 479 - > part of your organization. 480 - > And you can actually get third parties that are actually 481 - > actively looking at vendors, that's an option, as well as you 482 - > just monitoring their access into your environment. 483 - > So least privilege for all vendor access, scope it to 484 - > exactly what they need and nothing more.

485 - > Audit logs for all vendor activity and session recording 486 - > for any privileged remote access. 487 - > If they have remote access, you should be recording it. 488 - > If a vendor needs to touch your production environment, you 489 - > should be recording that session no matter what. 490 - > After offboarding, this is the phase that organizations fail 491 - > most consistently.

492 - > So when a vendor relationship does end, and they all do end, 493 - > all access must be revoked and all credentials must be rotated. 494 - > All OLAuth tokens must be invalidated. 495 - > Big gotcha there. 496 - > Data returned or destroyed per your data classification policy.

497 - > This is where the shiny hunter attack that we talked about. 498 - > Earlier exploited a legacy credential. 499 - > A credential that should have been decommissioned a long time 500 - > ago. 501 - > That is an off-boarding failure.

502 - > And the call out at the bottom of the slide, SBOM. 503 - > Software build of materials. 504 - > Know every library in your software before a zero day 505 - > forces you to find out. 506 - > We're going to cover SBOM in detail in the next slide, but 507 - > you need to really understand your S Bomb for your 508 - > organization.

509 - > Okay, so if you've never been introduced to SBOM, this is a 510 - > great little introduction that will be helpful for many. 511 - > And I do I want to kind of highlight the fact that all I 512 - > ever heard this once was I heard someone say soft bomb or SBOM. 513 - > And I'm like, what the heck is an S-Bomb? 514 - > Well, let's get into that a little bit.

515 - > So the Software Bill of Materials is what they call the 516 - > S Bomb or S or Sierra Bravo Oscar Mike. 517 - > This is one of those topics that shows up on the CISB exam, and 518 - > candidates either know it cold or they completely just go blank 519 - > on it and they don't know what to do. 520 - > So you're gonna know it cold after today. 521 - > So what is the SBOM?

522 - > Think of it as the nutrition label for your software. 523 - > A complete inventory of every component, every library, every 524 - > dependency, every version used in your product. 525 - > All of it is there in the SBOM. 526 - > So just like the food label tells you exactly what's in your 527 - > meal, the S Bomb tells you exactly what's inside your 528 - > application.

529 - > So why does this matter? 530 - > Because when a zero day drops, and it will drop, right? 531 - > We talk about it, it's not a matter of if, it's a matter of 532 - > when. 533 - > The first question your C Cell asks you is do we use this in 534 - > our library?

535 - > So often I'll send out, hey, this article happened here, this 536 - > article happened here. 537 - > Do you actually know if that is sitting in your library? 538 - > If you have an SBOM, you can answer this in minutes. 539 - > If you do not have an S Bomb, you're going to spend days 540 - > tearing through your code base, calling your vendors, and hoping 541 - > nobody is already exploiting you.

542 - > So it's an important part that you need to plan for. 543 - > So where should your SBOM live? 544 - > Your source code repository along with your build artifacts, 545 - > your CI CD artifact registry, or a dedicated S Bomb registry 546 - > that's tied to your CI CD pipeline, or a vulnerability 547 - > management platform that has all that information into it. 548 - > There's different Qualas and different companies out there 549 - > that have that.

550 - > And here's a critical rule about SBOM maintenance. 551 - > It must be regenerated every single build. 552 - > Not quarterly, not annually, every time a dependency changes. 553 - > If you have a good automated CI CD pipeline, this is a very easy 554 - > process.

555 - > If you do not, it's going to be kind of painful. 556 - > So a stale bus SBOM is almost as dangerous as no SBOM at all. 557 - > Because it gives you false confidence that you have all the 558 - > information in place and you know what's going on in your 559 - > organization. 560 - > But it's only as good as the last time you updated it.

561 - > So now let me give you the tools you need to know. 562 - > Because the CISP and real world employees expect you to know 563 - > these names. 564 - > So it's an important part for you to understand, at least from 565 - > a mentorship standpoint as well. 566 - > You have SIFT from Ancor.

567 - > This is an open source product that generates S-bombs from 568 - > containers and file systems. 569 - > You have GRIPE, it's also from Ancor, and it's a vulnerability 570 - > scanner that consumes S-BOMs and maps components to known CVEs. 571 - > Sneak, this is dependency scanning, license compliance, 572 - > and integrates directly into CICD pipelines. 573 - > You have OWASP dependency check, this is an open source product 574 - > that maps your components to your CVEs.

575 - > And then you have Black Duck by Synopsys. 576 - > This is an enterprise grade solution for open source risk 577 - > management. 578 - > And then finally we have Renovate and Dependabot. 579 - > I can't never say that word.

580 - > Automated dependency update tools that pull open pull 581 - > requests when vulnerable versions are detected. 582 - > And then you need to lock this exam tip in. 583 - > This is a big, big factor. 584 - > Exam tip plus its life's tip.

585 - > The U.S. 586 - > government now requires S bombs from software vendors selling to 587 - > federal agencies. 588 - > So that's an executive order 414028.

589 - > So you need to know that that is something that is being required 590 - > by the US government for anybody that is selling to agencies. 591 - > So if you're getting CMC CMMC certified, you will need an 592 - > SBOM. 593 - > So this does show up in exam questions on software supply 594 - > chain. 595 - > Okay, so now let's get into the little bit of a deep dive on 596 - > OAuth tokens.

597 - > So this is an attack vector that Shiny Hunters used in Oracle's 598 - > People Soft campaign. 599 - > And it's one of the most important concepts you need to 600 - > understand for both the CISP exam and for real-world 601 - > defenses. 602 - > So what is an OAuth token? 603 - > Think of it like a valet key.

604 - > When you give a valet your car, you don't just hand them your 605 - > master key, you give them a valet key. 606 - > A key that opens the car door and starts the engine, but not 607 - > open the glove box or the trunk. 608 - > Now I don't have a valet key because I don't have go to valet 609 - > places, but those guys that have really nice cars, they have 610 - > those. 611 - > So it's scoped access, it's limited time access, it's 612 - > specific access.

613 - > That is what OAuth is designed to do. 614 - > It grants access to resources without sharing the actual 615 - > password. 616 - > So when your organization connects a SaaS provider, 617 - > software as a service provider, this to your like to your 618 - > Salesforce environment or whatever that might be, you give 619 - > that vendor an OAuth token, not your admin password, a scope 620 - > token that allows them to read or write to a specific data they 621 - > need to get the job done.

622 - > That's the decision. 623 - > So it's the actual good design when it comes and it's 624 - > implemented correctly. 625 - > But here's how it gets abused. 626 - > Just like everything we talk about, as an attacker, I did in 627 - > the past from a red team standpoint, we abused all the 628 - > good stuff that we could because we knew abusing the positive 629 - > things would give us an outcome that we wanted.

630 - > So step one, the attacker compromises a trusted vendor. 631 - > So in the Shiny Hunter's case, the SaaS platform that your 632 - > organization is connected to, that is what they go after. 633 - > Step two, they extract the OAuth tokens that the vendor holds 634 - > from your environment. 635 - > These tokens are sitting on the vendor's servers.

636 - > Step three, they use these tokens to access your 637 - > Salesforce, your HR system, or your cloud storage. 638 - > No password required, and they are allowed right in. 639 - > Step four, and this is really the dangerous part: the access 640 - > looks completely legitimate to your audit logs, completely, 641 - > right? 642 - > No failed login attempts, no brute force alerts, no 643 - > geolocation anomalies.

644 - > They are you. 645 - > They are somebody within your organization that has the rights 646 - > to do so. 647 - > So just as a valid OAuth token being used across to access 648 - > data, that is why OAuth token abuse is so powerful. 649 - > And it's why it's so hard to detect with traditional security 650 - > tooling.

651 - > So now let me walk you through why tokens are dangerous when 652 - > they are mismanaged. 653 - > Long lived tokens. 654 - > Yes, so long live the token, said a Caesar. 655 - > How many organizations grant OAuth tokens that never expire?

656 - > Right, a token created two years ago from a vendor you stopped 657 - > working with 18 months ago might still be active. 658 - > And yeah, it could still allow somebody into your environment. 659 - > That's a legacy credential waiting to be exploited. 660 - > Overly broad scopes, the scope of what they're allowed to do.

661 - > So instead of being very narrow scoped, they have a very wide 662 - > scope. 663 - > So instead of granting a vendor read access to specific tables 664 - > they need, someone clicked grant all. 665 - > It's easier. 666 - > I'd have less problems during the setup process.

667 - > Now that vendor and anyone who compromises that vendor has read 668 - > at write access to everything. 669 - > No audit trail, won't even know it because they're just part of 670 - > the organizations. 671 - > So most organizations I talk to cannot quickly answer this 672 - > question. 673 - > What vendors currently have active OAuth grants into your 674 - > environment?

675 - > And many just kind of smile and wave and go, I have no idea. 676 - > So if you can't answer this question, you cannot manage that 677 - > risk. 678 - > And that gap is exactly what Shiny Hunters exploited. 679 - > All right, so now let's talk controls because knowing the 680 - > attack is only half the battle.

681 - > The CICP exam is going to ask you what to do about it. 682 - > There are five controls you need to know for OAuth token 683 - > governance, and they all live in domain five, identity and access 684 - > management. 685 - > So control one, token scoping. 686 - > Least privilege, just think least privilege.

687 - > Grant the vendor only the permissions their integration 688 - > actually requires. 689 - > If they need to read invoice data, they get to read the 690 - > access, they get read access to invoice data. 691 - > Not read write, only read. 692 - > They don't get read write to your entire customer database, 693 - > only to that specific table, only to the invoice data there 694 - > specifically.

695 - > Control two, token expiration. 696 - > Short-lived tokens with forced rotation. 697 - > Hours or days, not years. 698 - > And this doesn't expire in a hundred years thing, right?

699 - > I've seen this in production environments. 700 - > I have. 701 - > They have no expiration date or they just put it out to 100 702 - > years. 703 - > Build token expiration into your integration architecture so that 704 - > rotation is automatic.

705 - > Do not do a manual process. 706 - > No one ever actually goes and does the manual process. 707 - > Control three, token inventory. 708 - > Maintain a register of every active OAuth grant in your 709 - > environment.

710 - > What the vendor has it, what permissions it carries, and when 711 - > it was issued, when it expires, and who approved it. 712 - > All of those are key factors in what you need to do when you're 713 - > dealing with OAuth environments and the register for someone 714 - > who's maintaining it. 715 - > The review that inventory, you should review it at least 716 - > quarterly, because monthly is too soon, but quarterly most 717 - > definitely. 718 - > Because things change, people change, integrations change.

719 - > You get new vendors and relationships will end. 720 - > So when this happens, you need to know immediately which token 721 - > to invalidate. 722 - > Control four, revocation and offboarding. 723 - > When a vendor relationship ends, the first security action is to 724 - > invalidate all tokens associated with that vendor.

725 - > Not eventually, not when someone gets around to it. 726 - > It's immediately. 727 - > It's like when a person leaves your organization who's been 728 - > fired. 729 - > What happens to their access?

730 - > It's terminated immediately. 731 - > Same thing with your vendors. 732 - > Once they've been terminated, they immediately lose access. 733 - > The Shiny Hunters Attack exploited this legacy 734 - > credential, which means somebody ended up in a relationship and 735 - > forgot to revoke the access.

736 - > So this is an off-boarding failure. 737 - > And do not let it happen on your watch. 738 - > You're studying for the CISSP, you're going to be taking the 739 - > test, you're going to be a security professional, which you 740 - > already probably are, within the organization. 741 - > Use this.

742 - > This is a great opportunity for you to grow something within 743 - > your company. 744 - > Control five, anomaly detection. 745 - > Even with all the other controls in place, build detection logic 746 - > for token abuse patterns. 747 - > Token used outside of normal business hours is a great thing 748 - > that you can alert on.

749 - > Token used from an unusual IP or geography location. 750 - > Great place to alert from. 751 - > Token pulling volumes of data from outside your normal 752 - > patterns. 753 - > That's not normal.

754 - > That should be stopped. 755 - > The goal is to catch the cases that slip through because no 756 - > access control is perfect. 757 - > And here's your exam tip. 758 - > At the bottom of this slide, it's talking OAuth token abuse 759 - > maps both to domains five and one.

760 - > Domain five for the IAM controls in identity and access 761 - > management, and domain one for vendor risk management program. 762 - > And on the exam, the distractors will try to confuse you between 763 - > token scoping and token expiration and token revocation. 764 - > Know the difference between all three and which one applies. 765 - > Again, token scoping, token aspiration, and token 766 - > revocation.

767 - > Know the differences between those. 768 - > Okay, so question number one. 769 - > A payroll vendor announces they are experienced a breach. 770 - > API credentials used to access your HR system may have been 771 - > exploited.

772 - > What should be your first response? 773 - > Again, so payroll announced vendor announces experienced a 774 - > breach. 775 - > Your API credentials used to access your HR system may have 776 - > been exposed. 777 - > What should be your first response?

778 - > A notify your HR department of a potential breach. 779 - > B revoke and rotate the affected API credentials immediately. 780 - > C conduct a forensic investigation of the vendor 781 - > system, or D. 782 - > Update your vendor risk assessment document.

783 - > Okay, so think about that a little bit. 784 - > So when you're dealing with the question, is it what a look at 785 - > what it's asking? 786 - > So it's asking you what do you do first? 787 - > Not what you do eventually, not what you do when you have time.

788 - > What do you do first? 789 - > So the answer is B. 790 - > Revoke and rotate the credentials, and here's the 791 - > reasoning. 792 - > If the credentials are compromised, the attacker may 793 - > already be using them right now, this moment.

794 - > So every second of the credentials are active is 795 - > another second the attacker has the live connection into your HR 796 - > system. 797 - > Notifications matter, investigations matter, risk 798 - > updates matter, but none of this stops an active attacker. 799 - > So if you have to stop the bleeding first, rotate, 800 - > revocate, and then investigate. 801 - > Actually, it's just the other way around.

802 - > Revoke. 803 - > You need to stop the bleeding first. 804 - > Revoke, rotate, and then investigate. 805 - > Now let me walk you through why the others were wrong.

806 - > Because the understanding of the distractor is just as important 807 - > as knowing the right answer. 808 - > So notify your HR department. 809 - > This feels right because HR manages the data being 810 - > threatened. 811 - > But notification while their credentials are still active 812 - > means you're alerting people to a problem you have not yet 813 - > controlled or contained.

814 - > So stop the access first. 815 - > C. 816 - > Conduct a forensics investigation of the vendor 817 - > systems. 818 - > Forensics will be critical, but the forensics comes after 819 - > containment.

820 - > You do not investigate while the door is still open. 821 - > The horse is leaving the barn. 822 - > You gotta close the door. 823 - > Think of it like a house fire.

824 - > If you don't get a lot of the damage while it's burning, you 825 - > know, okay, my new chair just started on fire. 826 - > No, you actually stopped the fire. 827 - > D, update your vendor risk management assessment. 828 - > This is an after action step.

829 - > Updating documentation does not protect you right now. 830 - > B is correct. 831 - > Stock the active threat first. 832 - > Okay, so practice question two.

833 - > Your organization is evaluating a new cloud-based ERP vendor. 834 - > Which of the following is the most important control to 835 - > include in the vendor contract? 836 - > A mandatory encryption of all data at rest and in transit. 837 - > B the right to audit the vendor security practices.

838 - > C a specific patch management and remediation timeline, or D 839 - > prohibition of the vendor using any subcontractors. 840 - > Okay, so think about what makes the vendor contract control 841 - > actually meaningful. 842 - > The answer will be B, the right to audit, right? 843 - > So we talked about these again, real quickly go through them.

844 - > Mandatory encryption of all data at rest in a transit, the right 845 - > to audit the vendor security practices, that's B, a specific 846 - > patch management and remediation timeline, that's C, or D, 847 - > prohibition to the vendors using any subcontractors. 848 - > And we said the answer will be B, the right to audit. 849 - > So here's the principle. 850 - > Every other requirement in that contract, encryption, patch 851 - > timelines, subcontractor restrictions, all of those are 852 - > only as good as your ability to verify that they are actually 853 - > complying.

854 - > You cannot audit. 855 - > If you don't audit, if you cannot audit, you are trusting 856 - > the vendor's word. 857 - > And trust, as we established in the beginning of this session 858 - > and this discussion, is a vulnerability. 859 - > Trust is not good, right?

860 - > You've but trust is good, but you gotta have to be able to 861 - > trust but verify. 862 - > The right to audit is the control that makes all other 863 - > controllables controls verifiable. 864 - > And without it, all you have is a list of promises. 865 - > And list of promises don't go very far, right?

866 - > With it, you actually have a program. 867 - > So now let's walk through the distractors a bit. 868 - > The mandatory encryption, this is an excellent security 869 - > requirement. 870 - > But if you have no right to audit, how do you know 871 - > encryption is actually happening?

872 - > Yes, I have encryption. 873 - > I'm using it. 874 - > Uh yeah, you don't know that, right? 875 - > So the right to audit is what makes encryption requirement 876 - > enforceable.

877 - > Patch management timeline, C. 878 - > This is also a great requirement, but again, without 879 - > the right to audit, you cannot verify the vendor is actually 880 - > patching on schedule. 881 - > Patch timelines without audit rights are just wishful thinking 882 - > in contract form. 883 - > D, prohibition of subcontractors, this is often 884 - > impractical.

885 - > Most enterprise vendors are use subcontractors for hosting, 886 - > support, and development. 887 - > A blanket prohibition is more likely to kill the deal than to 888 - > actually improve the security. 889 - > So a better approach is to require that subcontractors meet 890 - > the same security standards and verify that through the right to 891 - > audit. 892 - > So B is correct.

893 - > All right, so let's move on to the next question. 894 - > Alright, last question, the last melon. 895 - > Practice question three. 896 - > Here, here we go.

897 - > This specifically is testing whether you know the 898 - > distinctions between similar sounding attack techniques and 899 - > the CISSP just loves these. 900 - > So a developer accidentally installs a malicious package 901 - > from a public repository. 902 - > The package name was one character off from a legitimate 903 - > commonly used library. 904 - > Aha, we've talked about this before.

905 - > Which supply chain attack technique does this represent? 906 - > A dependency confusion. 907 - > B typosquatting. 908 - > C watering hole attacks or D maintainer account compromise.

909 - > So think about the mechanism and what exactly happened. 910 - > The package name was on one character off. 911 - > So the developer mistyped it. 912 - > So if they mistyped something, the answer would be B.

913 - > Typosquatting. 914 - > So the attacker registered a package name that almost looks 915 - > identical to the legitimate library, counting the developers 916 - > to mistype during install. 917 - > This name is just different. 918 - > The name looks almost the same.

919 - > Here's why the distractors matter. 920 - > Because all these four techniques are all in the same 921 - > family. 922 - > The exam will definitely use them to trip you up. 923 - > A dependency confusion.

924 - > This is not typosquatting, and they are commonly confused. 925 - > In dependency confusion, the attacker uploads a public 926 - > package with the exact same name as a private internal package. 927 - > The package manager often resolves the public version over 928 - > the private one. 929 - > So the attacker code runs inside the organization's build as 930 - > expected.

931 - > Same name, different repository, that's the key distinction. 932 - > If the name is different, typos squatting. 933 - > If the name is the same, dependency confusion. 934 - > C watering hole attack.

935 - > Completely different category. 936 - > A watering hole attack targets sub websites or online resources 937 - > that users frequently visit, and then compromises those sites to 938 - > deliver malware to the victims that has nothing to do with 939 - > package repositories. 940 - > D. 941 - > Maintainer account compromise.

942 - > So in this attack, the legitimate maintainer of a 943 - > popular package has an account hijacked. 944 - > The attacker then pushes the malicious update through a real 945 - > trusted package. 946 - > If the real package name with a real maintainer's reputation is 947 - > all there, the package name is correct. 948 - > Maintainer is the same.

949 - > The update continues with malicious code. 950 - > So again, everything goes according to plan. 951 - > So four different attacks, all in the supply chain family, all 952 - > potentially on your exam. 953 - > You need to know the distinctions cold.

954 - > You gotta know the differences between them when you're going 955 - > into this exam. 956 - > Okay, so let's bring it all home. 957 - > Supply chain security is one of the most critical and fastest 958 - > growing attack services in cybersecurity today. 959 - > As we saw in Shiny Hunters, this is not theoretical, it's real.

960 - > Real universities, real student data, real credentials stolen 961 - > through real vendor trust relationships. 962 - > So for the exam, remember cross-domain picture. 963 - > Risk assess every vendor, build a program, not just a checklist. 964 - > Domain three, least privilege, defense in depth, scope vendor 965 - > access, segment the network.

966 - > Domain five, control and audit vendor access, OAuth tokens, 967 - > privilege access and revocation offboarding. 968 - > And then domain eight, S bombs, code signing, secure SDLC, and 969 - > know what's in your software before the zero day tells you 970 - > what's going on. 971 - > Okay, so again, you need to think like a manager. 972 - > You don't need to be a technician, you need to be a 973 - > manager.

974 - > And you need to design a program that prevents this incident from 975 - > occurring, right? 976 - > All right, that's all I've got for you today. 977 - > I hope you've enjoyed this. 978 - > I hope there's been a lot of great information for you.

979 - > Head on over to CISSP Cyber Training. 980 - > Lots of free stuff that's available for you. 981 - > You can sign up for all my free essentials. 982 - > And if you're a self-study person, it'll give you what you 983 - > need to be able to get prepared for the CISSP exam.

984 - > There's other paid products that are there and available for you. 985 - > If you really want to get the level of detail that you really 986 - > want, go there to get that level of detail. 987 - > It's going to be able to provide you for that. 988 - > Or finally, if you plan on getting your CISSP and you want 989 - > help doing this and you want to have people that can be there 990 - > and hold you accountable for your self-study plan, go to look 991 - > at my sprint cohort.

992 - > Only two slots left, two left for this cohort that ends in 993 - > begins in July 7th of this year. 994 - > And then I'll be doing another cohort starting in September. 995 - > So if you're interested in getting your C I SP knocked out, 996 - > now is the time to do it. 997 - > Only two spots left.

998 - > All right. 999 - > Thank you guys so much for joining me today, and we'll 1000 - > catch you on the flip side. 1001 - > See ya. 1002 - > Thanks so much for joining me today on my podcast.

1003 - > If you like what you heard, please leave a review on iTunes 1004 - > as I would greatly appreciate your feedback. 1005 - > Also, check out my videos that are on YouTube and just head to 1006 - > my channel at CISSP Cyber Training, and you'll find a 1007 - > plethora or a conocopia of content to help you pass the 1008 - > CISSP exam the first time. 1009 - > Lastly, head to CISSP Cyber Training and sign up for 360 1010 - > free CISSP questions to help you in your CISSP journey.

1011 - > Thanks again for listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why Your Marketing Attribution Breaks on MarketplacesMarketing Analytics with Fexingo · on Snowflake92 / 100
  • How Fortune 500s Use Procurement to Manage Vendor AI Training Data RightsEnterprise Tech with Fexingo · on Salesforce90 / 100
  • Why B2B Brands Fail at Account Based Marketing AttributionThe Marketing Operator Podcast with Fexingo · on Salesforce88 / 100
  • #410 - How Mazy Dar found room in Google and Microsoft's market - and won the world's biggest banksThe Remarkable SaaS Podcast · on Salesforce87 / 100
  • Is Your AI Actually Worth What You're Spending? with Parker ConradStrictlyVC Download · on Snowflake86 / 100
  • How to Sell Against a Competitor Already in the BuildingSales Leadership with Fexingo · on Salesforce85 / 100

More from CISSP Cyber Training Podcast

All episodes →
  • CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know68 / 100
  • CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP59 / 100
  • CCT 356: Supply Chain Attacks Are Exploding in 2026 - Here's What the NCSC Wants You to Do59 / 100
  • CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes69 / 100
  • CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY59 / 100
Explore the best B2B Engineering & DevTools podcasts →
All CISSP Cyber Training Podcast episodes →