The software supply chain attack surface is a lot more complicated now, and can be compromised at every stage. Developers are the new high-value targets and we have seen developers fall victim to stolen credentials and secrets, compromised workstations, CI/CD attacks and malicious packages that end up in source code.
Co-founder at Phylum
Aaron has 14 years of experience working in software engineering and information security. He spent 11 years working within the U.S. Intelligence Community before joining Sony to lead development for the Global Threat Emulation cell. Aaron’s past research has focused on program synthesis, malware diversity, software anomaly detection, and the application of natural language processing techniques to binary analysis.