Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk

DefCon 34 @ USA 2026

07 August 2026

Date: August 7, 2026 | 1 Day Training (Friday)
Time: 8:30 AM – 5:30 PM
Location: Las Vegas Convention Center W224
Level: Intermediate
Format: 1 Day Hands-on Training
Instructors: Anant Shrivastava (Founder, Cyfinoid Research), Sunil Yadav (Founder / Head of Security, x-biz Techventures)

Course Overview

This course takes practitioners inside real supply chain attack chains, from compromised packages to tampered upstream artifacts to abused third-party integrations, and teaches how to technically verify what upstream dependencies actually ship. Students work hands-on with provenance verification, runtime detection, inherited risk analysis, and practical defense implementation — skills that go beyond policy documents and questionnaires.

Supply chain attacks succeed because they exploit trust: in packages, in integrations, and in the assumption that upstream components are safe. Using real case studies including SolarWinds, xz Utils, Log4Shell, and 3CX, the course reconstructs how small trust failures chain into full organizational compromise, and where technical verification would have caught them.

This is not a risk management or governance course. It is built for security practitioners who need to technically verify supply chain components and build detection capabilities in their own environments.

Topics Covered

Training Curriculum

Module 1 — Anatomy of Supply Chain Attack Chains

Technical reconstruction of major incidents and kill-chain mapping. Students reconstruct attack chains using build logs and artifact signatures, and build a supply chain attack taxonomy referenced throughout the course.

Module 2 — Package Ecosystem Attacks and Detection Engineering

Typosquatting, dependency confusion, namespace hijacking, maintainer account takeover, and hidden capability abuse. Students write detection rules and test them against a curated set of real malicious packages.

Module 3 — Inherited Risk Analysis

Hands-on verification of upstream dependencies and third-party software: undisclosed transitive dependencies, cryptographic weaknesses, AI component metadata, tampering detection, and vulnerability cross-referencing.

Module 4 — Building Supply Chain Defenses That Work

Provenance verification workflows, admission controls gated on attestations, package governance policies, and runtime detection rules assembled into a technical supply chain defense playbook.