# YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74 Page: https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/yellowkey-cve-enrichment-chipmaker-breach-bts-74 Text version: https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/yellowkey-cve-enrichment-chipmaker-breach-bts-74.md Podcast: [Below the Surface (Audio) - The Supply Chain Security Podcast](https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778) Published: 2026-05-19T18:06:00+00:00 Episode link: https://belowthesurfacesw.libsyn.com/yellowkey-cve-enrichment-chipmaker-breach-bts-74 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/belowthesurfacesw/74.mp3?dest-id=3822522 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/below-the-surface-audio-the-supply-chain-security-podcast-5987778/episodes/yellowkey-cve-enrichment-chipmaker-breach-bts-74 Duration seconds: 3292 ## Resource In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats. Topics https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth https://github.com/Nightmare-Eclipse/YellowKey https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack https://x.com/AlvieriD/status/2053835732658143416 Chapters 00:00 Introduction to Vulnerability Research and AI 03:42 NIST and CVE Growth Challenges 06:46 Building Tools for CVE Analysis 10:58 The Complexity of CVSS Scoring 15:08 CISA's Role in Vulnerability Enrichment 18:06 Challenges in CWE and CPE Data 19:55 The Future of Vulnerability Research 27:18 BitLocker Bypass: A Case Study 33:05 Exploring the Complexity of Windows Features 34:49 Speculation on Microsoft and Conspiracy Theories 35:57 The Impact of BIOS Passwords on Security 39:12 The Foxconn Breach: A Major Data Compromise 47:34 Supply Chain Attacks on Package Managers 51:13 Deceptive Techniques in Cybersecurity ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/below-the-surface-audio-the-supply-chain-security-podcast-5987778/episodes/yellowkey-cve-enrichment-chipmaker-breach-bts-74/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/yellowkey-cve-enrichment-chipmaker-breach-bts-74.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.