{"podcast":{"title":"Below the Surface (Audio) - The Supply Chain Security Podcast","slug":"below-the-surface-audio-the-supply-chain-security-podcast-5987778","podcast_index_feed_id":5987778,"rss_url":"https://feeds.libsyn.com/454509/rss","website_url":"https://eclypsium.com/","image_url":"https://static.libsyn.com/p/assets/2/a/8/7/2a879f07ebbd201d27a2322813b393ee/ecl_bts2_cta_1400x1400-20240911-gw2wy33qw9.png","author":"Eclypsium","episode_count":82,"summary":"A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions. Get the Supply Chain Security Toolkit from Eclypsium here: https://eclypsium.com/go","last_synced_at":"2026-09-17T04:19:26.188600+00:00","page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778"},"episode":{"title":"YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74","slug":"yellowkey-cve-enrichment-chipmaker-breach-bts-74","published_at":"2026-05-19T18:06:00+00:00","page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/yellowkey-cve-enrichment-chipmaker-breach-bts-74","show_page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778","url":"https://belowthesurfacesw.libsyn.com/yellowkey-cve-enrichment-chipmaker-breach-bts-74","audio_url":"https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/belowthesurfacesw/74.mp3?dest-id=3822522","summary":"In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats. Topics https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth https://github.com/Nightmare-Eclipse/YellowKey https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack https://x.com/AlvieriD/status/2053835732658143416 Chapters 00:00 Introduction to Vulnerability Research and AI 03:42 NIST and CVE Growth Challenges 06:46 Building Tools for CVE Analysis 10:58 The Complexity of CVSS Scoring 15:08 CISA's Role in Vulnerability Enrichment 18:06 Challenges in CWE and CPE Data 19:55 The Future of Vulnerability Research 27:18 BitLocker Bypass: A Case Study 33:05 Exploring the Complexity of Windows Features 34:49 Speculation on Microsoft and Conspiracy Theories 35:57 The Impact of BIOS Passwords on Security 39:12 The Foxconn Breach: A Major Data Compromise 47:34 Supply Chain Attacks on Package Managers 51:13 Deceptive Techniques in Cybersecurity","meta_description":"In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hard…","key_points":[],"chapters":[],"topics":[],"duration_seconds":3292,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/below-the-surface-audio-the-supply-chain-security-podcast-5987778/episodes/yellowkey-cve-enrichment-chipmaker-breach-bts-74/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/yellowkey-cve-enrichment-chipmaker-breach-bts-74.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}