In episode 86 of the Cybersecurity Minute, Chris Hughes discusses a new resource from Microsoft, the DevOps threat matrix.
Highlights
0:45 — Microsoft released this DevOps threat matrix. It’s in the style of the MITRE attack framework. It lets you get an idea of the techniques, tactics, and procedures used by malicious actors and attack vectors.
01:18 — The DevOps threat matrix touches on a lot of different techniques that we’ve seen successfully used in recent software supply chain attacks, in particular, things such as compromising source code management systems or CI/CD services.
01:49 — Developers are using dependencies that malicious actors try to take advantage of with techniques such as typosquatting in libraries and so on.
02:08 — We’re seeing more and more organizations move to cloud-native environments. So, this threat matrix is a great resource from Microsoft.





