Lambert has more than 20 years of experience in the information security and currently serves as the VP of Docutek Solutions. Having obtained the CISSP Certificate for nearly 20 years, he is committed to simplifying and popularizing information security, and bringing risk management concepts into information security management and defense. We know that hackers are always in the dark, and the threats to information security change so fast that often defense technologies may not be watertight. People are an important line of defense for information security. For enterprises, the only way is to continuously invest in improving all employees. Only with a better understanding of information security and risk awareness can we effectively respond to ever-changing information security threats and risks.
Based on the security incidents in which application security was invaded in recent years, this paper explores the potential threats to today's application system security and supply chain vulnarability. In addition to the currently well-known security threats, this session specifically explores threats that may not be considered in "application security testing" and "software supply chain security". We will also discuss the technical and management process aspects, and how to complete necessary security checks in S-SDLC and automated CI/CD processes. And add these TTP into your Threat Modeling knowledge.
CYBERSEC 2025 uses cookies to provide you with the best user experience possible. By continuing to use this site, you agree to the terms in our Privacy Policy 。