Podcast

Alice in Supply Chains - Episode 21

September 15, 2026

Descrição do episódio:

In this episode of the Alice in Supply Chains Podcast, Adrian Sanabria and Alexandre Sieira discuss four stories shaping third-party cyber risk management - from a BGP hijacking that compromised software updates to emerging AI risks, the rise of inside-out scanning in financial institutions, and proposed UK restrictions on risky technology suppliers.

Show notes:

- Story one focuses on a wild BGP hijacking incident that compromised updates for a vendor that makes hypervisor management software (Virtualizor by Softaculous). Attackers were able to take over part of hosting company Hetzner’s IP space, create a valid TLS certificate for Softaculous’s website and serve up an identical copy of the website. Softaculous didn’t cryptographically check the integrity of updates, so the attack succeeded in compromising customers.

- In story two, the Financial Stability Board, an organization created by the G20 after the 2008 financial crisis, warns of risks from AI. The risks were twofold: the AI bubble and threats directly from rogue AI agents.

- In story three, Alexandre shares an observation that, at least in Latin America, financial institutions are writing inside-out scanning into their MSAs.

- Finally, in story four, UK politicians propose to amend the Cyber Security and Resilience bill to expand restrictions on tech suppliers seen as ‘risky’. A troubling addition aims to remove transparency at the same time.

Links - for reference:

Show Transcript

Assista ou ouça os episódios completos em Inglês

Episódios Recentes