CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.
We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it’s not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.
Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what’s inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.
If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
buzzsprout.comFreeCISSPQuestions.com
freecissptraining.com
- 0:00Welcome And Today’s Focus
- 1:41Shiny Hunters Hit Oracle PeopleSoft
- 5:58The Real Lesson: Vendor Oversight
- 8:37Training Roadmap For CISSP Domains
- 9:27What Supply Chain Security Really Means
- 12:16Four Supply Chain Attack Vectors
- 16:28How Supply Chain Maps To CISSP
- 19:51Controls Before During After Vendors
- 22:28SBOM Basics Plus Tools To Know
- 26:06OAuth Token Abuse And Governance
- 33:14Three Practice Questions Walkthrough
- 40:39Manager Mindset And Final Takeaways
- 41:35Where To Get More Help