<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply Chain on lcz's Blog</title><link>https://book.llcczz.org/tags/supply-chain/</link><description>Recent content in Supply Chain on lcz's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 28 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://book.llcczz.org/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions</title><link>https://book.llcczz.org/posts/cicd-github-actions-secrets/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/cicd-github-actions-secrets/</guid><description>Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.</description></item><item><title>XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem</title><link>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</guid><description>A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.</description></item><item><title>Log4Shell (CVE-2021-44228): Exploitation, Detection, and Mitigation</title><link>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</link><pubDate>Wed, 15 Dec 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</guid><description>A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.</description></item></channel></rss>