Supply Chain Security
Software supply chains are among the most targeted and least understood attack surfaces in modern development. This course teaches developers to see their software the way an attacker does — not just the code they write, but every dependency, build tool, CI/CD pipeline, registry, and AI assistant that touches it. You will learn how landmark attacks like SolarWinds, XZ Utils, and event-stream unfolded, how to map and harden your own supply chain, and how to apply practical controls including lockfile pinning, artifact signing, SBOM generation, and policy-as-code gates. The course closes with the emerging threat of AI supply chain attacks — hallucinated packages, insecure code suggestions, prompt injection, and backdoored models — equipping you to ship software you can actually trust.