NoLimitSecu #523 - interview Roni Carta

NoLimitSecu #523 - interview Roni Carta

🎙 NoLimitSecu 👥 2K 📅 December 8, 2025 ⏱ 44 min 👁 171 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

software supply chaindependencyopen sourcesupply chain attackSBOM

Summary

In this episode of NoLimitSecu, recorded at the Assises de la Cybersécurité in Monaco, host Fabien Le Marchand and co-hosts interview Roni Carta, a security researcher at Lupin & Holmes, about software supply chain security. Carta defines the software supply chain, highlighting the risks of using third-party components and the attack surface from source, build, and distribution. He discusses notable attacks such as the compromise of the ‘colors’ npm package, the XZ Utils backdoor, the Kong GitHub Action compromise, the British Airways Magecart attack, and the massive Bybit hack attributed to North Korea. He emphasizes that attackers often target dependencies and pipelines, and that many attacks are detected by the open-source community. Carta also discusses the importance of standards like SLSA and the EU Cyber Resilience Act, and the need for better observability and mapping of dependencies. He suggests that while no single solution exists, a combination of standards, regulations, and offensive security practices can improve resilience.

157 words

Critical Evaluation

Value of the Information & Strength of the Argument

The interview provides valuable insights into the software supply chain threat landscape, with concrete examples and references to well-known incidents. Carta’s argumentation is coherent and well-structured, explaining the complexity of the supply chain and why it is often overlooked. He effectively challenges the common focus on externally exposed systems, arguing that ingested components are equally critical. The discussion of standards like SLSA and the CRA adds practical relevance. However, some points are based on personal experience and may lack broader statistical evidence.

91 words

Title / Content Match

The title accurately reflects the content: an interview with Roni Carta on software supply chain security.

Quality & Reliability

8/10

The interview features a recognized expert in software supply chain security, discussing well-documented attacks and industry standards. The content is technically accurate and aligns with known events (e.g., XZ Utils backdoor, Bybit hack). However, it is a conversational interview without formal citations or peer-reviewed sources, and some claims are anecdotal.

Key Moments

Cited Sources

Concurring Sources

  • XZ Utils Backdoor — The interview references the XZ Utils backdoor, a well-documented supply chain attack.
  • Bybit Hack — The interview discusses the Bybit hack, a major cryptocurrency theft attributed to North Korea.

Contribution & Novelties

The interview provides a comprehensive overview of software supply chain security, synthesizing recent attacks and industry standards. It offers practical insights into the challenges and potential solutions, emphasizing the need for a holistic approach. The discussion of the CRA and its implications is particularly relevant for organizations.

Pour aller plus loin :

  • SLSA Framework — Official website for the Supply-chain Levels for Software Artifacts framework.
  • Cyber Resilience Act — European Commission page on the CRA.
  • OWASP Top 10 for Supply Chain — OWASP’s list of top supply chain risks.

89 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-informed discussion that is accessible to a broad audience while maintaining technical depth.

Reliability 8/10