"Industry has gotten good at identifying vulnerabilities in the supply chain; SBOMs and so on [but not at] at insidious backdoors and logic issues that are built into software, and update mechanisms that could cause implants..."
Multinational's Global CISO touts critical work being done by the OpenSSF and tools like its Security Scorecard...