OSC&R in the Wild: A New Look at the Most Common Software Supply Chain Exposures

watch now oscr

In this OX Security webinar, Katie Teitler-Santullo and Boaz Barzel introduce OSC&R, the Open Software Supply Chain Attack Reference, and use it to make sense of the most common software-supply-chain exposures. Drawing on research across more than 100 million alerts, they explain why supply-chain risk is now everyone’s problem, why a pipeline bill of materials (PBOM) matters more than an SBOM alone, and how OSC&R, inspired by MITRE ATT&CK, maps the supply chain to attacker tactics and techniques. They walk through where vulnerabilities concentrate along the kill chain, how cross-technique attacks amplify damage, and how teams can use OSC&R, a free, open resource, to prioritize, threat-model, and build a stronger AppSec program.

Key Takeaways

  • Software supply chain risk is widespread and costly. Across 100M+ alerts, 95% of organizations had at least one high, critical, or “apocalyptic” supply-chain risk, the average had nine, and one in five apps had one at runtime.
  • Up to 90% of a codebase can be open source. Reuse speeds delivery but pulls in transitive vulnerabilities, while security lacks visibility and developers move fast, so issues surface too late.
  • Think PBOM, not just SBOM. A pipeline bill of materials covers the whole attack surface: code plus build and deploy environments, access, sharing, and API and SaaS bills of materials, not just the code.
  • OSC&R maps the software supply chain to attacker TTPs. Inspired by MITRE ATT&CK, it gives a common language across code, cloud, and security teams and a reference for building strategy and maturing an AppSec program.
  • Vulnerabilities span the whole kill chain, and combining stages amplifies damage. Initial access (~36%) and execution/persistence (~32%) lead, cross-technique attacks do the most harm, and 31% of apps still carry back doors in code.
  • Use OSC&R to prioritize, threat-model, and collaborate. It cuts noise to the few items that matter and founds threat modeling specific to your apps; favor vendors who show evidence, not a “silver bullet.”

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

Director of Product Marketing, Sales Enablement and Revenue Operations, OX Security

Leads product marketing, sales enablement, and revenue operations at OX Security.

katieteitler 0

Katie Teitler-Santullo

View on LinkedIn

Director of Product Marketing and Cybersecurity Strategist, OX Security

Director of product marketing and a cybersecurity strategist at OX Security.

FAQ

The Open Software Supply Chain Attack Reference: a free, open framework, inspired by MITRE ATT&CK, that maps how attackers operate across the software supply chain. It is a community resource, not a product OX sells.

Every company ships software, increasingly built on open source and cloud. The resulting unknowns create financial, brand, regulatory, and operational risk, and software-supply-chain attacks are growing more frequent and sophisticated.

A pipeline bill of materials extends the software bill of materials to the entire pipeline: the build and deploy environments, access, and sharing, plus API and SaaS bills of materials, so you see everything that goes into building and deploying software, not just the code.

It was built collaboratively by industry leaders, including Check Point, GitLab, Microsoft, and Fico, alongside OX’s research team and founders and contributors such as OWASP, after analyzing more than 300 attacks. It is a free, open resource, not something OX sells.

They span the kill chain: about 36% in initial access and about 32% in execution and persistence, with cross-technique combinations amplifying damage. Notably, 31% of apps evaluated still contained back doors in code, a decades-old issue.

To cut a flood of alerts down to the few items that actually matter, build threat models specific to your applications, create a common language between development and security, and detect threats earlier for faster remediation and a smaller attack surface.