Socket CTO Ahmad Nassri recently sat down with five other AppSec leaders on The Secure Disclosure podcast for an unfiltered discussion on the state of software supply chain security. Hosting six competing CTOs and security researchers in one room provided a candid look at how upstream threats are evolving, the operational limits of package registries, and why commercial threat intelligence siloing leaves engineering teams exposed. A few of the highlights: Vulnerabilities vs.