The mist is low over the ground. You walk past the rubble of ransom’d hard drives, manipulated PCBs, and broken systems. The air is heavy with disappointment from keys lost, and the silent betrayal of infected third party libraries. The power has been out for so long and you have lost track of time. But you see a path forward, and It fills you with determination. This talk examines four examples of software supply chain attacks. Each example highlights different aspects of this class of attacks. I discuss method, motive, scale and impact. The examples which will be presented are: getcookies NPM backdoor; Linux mint distribution takeover; MEGA chrome extension hijacking; and NotPetya ransomware attack. Hacking just by browsingRewanth CoolN/AN/AWith the recent advancements in technology, more people are aware of the importance of security. More companies started paying huge rewards to protect the sensitive information of their customers. Automated scanners won’t yield you bugs these days. Automated scanners can’t be used to scan every website you visit daily. You need a smart scanner while hunting for bugs. Github link of the tool - https://github.com/rewanth1997/vuln-headers-extension I found vulnerabilities in Bugcrowd, Hotstar, Medium, Signup.com, Chargify etc using this minimal browser extension. In this talk, we will be focusing on creating your own minimal smart scanner as browser(Firefox ESR) extension to detect header related vulnerabilities. This extension monitors the request and response headers passing through your browser and detects vulnerabilities in them. The browser extension is capable of detecting CORS misconfigurations, host header injections, and clickjacking vulnerabilities. In the process, you will be learning about basic header vulnerabilities like CORS misconfiguration, host header injection, clickjacking and exploitation scenarios, detection methods and the biggest bounties earned through simplest detection techniques for each of the above vulnerabilities.