Event

OWASP London Meetup

Date
May 19, 2025
Time
6:00 PM - 9:00 PM
Event Type
In person
Location
Europe
Event Overview

We’re excited to feature Henrik Plate principal security researcher at Endor Labs, at this meetup, who will deliver an insightful session titled “Attacks on Open Source Supply Chains: How Hackers Poison the Well

Session Overview:

The ubiquitous use of open source during software development makes it an interesting and valuable target for software supply chain attacks, where

attackers inject malicious code in upstream open source projects such that it is executed by software developers or end users down the line. Thistalk provides an overview about common attack vectors, illustrated by real-world examples, and sheds some light on countermeasures.

Don't miss this insightful discussion on the emerging risks and challenges of securing AI-generated code in the era of accelerated development.

Join us for the OWASP London Meet-up!

Want to stay in the loop?

Sign up for our newsletter.

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
Average results with 59.8% on functional solves and just 19.0% on security solves
Read more
Recall, not reasoning: how AI coding agents cheat security benchmarks
Recall, not reasoning: how AI coding agents cheat security benchmarks
Read more
Endor Labs + Cursor: Building the security foundation for agentic coding
Endor Labs + Cursor: Building the security foundation for agentic coding
Read more
Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise
Cut container vulnerability noise by up to 90% with full-stack reachability analysis spanning application and container image OS layers.
Read more
Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
MCP servers inherit classical vulnerabilities like command injection, path traversal, and SSRF. Here's why LLMs and MCP deserve the same security practices as traditional applications.
Read more
How Fake Font Packages Abused npm as a CDN
101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.
Read more