No items found.
Event

OWASP Amsterdam, Netherlands - June 2024 Chapter Meetup

Date
June 20, 2024
Time
6:00 PM - 9:00 PM CEST
Event Type
In person
Location
Europe

Location: Vrije Universiteit Amsterdam De Boelelaan 1105 · Amsterdam, NH

Ship Happens: The Stormy Seas of Supply Chain Security

“The more I know about how software is made, the less I want to know” - Me

As a software developer with over a decade of experience and countless interactions with application security teams, I’ve discovered the unsettling complexities of modern software production. Despite what I thought I knew, the reality was far more intricate.

Modern software development is a sprawling network of open-source dependencies, sophisticated build tools, plugins, pipelines, and runtimes. These components are fundamental in securing critical sectors of our daily lives—finance, healthcare, infrastructure, transportation, and social interactions. However, this supply chain is under relentless attack and many of the potential threats are poorly understood.

This talk will delve into specific vulnerabilities, such as dependency poisoning and pipeline compromises, that exemplify the challenges we face. We’ll explore strategies to mitigate these threats and discuss practical takeaways that attendees can immediately implement in their software development practices. Expect to leave with a deeper understanding of supply chain security and with ideas to fortify your software factory against these escalating threats.

CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more
The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
Read more
CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more
The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails
Read more

Want to stay in the loop?

Sign up for our newsletter.