Learn Python with Generative AI - Self Paced Online
Most AI Pilots Fail to Scale. MIT Sloan Teaches You Why — and How to Fix It
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore a 30-minute conference talk from NorthSec that delves deep into the often-overlooked vulnerabilities within Open Source package Build Pipelines. Learn how researchers developed sophisticated data analysis infrastructure to uncover 0-day vulnerabilities in major OSS projects, including Terraform providers, AWS Helm Charts, and GitHub Actions. Gain valuable insights through a comprehensive attack tree analysis of GitHub Actions pipelines, understanding both potential attack vectors and essential mitigations. Discover a novel 'Living Off the Pipeline' (LOTP) components reference designed to help Red and Blue teams identify and prioritize high-risk scenarios. Presented by Benoît Côte-Jodoin, a Senior Product Security Engineer at BoostSecurity and former CTF player, alongside François Proulx, who leads the Supply Chain research team at BoostSecurity and brings over a decade of AppSec program development experience from both large corporations and startups.
Syllabus
NSEC2024 - Benoit Cote-Jodoin & François Proulx - Under the Radar: 0-days in the Build Pipeline
Taught by
NorthSec