Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Under the Radar: Zero-Day Vulnerabilities in Build Pipelines

NorthSec via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore a 30-minute conference talk from NorthSec that delves deep into the often-overlooked vulnerabilities within Open Source package Build Pipelines. Learn how researchers developed sophisticated data analysis infrastructure to uncover 0-day vulnerabilities in major OSS projects, including Terraform providers, AWS Helm Charts, and GitHub Actions. Gain valuable insights through a comprehensive attack tree analysis of GitHub Actions pipelines, understanding both potential attack vectors and essential mitigations. Discover a novel 'Living Off the Pipeline' (LOTP) components reference designed to help Red and Blue teams identify and prioritize high-risk scenarios. Presented by Benoît Côte-Jodoin, a Senior Product Security Engineer at BoostSecurity and former CTF player, alongside François Proulx, who leads the Supply Chain research team at BoostSecurity and brings over a decade of AppSec program development experience from both large corporations and startups.

Syllabus

NSEC2024 - Benoit Cote-Jodoin & François Proulx - Under the Radar: 0-days in the Build Pipeline

Taught by

NorthSec

Reviews

Start your review of Under the Radar: Zero-Day Vulnerabilities in Build Pipelines

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.