InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Malicious Packages & Malware Campaigns: The New Reality of the Software Supply Chain

Presented by

Amit Chita, Field CTO, Mend.io & Ben Rieger, Head of DevOps & Security, Mend.io

About this talk

Open source and package registries are now primary attack surfaces. What begins as a malicious or backdoored dependency on a developer workstation can quickly cascade through CI/CD pipelines and into production, creating high-blast-radius incidents that evade traditional AppSec controls. In this technical deep-dive, Amit Chita (Field CTO) and Ben Rieger (Head of DevOps & Security) present real investigations from the front lines and translate them into an operational playbook you can use tomorrow. What attendees will learn -The anatomy of a modern malicious-package campaign: entry vectors, propagation mechanisms, and why one compromised package can impact thousands of projects. -Why conventional AppSec and signature-based tools miss these attacks, and where developer workflows and CI/CD pipelines are most exposed. -Practical detection patterns and containment strategies for developer environments, build pipelines, and artifact repositories. -How to design and operate effective processes to handle modern attack campaigns.
Mend.io

Mend.io

18156 subscribers52 talks
AI native application security platform
Mend.io offers the first AI native application security platform, empowering organizations to build and run a proactive AppSec program tuned for AI powered development. The unified platform secures AI generated code and embedded AI components, drives risk reduction through AI powered remediation, automates compliance, and provides a holistic enterprise scale view of risks and clear actions for developers across your entire codebase. Learn more at www.mend.io
Related topics