BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2025//speaker//ULAPT8
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20241024T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20241027T030000
RDATE:20251026T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20250330T030000
RDATE:20260329T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:From YAML to Root: CI/CD Pipeline Attacks and Countermeasures - Hu
 go
DTSTART;TZID=Europe/Luxembourg:20251024T093000
DTEND;TZID=Europe/Luxembourg:20251024T100000
DTSTAMP:20260809T012311Z
UID:pretalx-hack-lu-2025-CGRNFY@pretalx.com
DESCRIPTION:As CI/CD pipelines become integral to modern software developm
 ent through systems like Azure DevOps or GitHub Actions\, and tools such a
 s Terraform and Ansible\, their compromise can have devastating effects\, 
 from infrastructure breaches to mass malware distribution.\n\nOriginally\,
  CI/CD pipelines were managed and accessed only by a limited group of admi
 nistrators or integration engineers. However\, with the widespread adoptio
 n of Infrastructure as Code\, it has become increasingly common for compan
 ies to open controlled access to their pipelines—sometimes even to exter
 nal clients. This shift supports use cases such as self-service sandbox en
 vironments\, client-controlled infrastructure provisioning\, or dynamic te
 stbed deployments in multi-tenant platforms. While these scenarios offer f
 lexibility and scalability\, they also introduce new risks and potential a
 ttack vectors\, making it critical to rethink pipeline security under this
  broader exposure model.\n\nIn this talk\, we will demonstrate how an atta
 cker can exploit seemingly limited permissions—such as those of a standa
 rd contributor account—to fully compromise a CI/CD pipeline and the unde
 rlying infrastructure. By chaining misconfigurations\, abusing legitimate 
 features\, and bypassing common restrictions\, we’ll show how limited ac
 cess can quickly escalate into full control. \nIn the second phase of the 
 talk\, we’ll look at the defensive side: how a company can effectively s
 ecure its pipelines in a context where access is no longer limited to inte
 rnal teams.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2025/talk/CGRNFY/
END:VEVENT
END:VCALENDAR
