Daniel Schwendner
Daniel Schwendner is a Cyber Security Specialist and former DevOps Engineer with a strong passion for Cyber Security. With a background in mobile application security and hardware security, he participates in bug bounty hunting and shares his security knowledge online.
Session
Last year's CI/CD attacks didn't come through the front door, they came pre-installed. In 2025, the Shai-Hulud worm tainted 500+ npm packages, the chalk/debug compromise hit packages with 2.6 billion weekly downloads, and axios was backdoored in a 3-hour window. In this hands-on workshop you'll become the attacker: build a malicious npm/PyPI package, poison a pipeline, exfiltrate secretss. Then switch hats and run the incident response, tracing the blast radius and learning the defenses that actually stop these attacks.