BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//speaker//KWLFFV
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251021T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Poisoned at the Source: Hacking the Software Supply Chain in Your 
 CI/CD Pipeline - Daniel Schwendner
DTSTART;TZID=Europe/Luxembourg:20261021T141500
DTEND;TZID=Europe/Luxembourg:20261021T171500
DTSTAMP:20261009T050418Z
UID:pretalx-hack-lu-2026-3JKMYU@pretalx.com
DESCRIPTION:Last year's CI/CD attacks didn't come through the front door\,
  they came pre-installed. In 2025\, the Shai-Hulud worm tainted 500+ npm p
 ackages\, the chalk/debug compromise hit packages with 2.6 billion weekly 
 downloads\, and axios was backdoored in a 3-hour window. In this hands-on 
 workshop you'll become the attacker: build a malicious npm/PyPI package\, 
 poison a pipeline\, exfiltrate secretss. Then switch hats and run the inci
 dent response\, tracing the blast radius and learning the defenses that ac
 tually stop these attacks.
LOCATION:Schengen 1 & 2
URL:https://pretalx.com/hack-lu-2026/talk/3JKMYU/
END:VEVENT
END:VCALENDAR
