BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//open-source-conference-luxembourg-2026//sp
 eaker//AHRRNA
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251007T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Securing Open Source CI/CD  Pipelines: Lessons from Handling 2 Sup
 ply Chain Incidents - Florence Njeri\, Łukasz Górnicki
DTSTART;TZID=Europe/Luxembourg:20261007T153000
DTEND;TZID=Europe/Luxembourg:20261007T160000
DTSTAMP:20260916T160802Z
UID:pretalx-open-source-conference-luxembourg-2026-ETANAX@pretalx.com
DESCRIPTION:**Open-source packages are now the primary attack surface used
  by threat actors.** Rather than targeting enterprises directly\, attacker
 s are now compromising widely-used packages with a goal of reaching millio
 ns of CI/CD systems simultaneously through trusted releases.\n\nBecause th
 ese open-source packages form the backbone of modern enterprise workflows
 —including cloud pipelines\, CI/CD systems\, and developer tooling—att
 ackers are increasingly targeting open-source organizations to poison thes
 e packages and publish them to trusted registries such as **npm** and the 
 **VS Code Marketplace**\, compromising hundreds of downstream organization
 s simultaneously through trusted releases installed by their developers.\n
 \nOver the past year\, AsyncAPI faced two supply chain attacks by **TeamPC
 P** and **Miasma**\, compromising packages with up to **3.3+ million combi
 ned weekly downloads**\, such as:\n\n* `@asyncapi/specs` (3.1M weekly)\n* 
 `@asyncapi/generator` (~129k weekly)\n* Official VS Code extensions\n\nThi
 s session presents the **tactics\, techniques\, and procedures (TTPs)** we
  saw used in both incidents\, mapped directly to the **MITRE ATT&CK framew
 ork**. We will trace the end-to-end blast radius to illustrate how automat
 ed supply-chain compromises propagate into enterprise and public sector en
 vironments across Europe and Luxembourg.\n\nFinally\, attendees will gain 
 actionable defense strategies and tools we have been using to tighten our 
 security measures. We will showcase how we overhauled our release pipeline
 s using:\n\n* **OIDC Trusted Publishing**\n* Automated CI/CD security scan
 ning\n* Hardened token isolation\n* Least-privilege permission scopes on a
 utomation bots\n* Continuous workflow auditing to catch anomalous triggers
  prior to artifact publication\n\nAttendees will leave with practical chec
 klists to audit their own GitHub Actions\, build pipelines\, and IDE exten
 sion supply chains against active threat groups.
LOCATION:CyberSecurity
URL:https://pretalx.com/open-source-conference-luxembourg-2026/talk/ETANAX
 /
END:VEVENT
END:VCALENDAR
