54 subscribers
Pergi ke luar talian dengan aplikasi Player FM !
Podcast Berbaloi untuk Didengar
DITAJA


1 From Backroom Bars to Broadway with Dustin Lynch 36:27
François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
Manage episode 446413733 series 2408745
François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal.
Mentioned in the Episode:
Cooking for Geeks by Jeff Potter
Poutine
Living Off the Pipeline project
Grand Theft Actions Abusing Self Hosted GitHub Runners - Adnan Khan and John Stawinski
Where to find Francois:
LinkedIn
X: @francoisproulx
Previous Episodes:
François Proulx -- Actionable Software Supply Chain Security
FOLLOW OUR SOCIAL MEDIA:
➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
Thanks for Listening!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
309 episod
Manage episode 446413733 series 2408745
François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal.
Mentioned in the Episode:
Cooking for Geeks by Jeff Potter
Poutine
Living Off the Pipeline project
Grand Theft Actions Abusing Self Hosted GitHub Runners - Adnan Khan and John Stawinski
Where to find Francois:
LinkedIn
X: @francoisproulx
Previous Episodes:
François Proulx -- Actionable Software Supply Chain Security
FOLLOW OUR SOCIAL MEDIA:
➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
Thanks for Listening!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
309 episod
Semua episod
×
1 Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications 47:31

1 Jim Routh -- The CISO Transition to the rest of life 49:36

1 Henrik Plate -- OWASP Top 10 Open Source Risks 38:26

1 Tanya Janca -- A Secure SDLC from a Developer's Perspective 48:54

1 Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements 45:08

1 Kalyani Pawar -- Shaping AppSec at Startups 39:52


1 MO Sadek -- Building an AppSec Program from Scratch 48:50

1 Brett Crawley -- Threat Modeling Gameplay with EoP 45:28

1 Matin Mavaddat - Understanding Security as a Systemic Concern: The Role of Anti-Requirements 50:20


1 François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages 45:31

1 Steve Wilson -- The Developer's Playbook for Large Language Model Security: Building Secure AI Applications 36:32

1 Jeff Williams -- Application Detection & Response (ADR) 51:28

1 Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing 52:08
Selamat datang ke Player FM
Player FM mengimbas laman-laman web bagi podcast berkualiti tinggi untuk anda nikmati sekarang. Ia merupakan aplikasi podcast terbaik dan berfungsi untuk Android, iPhone, dan web. Daftar untuk melaraskan langganan merentasi peranti.