Anatomy of a Modern Supply Chain Attack: Github Actions FTW!
Speaker: JR Hernandez
In the eternal words of Bob Dylan 'the times they are a-changin'.
Modern supply chain attacks hit like a gut punch for security folks because they exploit something we hold sacred, our ability to share code (open-source software). In this talk I will cover an attack that targeted coinbase but ended up impacting over 23000 repositories.
The attack targets the DevOps mindset of automating everything. The attackers exploited weaknesses in the CI / CD pipeline and utilized Github Actions to steal infrastructure secrets. Stealing secrets is game over for many companies and these attacks are going to keep happening because they are successful and difficult to stop. There is no easy fix for supply chain attacks but I will discuss utilizing tools like the zero trust model that can reduce the blast radius of these attacks.
Join me as we explore this new wild frontier because one thing is certain 'the times they are a-changin'.