The following supply-chain scenarios, exploits and lateral movement scenarios will be explored in this training: * Application Supply Chains: * Client-side Supply Chain attacks ranging from magecart-style attacks to other client-side exploits* Server-side dependency attacks* Build System Attacks and Package Manager focused attacks* Dependency Confusion Attacks* Cross-Build Injection Attacks* Container Supply Chains* Container Build System Attacks* Container Registry Attacks* Trojanizing Containers* Attacks against CI Services:* Attacks against on-prem CI services like Jenkins, Bamboo, etc. * Webhook Boomerang Attacks against CI/CD Systems* Dependency attacks and template attacks against Github Actions and Gitlab CI* Cloud-Native Supply Chain Attacks: * Attacking Kubernetes Supply-Chains (Helm, Admission Controllers) etc* Attacking Continuous Deployment Services for Kubernetes and Cloud-native environments* Supply Chain Attacks and Lateral Movement with AWS and Azure.
United States
11166 Fairfax Boulevard, 500, Fairfax, VA 22030
APAC
68 Circular Road, #02-01, 049422, Singapore