SUPPLY CHAIN ATTACKS: when the vector is the pipeline, not the code

No ratings

Presented at Ekoparty Miami 2026 by

The most recent supply chain attacks don't exploit vulnerabilities in code. They exploit the pipeline. Nobody treats it as an attack surface, and that's exactly how Shai-Hulud compromised 14k+ secrets without touching a single application. Through a live demo you'll see the attack from the attacker's perspective and walk away with a practical framework to evaluate and strengthen your own pipelines.