Untrusted Execution: Attacking the Cloud Native Supply Chain - Francesco Beltramini
About this talk
This talk explores the critical issue of trust regarding code executed in production workloads, particularly in light of vulnerabilities posed by complex software supply chains that may be exploited by motivated attackers. The speaker discusses the inherent risks that organizations face and the challenges of securing software supply chains end-to-end while maintaining integrity. By examining threat modeling and aligning security practices with an organization's risk appetite, attendees will learn about practical threat modeling techniques, common attack scenarios, and effective countermeasures. The session provides insights into best practices, frameworks, and an industry-standard technology stack specifically designed to secure software supply chains running on Kubernetes.