Kalle Sirkesalo: AI-Powered Slopsquatting: Is Your Software Supply Chain Compromised?
About this talk
In this session, Kalle Sirkesalo addresses the critical issue of software supply chain vulnerability posed by AI-driven slopsquatting, a threat that takes advantage of naming variations and developer behaviors to introduce malicious code. He elaborates on the enhanced effectiveness of this technique through artificial intelligence and outlines the potential risks organizations face due to inadequate dependency management in CI/CD pipelines. By providing real-world examples, Kalle offers practical strategies for implementing automated checks and enhancing vetting processes, emphasizing the importance of DevSecOps practices for securing applications and the responsibility of all stakeholders in maintaining the integrity of the open-source ecosystem.
More from this event
See all 5 talks →
Mackenzie Jackson: The Mechanisms That Enable Misuse and What We Can Do About It
40:11
Falko Banaszak: Why a Layered Storage Architecture is Critical for Cyber Resilience
30:21
Andriy Kusyy: The Hidden Layer of Cyberattacks
30:25
Gediminas Černiauskas: Resilience Under Fire: Lessons from Cyber Defense in Ukraine
45:12