Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialWednesday, August 7, 2024, 11:20 am–12:00 pm
Microsoft Copilot Studio is the technology that powers Microsoft's copilots (AI assistants), and the platform behind custom copilots built in the enterprise. The promise behind this technology is that every copilot build is secure, which results in the assumption that every bot will be secure by default. This talk, by Michael Bargury, will answer the question: Does this promise and inherent assumption hold up under scrutiny? Spoiler: It does not. Attend this talk to find out why and how to build copilots that mitigate such failures.
Wednesday, August 7, 2024, 1:30 pm–2:10 pm
Chris Wysopal, CTO and co-founder of Veracode, will explore the impact of GenAI on software development and its implications for cybersecurity in this Black Hat session. With GenAI, developers are shifting from doing traditional code reuse to generating new code snippets by GenAI prompt, signifying a huge change in software development dynamics. This change also means new AppSec challenges. Come to this talk to learn more about what these challenges are, why they exist, and how to address them.
Wednesday, August 7, 2024, 1:30 pm–2:10 pm
There is currently a systemic lack of awareness around self-hosted CI/CD agent security. Organizations can speed up the development lifecycle by using CI/CD systems, but they make fundamental configuration errors, especially when using self-hosted build agents. These errors expose organizations, and any dependents, to potentially high-impact supply chain attacks. Two security researchers, Adnan Khan and John Stawinski, will address this insecurity in their talk and answer the questions: How can attackers exploit your organization's CI/CD pipelines? And how can you defend against these attacks?
Wednesday, August 7, 2024, 2:30 pm–3:00 pm
Python is a popular choice for creating malware, so much so that Python temporarily stopped the registration of new users in March 2024. However, what makes it a great choice for malicious campaigns (ease of development, wide user base, prebuilt modules, and multiplatform compatibility) also makes it popular within the cyber-community. Such popularity increases the demand for Python decompilers, but efforts to maintain these types of tools are hindered by Python's unstable bytecode specification, leaving the demand unmet. This presentation from nine researchers will attempt to address this issue by integrating natural language processing (NLP) techniques with classical programming language (PL) theory to create a Python decompiler that can function on Python with minimal human maintenance effort.
Wednesday, August 7, 2024, 4:20 pm–5:00 pm
Hillai Ben-Sasson and Sagi Tzadik, two security researchers from Wiz, will present the result of their attempts to answer the question: How susceptible are AI-as-a-service systems to attacks that could compromise their security and expose sensitive customer data? The result takes the form of a novel technique that gives cross-tenant access to customers' private data, including private models, weights, datasets, and even user prompts. The attack also can achieve global write privileges, allowing for the deployment of a backdoor to launch software supply chain attacks. This talk is a must in the growing age of AI.
Thursday, August 8, 2024, 11:20 am–12:00 pm
This talk introduces Certainly, a pioneering offensive/defensive tool. Security researchers STÖK and Joona Hoikkala designed it to simplify long-term passive credential harvesting and payload deployment of bitflip-typosquatting domains. Bit flipping is the process of changing a single bit from 1 to 0 or 0 to 1, which results in a valid domain that is off by one character. For example: Google could become “woogle,” if bit-flipped. The speakers will revisit and expand on previously published bit-flip research before showcasing how Certainly can be used in your next red-team engagement.
Thursday, August 8, 2024, 12:15 pm–12:40 pm
Join the director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Jen Easterly, for a quick 25-minute talk about technology and its future, one that’s focused on the betterment of cybersecurity, both within and outside critical infrastructure areas. The CISA has already taken some steps toward this future through its software supply chain security policies, such as Secure by Design. Find out what else is in the works by attending the talk.
Security leaders can stop by ReversingLabs' booth on the exhibition floor to chat with our experts about our powerful software supply chain security solution, RL Spectra Assure. Plus, we’ll have cookies (the good kind!).


The post-mortem reaches sobering conclusions, and demands a plan of action for the AI industry — plus your SecOps strategy.

The TeamPCP actors, alleged to be behind one of the most active supply chain threats, were arrested — but this is not the end of Shai-Hulud.

UAT-10147 leveraged agentic AI to go beyond scripting to deliver a backdoor. The method highlights the need for agentic SOCs.