Christian <cy> Kühn
Christian has worked in most fields in IT. From yawning in the Datacenter swapping hard drives at 03:00 in the night, through administrating and consulting on large-scale networks he rode the devops-wave over into development. While infosec had been a sidetrack for many years, he is now fully engaging in security engineering and consulting, helping secure one of Europe's largest retail companies.
Session
Supply chain attacks are increasingly focusing on developers and automation tools.
In early 2025, someone infected a widely used security tool, then used the knowledge from that attack to subsequently infect npm- and python packages to steal developer credentials.
The talk will show how these kinds of attacks worked and how developers can protect themselves (and their assets) against similar attacks and why ai might or might not be helpful in these scenarios.