BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//speaker//KX9XFS
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-L9ZERS@cfp.romhack.io
DTSTART;TZID=CET:20261002T150000
DTEND;TZID=CET:20261002T170000
DESCRIPTION:Modern software delivery runs on CI/CD pipelines and attackers 
 know it. From the SolarWinds Orion backdoor to the Codecov Bash Uploader c
 ompromise and the countless exposed Jenkins instances found on Shodan\, bu
 ild systems have become one of the most valuable and least monitored targe
 ts in the software supply chain. A single misconfigured runner\, an overpr
 ivileged token\, or a poisoned dependency can silently compromise everythi
 ng downstream\; and the rise of AI-based attacking agents\, capable of aut
 onomously discovering and chaining misconfigurations at scale\, is only ra
 ising the stakes.\n\nThis workshop is a practical introduction to CI/CD se
 curity through the lens of the OWASP Top 10 CI/CD Security Risks. We'll wa
 lk through each risk category (insufficient flow control\, poisoned pipeli
 ne execution\, dependency chain abuse\, exposed secrets\, insecure system 
 configuration\, and more) grounding each one in real-world incidents that 
 made these risks tangible rather than theoretical.\n\nAfter the theory\, a
 ttendees get their hands dirty with a set of self-contained challenges bui
 lt on the CICD Goat vulnerable-by-design environment\, hunting for and exp
 loiting common pipeline misconfigurations and attack chains\, followed by 
 a guided walkthrough of each solution.\n\nPrerequisites: basic web/Linux e
 xploitation knowledge\, familiarity with git\, and a laptop with Docker an
 d a git client installed.
DTSTAMP:20260921T190418Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks - m3ssap0
 \, Mattia Brollo\, Fleeenz\, IadRabbit
URL:https://cfp.romhack.io/romhack-camp-2026/talk/L9ZERS/
END:VEVENT
END:VCALENDAR
