BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//talk//QCMYJN
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-QCMYJN@cfp.romhack.io
DTSTART;TZID=CET:20261003T191000
DTEND;TZID=CET:20261003T195000
DESCRIPTION:Supply chain security conversation is booming these days after 
 attacks like log4j came to the scene.\n\nIn this in-house research\, we ha
 ve conducted research on publicly available open-source assets like NPM (J
 S packages) and WordPress Plugins find out the presence of mistakenly or d
 eliberately publicly exposed secrets (including private API keys and so on
 ) i.e. AWS\, Google\, etc. (33 different categories of secrets!)\n\nThis c
 ould pose a risk to anyone using those packages as dependencies or plugins
  so that this chain of not re-inventing the wheel could become a disaster 
 that stops the wheel once and for all.\n\nWe would be presenting our resea
 rch done on a large scale after in-house scanning on:\n\n- Scanning of aro
 und 2 Million+ NPM Packages.  (almost all publicly available at the time o
 f research)\n- Scanning of about 60\,000 WordPress Plugins. (almost all pu
 blicly available at the time of research)
DTSTAMP:20260921T191305Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Secret scanning in open source at scale (in-depth) - Hassan Khan Yu
 sufzai
URL:https://cfp.romhack.io/romhack-camp-2026/talk/QCMYJN/
END:VEVENT
END:VCALENDAR
