2026-10-03 โ, STAGE 1 (Section 9) Language: English
Supply chain security conversation is booming these days after attacks like log4j came to the scene.
In this in-house research, we have conducted research on publicly available open-source assets like NPM (JS packages) and WordPress Plugins find out the presence of mistakenly or deliberately publicly exposed secrets (including private API keys and so on) i.e. AWS, Google, etc. (33 different categories of secrets!)
This could pose a risk to anyone using those packages as dependencies or plugins so that this chain of not re-inventing the wheel could become a disaster that stops the wheel once and for all.
We would be presenting our research done on a large scale after in-house scanning on:
- Scanning of around 2 Million+ NPM Packages. (almost all publicly available at the time of research)
- Scanning of about 60,000 WordPress Plugins. (almost all publicly available at the time of research)
Hassan Khan Yusufzai is the Director and CoโFounder of Laburity, bringing deep experience in the internetโwide scanning, red teaming, penetration testing, threat intelligence and dark web monitoring. He combines deep technical research with practical, hands-on offensive security work to help organizations find and fix real-world security issues across different industries.
Hassan is an inโdemand speaker who shares his research and practical findings at international security conferences. He has presented at Cyber Security Asia ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ ๐ฅ๐ฒ๐๐ถ๐น๐ถ๐ฒ๐ป๐ฐ๐ฒ ๐ฎ๐ฌ๐ฎ๐ฒ, DeepSec 2025, OWASP AppSecDays 2025, BlackHat MEA (Riyadh) in 2022, 2023 and 2025, ThreatCon 2023, MCTTP Munich Cyber Tactics, Techniques & Procedures (MCTTP) 2024, HITBSecConf 2024, and the Security Analyst Summit in Phuket in 2024.
Hassan holds the Offensive Security Certified Professional (OSCP) certification, reflecting his solid technical mastery of penetration testing and exploit development techniques.
Hassan has identified and reported over 200 CVEs to date and was recognized as one of the top hackers by WPScan for his contributions to WordPress security. His responsible vulnerability reporting has been widely recognized: in 2017 Hassan was listed in the Google Security Hall of Fame, the Twitter Security Hall of Fame, and the Microsoft Security Hall of Fame for contributions that improved the security of major platforms.
Hassan develops tools and techniques for at-scale security research and analysis, designed to handle large datasets. His work focuses on efficiency and scalability, enabling faster identification of vulnerabilities across massive environments.