BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Commit\, Push\, Compromise: Attacking Modern GitHub 
 Orgs\n   Tags: Red Team Village | Misc\n   When: Sunday\, Aug 9\, 11:00 - 
 11:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop 
 Stage 2 -\n   [1]Map\n\n   Description:\n\n   GitHub is where identity\, a
 utomation\, and production changes all meet\,\n   which makes it a great t
 arget. Once an attacker gets in\, the distance\n   between read access and
  shipping malicious code to production is often\n   a lot shorter than tea
 ms expect.\n\n   This talk covers realistic attack paths into GitHub organ
 izations. We\n   start with initial access: device-code phishing and abuse
  of trusted\n   GitHub Apps like the GitHub CLI. Then we follow the creden
 tials\, from\n   long-lived Personal Access Tokens sitting on developer ma
 chines to\n   short-lived secrets like GITHUB_TOKEN that leak through logs
  and\n   artifacts\, and show how both enable lateral movement and privile
 ge\n   escalation.\n\n   Then we get into a technique we call secret stomp
 ing. Anyone with\n   write access to a repo can overwrite an Actions secre
 t\, including\n   protected environment secrets reviewers assume are safe.
  Leak the real\n   value first\, then overwrite the secret with a payload 
 that keeps the\n   original value intact\, and the pipeline stays green wh
 ile your code\n   runs on the runner. Using the org\, repo\, and environme
 nt scope\n   hierarchy\, you can shadow a secret in one repo without touch
 ing\n   others\, then delete it and leave nothing behind at the org level.
 \n\n   We close on the defensive side with detection strategies and respon
 se\n   playbooks built around the signals that matter\, plus how to get\n 
   coverage into the places GitHub is hardest to watch. Blue teams leave\n 
   with a checklist for locking down identities\, tokens\, integrations\,\n
    and workflows. Red teams leave with a map of where GitHub controls\n   
 break in practice.\n\n   After the talk we're running a hands-on workshop 
 in a private GitHub\n   org built for this\, focused on secret stomping. Y
 ou'll leak a secret\,\n   stomp it with a payload that keeps the pipeline 
 green\, and use scope\n   shadowing to exploit your way onto a sensitive r
 unner without tripping\n   the obvious alarms. Bring a laptop.\n\n   Speak
 ers:Andrew Buchanan\,Max CM\n\n   SpeakerBio:  Andrew Buchanan\n\n   Andre
 w Buchanan is a Senior Red Team Operator with over six years of\n   offens
 ive security experience spanning adversary simulation\,\n   penetration te
 sting\, and real-world attack execution.\n\n   Andrew has spent years cond
 ucting advanced red team engagements and\n   security assessments across h
 ighly complex enterprise environments at\n   one of Canada's largest finan
 cial institutions.\n\n   Andrew specializes in initial access and social e
 ngineering\, having\n   designed and delivered numerous campaigns that clo
 sely mirror\n   real-world threat actor tradecraft. His work spans offensi
 ve\n   operations across on-premises\, cloud\, and hybrid environments\, w
 ith a\n   particular focus on cloud attack surfaces\, execution chains\, a
 nd\n   targeted phishing and pretexting campaigns.\n\n   SpeakerBio:  Max 
 CM\n\n   Max leads offensive security at Figment and brings over a decade 
 of\n   experience spanning national security\, security research\, and\n  
  blockchain security. He has published multiple CVEs and conducts\n   rese
 arch focused on CI/CD pipeline security\, threat modeling\, secure\n   key
  management\, and practical security controls for high-risk systems.\n\n  
  '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T180000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 2
SUMMARY:Commit\, Push\, Compromise: Attacking Modern GitHub Orgs
END:VEVENT
END:VCALENDAR
