BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Sold Out - CI/CD Weaponization: Build It\, Deploy It
 \, Own It\n   Tags: DEF CON Workshop | DEF CON Workshops\n   When: Sunday\
 , Aug 9\, 09:00 - 12:59 PDT\n   Where: LVCCW Level 2 W230 (Workshops) - [1
 ]Map\n\n   Description:\n\n   GitHub Actions has become the de facto autom
 ation layer for modern\n   software\, and the de facto attack surface. In 
 2025\, a single\n   compromised Action leaked secrets across 23\,000 repos
 itories. One year\n   later\, the TeamPCP group ran the same playbook at s
 cale by\n   compromising Trivy's actions. Different victims\, same root ca
 use: a\n   CI/CD pipeline that trusted what it shouldn't.\n\n   In this ha
 nds-on workshop\, participants will build a complete\n   end-to-end attack
  chain in a controlled lab environment\, emulating\n   adversary TTPs obse
 rved in recent GitHub Actions breaches. From\n   initial access through ma
 licious workflow manipulation to secret\n   exfiltration\, each phase is p
 aired with detection and analysis\n   techniques to bridge offensive and d
 efensive perspectives.\n\n   Whether you're on a red or purple team lookin
 g to simulate attacker\n   behavior\, or part of a blue team (AppSec or De
 vSecOps) aiming to\n   harden CI/CD pipelines\, this workshop delivers pra
 ctical\, real-world\n   skills grounded in today‚Äôs evolving threat l
 andscape.\n\n   Speakers:Ricardo Sanchez\,Daniel Malvaceda\n\n   SpeakerBi
 o:  Ricardo Sanchez\n\n   Ricardo Sanchez is an accomplished cybersecurity
  professional with a\n   passion for empowering others through knowledge s
 haring. He has built\n   his career designing and implementing innovative 
 technology strategies\n   for threat intelligence\, detection engineering\
 , and threat hunting to\n   combat evolving cyber threats. Currently\, Ric
 ardo leads the\n   Application Security (AppSec) practice at a leading ins
 urance company\n   in Peru\, where he works closely with DevSecOps teams t
 o enhance\n   security across the software development lifecycle (SDLC) an
 d supply\n   chain. Committed to lifelong learning\, Ricardo thrives on an
 alyzing\n   malware and staying at the forefront of cybersecurity advancem
 ents.\n\n   SpeakerBio:  Daniel Malvaceda\n\n   Daniel Malvaceda is a secu
 rity architect who spends most of his time\n   figuring out how CI/CD pipe
 lines and supply chains actually fail\, then\n   writes it up so others do
 n't have to learn it the hard way. Lately\n   he's also poking at AI/LLM a
 gents\, since pipelines aren't the only\n   thing shipping untrusted code 
 anymore. He co-founded pipebreach.com\,\n   where real-world supply chain 
 attacks get reproduced\, dissected\, and\n   written up for everyone else.
  He also co-organizes the DevSecOps\n   village at Ekoparty (Argentina and
  Miami)\, and has dragged these same\n   topics to stages at Ekoparty\, De
 vOps Days\, and 8.8 Security\n   Conference. If a pipeline can be weaponiz
 ed\, he wants to know about it\n   first.\n\n   Links:\n       Registratio
 n (July 14\, 2026\, Noon US Pacific) - [2]https://events.humanitix.com/sun
 _am_ws1_4043\n   '\n\n   1. #LVCCW_Level2_North\n   2. https://events.huma
 nitix.com/sun_am_ws1_4043\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T160000Z
LOCATION:DEF CON Workshops - LVCCW Level 2 W230 (Workshops)
SUMMARY:Sold Out - CI/CD Weaponization: Build It\, Deploy It\, Own It
END:VEVENT
END:VCALENDAR
