Post #3278506
2026-05-23 09:15 UTC
At the USENIX Security Enigma Track, Zach Steindler @steiza@a2mi.social detailed the massive effort to adopt Trusted Publishing. By swapping permanent passwords for ephemeral OIDC keys, we closed a major vulnerability window across registries. Watch his presentation: https://youtu.be/Vti6Av5NPuU 2/5
Replies (1)
-
@joebeone@techpolicy.social 2026-05-23 09:15
But as we secure the front door, the threat displaces. At NDSS 2026, Prof. William Enck showed how attackers are now targeting the CI/CD pipelines themselves, using cache blasting and Pwn Requests to hijack the automated assembly line. Watch here: https://youtu.be/rifS4khiNoM 3/5