Loading…
or to bookmark your favorites and sync them to your phone or calendar.
Venue: Hardwick Hub clear filter
arrow_back View All Dates
Wednesday, February 5
 

11:15am GMT

Securing Your Software Supply Chain One Open Source Project at a Time : Lori Lorusso, Percona, Head of Community
Wednesday February 5, 2025 11:15am - 11:30am GMT
Delivering software fast is one piece of the deployment puzzle, but delivering it securely is the glue that keeps your puzzle from falling apart. Software supply chain attacks are on the rise with security exploits directly targeting open source projects, central repositories, and software package managers. With 90% of enterprise companies using open source software in their builds no one is immune to these attacks and now more than ever the community is working hard to create safeguards and tooling to prevent potential attacks. The question then becomes who should you look to for best in class security protocols?

Thankfully the open source community is banding together and foundations like OpenSSF, CNCF and OWASP and companies are working to solve security problems. To help ensure a secure SDLC, these developer focused communities are investing time, energy, money and innovation in projects that provide security solutions. This talk will give a brief overview of some major attacks in the last decade, it will underscore the importance of securing your software supply chain at the source and will highlight a some open source projects that are on the market that are helping to close the security gaps.
Speakers
avatar for Lori Lorusso

Lori Lorusso

Head of Community, Percona
Lori has a passion and enthusiasm for working with the developer and open source community. She is a CNCF Ambassador, former CNCF Marketing Committee Chair, former Chair of the CDF Outreach Marketing Committee, program chair of cdCon 2023, and is active in the OpenSSF devrel committee... Read More →
Wednesday February 5, 2025 11:15am - 11:30am GMT
Hardwick Hub

11:35am GMT

Rust and Memory Safety : Rebecca Rumbul, Ethan Brierly, Tim Abell, David Haig, Ernest Kissiedu
Wednesday February 5, 2025 11:35am - 12:15pm GMT
Speakers
TA

Tim Abell

Rustacean, Rust Workshop
EK

Ernest Kissiedu

The Rust Foundation
DH

David Haig

Founder, Tundra Sense Limited
EB

Ethan Brierley

Rust Software Engineer, TrueLayer
avatar for Rebecca Rumbul

Rebecca Rumbul

ED and CEO, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
Wednesday February 5, 2025 11:35am - 12:15pm GMT
Hardwick Hub

1:15pm GMT

From Paper to Practice: Implementing NIST Cloud Security Guidance : Matt Turner , Andrew Martin and Ayse Vlok
Wednesday February 5, 2025 1:15pm - 1:55pm GMT
In recent years, NIST has published several Special Publications focused on cloud application and network security. These documents provide comprehensive guidance and standards for security best practices. They address cloud security controls, Zero-Trust Architectures, and microservice security, while also examining the security implications of various cloud network topologies.

In this talk, Matt will summarize the key recommendations from these publications and outline practical steps for implementation. He'll also demonstrate how to maintain ongoing compliance with these controls using OSCAL and Lula.
Speakers
avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →
avatar for Matt Turner

Matt Turner

Software Engineer, Tetrate
Matt is a software engineer at Tetrate, where he loves sharing what he's learning with the whole community. He helps people understand Istio, Envoy, and other open source projects, as well as Tetrate's solutions for enterprise service mesh management. He's been doing Dev, sometimes... Read More →
Wednesday February 5, 2025 1:15pm - 1:55pm GMT
Hardwick Hub

2:00pm GMT

See it, Hack It, Sort It: How can OSS protect our AI enablers : Marcus Tenorio, ControlPlane, Security Engineering Manager
Wednesday February 5, 2025 2:00pm - 2:15pm GMT
Your models are running, your clusters are purring, and everything seems ready to sail smoothly across the vast seas of AI. Everything’s good, right? Attacks targeting GPUs, especially those aimed at poisoning AI models during training and inference, represent a growing frontier—much discussed but rarely explored.
In this hands-on talk, we’ll dive deep into how GPUs can be attacked and, more importantly, how to defend against these threats. You’ll discover best practices and learn how open-source tools you already know—like Falco, Cilium, and others—can protect your precious models. Get ready for an adventure into the open field of GPU security in AI. See it, Hack It, Sort It.
Speakers
avatar for Marcus Tenorio

Marcus Tenorio

Security Engineering Manager, ControlPlane
People call me mart!Mart currently serves as an engineering manager on the security team at ControlPlane, where he enjoys managing various consultants who teach him every day how to break things and become a better manager and engineer.Mart began his journey in cybersecurity trying... Read More →
Wednesday February 5, 2025 2:00pm - 2:15pm GMT
Hardwick Hub

2:20pm GMT

Secure Isolation and Trust Boundaries: A Crash Course for Engineers : Sal Kimmich, Confidential Computing, Open Source security
Wednesday February 5, 2025 2:20pm - 2:45pm GMT
As our reliance on cloud-native infrastructure grows, so does the complexity of protecting sensitive data in multi-tenant and untrusted environments. This talk explores the core principles of secure isolation and trust boundaries to provide a practical understanding of how these concepts safeguard data during processing, enabling compliance, reducing risk, and building user trust. With a focus on real-world applications and accessible insights, this session demystifies the evolving security landscape and empowers engineers, policymakers, and technologists to collaboratively shape a more secure digital future.
Speakers
avatar for Sal Kimmich

Sal Kimmich

Open Source Security, Confidential Computing
Sal is a developer advocate for open source and passionate about helping engineers, ethical hackers and digital enthusiasts understand the complexity of modern software development. With over a decade of experience as building cloud-native machine learning pipelines in the healthcare... Read More →
Wednesday February 5, 2025 2:20pm - 2:45pm GMT
Hardwick Hub

3:30pm GMT

Coming AI Threats and Fixes : Kris Bondi, Mimoto, CEO and Co-founder
Wednesday February 5, 2025 3:30pm - 3:45pm GMT
Along with the benefits of AI are newly developed threats it enables. This talk spotlights new threats AI will create in 2025 as well as ways AI can be used to catch malicious activities.
Speakers
avatar for Kris Bondi

Kris Bondi

CEO and Co-founder, Mimoto
Kris Bondi is Mimoto CEO & Co-founder of Mimoto, an AI-powered cybersecurity company.In past lives, Kris has served as a crisis communications consultant to government entities, global not-for-profits, and some of the largest (and smallest) companies in the world.Kris is a long-time... Read More →
Wednesday February 5, 2025 3:30pm - 3:45pm GMT
Hardwick Hub

3:50pm GMT

Building Secure Open Source Panel : Shilpi Bhattacharjee, Sonya Moisset, Didar Gelici
Wednesday February 5, 2025 3:50pm - 4:30pm GMT
Speakers
avatar for Shilpi Bhattacharjee

Shilpi Bhattacharjee

Co-Founder, Kaizenteq Ltd
Shilpi is an international speaker, panelist. A Cloud Security and AI Security thought leader and advisor with over 13 years of expertise in business risk management leadership. She is the Co-Founder at Kaizenteq, an advisory and training company well known for their Globally Top... Read More →
avatar for Sonya Moisset

Sonya Moisset

Senior Security Advocate, Snyk
Sonya is a Senior Security Advocate and a lifelong traveler who lived in the Middle-East, North Africa and Asia. Always looking for new challenges – she made a career change from International Business Consultant in Tunisia, Saudi Arabia and Singapore to Full Stack Software Engineer... Read More →
DG

Didar Gelici

She was recognised as the DevSecOps Trailblazer at the Unsung Heroes awards 2020 and named one of the IT Security Guru's Most Inspiring Women in Cyber.Didar has held various roles in the Governance, Risk and Audit aspects of information security for 15+ years, in recent years she... Read More →
Wednesday February 5, 2025 3:50pm - 4:30pm GMT
Hardwick Hub

4:35pm GMT

Unifying Security Tools with OCSF and 60 lines of code : Spyros Gasteratos, OWASP, Security Engineer & Architect and Andrea Medda, Smithy-Security, Founding Engineer
Wednesday February 5, 2025 4:35pm - 5:00pm GMT
In today’s world, security without tool and information harmonization is impossible.

Sadly and understandably, most security projects excel at doing one thing very well, however this is insufficient for most projects and organizations who need a combination of tooling in order to efficiently implement a cybersecurity strategy.

This is why we built and open-sourced Smithy.

Smithy is a framework/SDK and an optional execution engine that allows practitioners to orchestrate any security tool and translate its information to the popular security results standard OCSF. Translating outputs to OCSF format is not an easy process as the standard can be loose in some parts.

In this talk we will walk the audience through our context, why we built Smithy, how the SDK works and our design decisions. We’ll also talk about how we leveraged protobuf to extend the OCSF format and accelerate our development thanks to its strong types, code generation capabilities and built in versioning.

Further we will show participants what are the supported components, how to create a sample component and of course pitfalls, tips and tricks.

At the end of the talk, participants will be able to orchestrate any security tool that provides an api or some sort of way to gather its results into any cybersecurity programme, for free.
Speakers
avatar for Spyros Gasteratos

Spyros Gasteratos

Security Engineer & Architect, OWASP
Spyros has over 15 years of experience in the security world. Since the beginning of his career he has been an avid supporter and contributor of open source software and an OWASP volunteer. Currently he is interested in the harmonization of security tools and information and is currently... Read More →
avatar for Andrea Medda

Andrea Medda

Founding Engineer, Smithy-Security
Founding Engineer at Smithy-Security & ex Senior Systems engineer at Cloudflare in Devtools.I started my career working in very small italian companies, mainly for free.I discovered Go and fell in love with it and I took the very difficult decision to leave my land and relocate to... Read More →
Wednesday February 5, 2025 4:35pm - 5:00pm GMT
Hardwick Hub
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -