Loading…
Friday November 6, 2026 10:30am - 11:15am PST
The modern application security boundary has shifted from the network edge directly into the software delivery pipeline. As organizations embrace cryptographic provenance and OpenID Connect (OIDC) identity federation to eliminate static cloud secrets, attackers have adapted. By exploiting weak isolation boundaries in shared CI/CD runner caches, threat actors can now extract OIDC tokens from execution memory, compromise cloud environments, and inject malicious code that carries valid supply-chain provenance signatures.

In this session, we will break down the mechanics of an advanced post-exploitation pipeline attack. We will move past generic supply-chain advice to look at how ephemeral runner states can be weaponized against cloud infrastructures. Attendees will walk away with an architectural blueprint for securing federated identities in CI/CD and an open-source audit script to evaluate their own pipeline runner configuration risks.
Speakers
avatar for Sneha Rangari

Sneha Rangari

Security Architect, Visa
I am a Cybersecurity Professional with over 7 years of experience in Security Engineering, Security Architecture, Gen AI/ML in security, Third party Vendor applications, Cloud applications and Technology Risk Management. I am CISSP and GMLE certified and currently working with Vi... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link