Loading…
Friday November 6, 2026 3:30pm - 4:15pm PST
Recent attacks such as S1ngularity, Shai-Hulud, and the Trivy GitHub Actions compromise have shown that CI/CD pipelines are among the most attractive attack surfaces in modern software development. A single workflow misconfiguration can lead to remote code execution, credential theft, repository takeover, and software supply chain compromise.

This session introduces RepoHunter, an AI-driven research bot that combines static analysis with LLM reasoning to discover exploitable CI/CD workflows at scale. Built in just 48 hours, RepoHunter models real attack paths, prioritizes repositories by supply chain impact, and helps uncover vulnerabilities that traditional approaches often miss.

Using this methodology, I identified and responsibly disclosed more than 30 critical vulnerabilities across major open-source and enterprise projects, including repositories maintained by Microsoft, Red Hat, SAP, Ansible, Eclipse, Ceph, and QGIS. The research identified attack patterns—including CI/CD propagation and supply chain worm-like behavior—before they appeared in major real-world incidents. Later attacks, including the Trivy compromise, demonstrated these same techniques in practice.

Attendees will learn how these attacks work, why AI is changing vulnerability research, and how to combine static analysis with AI reasoning to find and prevent the next generation of CI/CD supply chain attacks.
Speakers
avatar for Barak Haryati

Barak Haryati

Senior Director of Product Security, JFrog
Barak Haryati is Senior Director of Product Security at JFrog, focused on CI/CD security, AI/LLM systems, and software supply chain risk. His research explores how attacker-controlled input flows through build systems and is executed in privileged environments.

He developed RepoHunter, an AI-driven research agent that discovers, prioritizes, and models real exploitation paths across CI/CD workflows at scale. Using this approach, he identified and responsibly disclosed 30+ critical vulnerabilities across widely used open source and enterprise... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)

Attendees (1)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link