Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Red Team vs. the Build Pipeline

Solution Category Security Operations
Type Webinar
Organization ReversingLabs
Event Format Company Webinar

Webinar Description

What the event is about
“Red Team vs. the Build Pipeline” is a tactical webinar hosted by ReversingLabs as part of their Spectra Collective series. The event focuses on demonstrating real-world attack techniques targeting the software build pipeline, specifically CI/CD systems, and showcases both offensive (red team) and defensive (blue team) perspectives. Attendees will witness live demonstrations of how attackers exploit vulnerabilities such as stolen secrets, poisoned dependencies, and misconfigured runners to compromise software supply chains. The session also covers real-world incidents, including the Shai-Hulud worm attack on npm, to illustrate the practical impact of these threats. The core purpose is to educate DevSecOps and AppSec professionals on the necessity of proactively testing and defending their build pipelines against evolving supply chain attacks.

Subject Matter
– Software supply chain security
– Red teaming and penetration testing of CI/CD pipelines
– Attack techniques: stolen secrets, poisoned dependencies, misconfigured runners
– Real-world case studies (e.g., npm Shai-Hulud worm)
– Defensive best practices for DevSecOps and AppSec

Niche
Application Security, specifically Software Supply Chain Security and DevSecOps.

Target Audience
– DevSecOps practitioners
– Application Security (AppSec) professionals
– Security researchers
– Software developers and engineers involved in CI/CD
– Security teams in organizations with software development pipelines
– Likely job titles: DevSecOps Engineer, AppSec Engineer, Security Researcher, Software Engineer, Security Architect
– Industries: Technology, Finance, Healthcare, Energy, Public Sector, High Tech

Problems the Event Helps Solve
– Identifying and mitigating vulnerabilities in software build pipelines
– Understanding attacker tactics in CI/CD environments
– Preventing supply chain attacks, account takeovers, and dependency confusion
– Bridging the knowledge gap between offensive and defensive security in software development

Commercial Intent Signals
– Education and thought leadership
– Product marketing (mentions of Spectra Assure and ReversingLabs solutions)
– Community building (Spectra Collective)
– Lead generation (registration required, free trial offers)

Key Messaging & Positioning
– “Testing the defenses of the software supply chain has never been more essential”
– “Stop Trusting & Start Verifying Your Software”
– “Red teaming the build pipeline itself is essential to software supply chain security”
– Emphasis on real-world attacks and actionable best practices

Sponsors / Vendors / Technologies Mentioned
– ReversingLabs (host and technology provider)
– Spectra Assure (ReversingLabs product)
– Safety Cybersecurity (speaker’s organization)
– npm (referenced in case study)

Format & Experience
– Virtual webinar
– Live tactical demonstration
– Expert-led, technical, hands-on focus
– Community-oriented (Spectra Collective)

Final Classification
Event Category: Software Supply Chain Security Webinar
Primary Audience: DevSecOps and AppSec professionals
Primary Problem Solved: Securing CI/CD pipelines against real-world supply chain attacks
Commercial Goal of the Event: Education, thought leadership, and product marketing/lead generation
5 relevant keywords: Software Supply Chain, CI/CD Security, Red Teaming, DevSecOps, Dependency Attacks