World Congress 2024

How your .NET software supply chain is open to attack : and how to fix it

July 18, 2024 16:50 – 17:20 · 30 min STAGE 2 (500)

What this session covers

Software supply chain attacks can be catastrophic, as seen with the 2020 SolarWinds hack that impacted both the government and private sectors in the United States.

Security researchers have identified that all significant package managers are vulnerable to supply chain attacks, such as typosquatting and dependency confusion. NuGet’s default configuration makes it vulnerable by design.

This session will first demonstrate how typosquatting and dependency confusion attacks can compromise .NET supply chains using the default NuGet setup. Then, we will explore effective strategies to secure your NuGet configuration and protect against these threats.

Related talks at this congress

Open session

World Congress 2024

July 19, 2024 · 09:40–10:10

STAGE 6 (120)

Supply Chain Security - Strategies and Best Practices

Hendrik Ebbers

Creating the Hedera Hashgraph | Java Punk | Board Game Nerd ✌️

HE
Open session

World Congress 2024

July 18, 2024 · 16:10–16:40

STAGE 2 (500)

Programming secure C#/.NET Applications: Dos & Don'ts

Sebastian Leuer

Fraunhofer IEM, Research Associate

Sebastian Leuer
Open session

World Congress 2024

July 18, 2024 · 13:30–14:00

STAGE 9 (600)

Open Source Secure Software Supply Chain in action

Natale Vinto

Developer Advocate Global Lead

Natale Vinto
Open session

World Congress 2024

July 19, 2024 · 10:20–10:50

STAGE 6 (120)

How Can My Software Development Be 'Secure by Design'?

Christoph Niehoff

TNG Technology Consulting

Christoph Niehoff
All sessions at this congress