Speakers
Sign up now
Register Now!
Speakers
Schedule
Want to stay in the loop?
Sign up for our newsletter.
Integrate Microsoft Defender for Cloud with Endor Labs for reachability analysis and attack path visibility — available natively within the Defender for Cloud console. Prioritize what to fix without switching tools.
Click to read
The Cyber Resilience Act (CRA) sets mandatory security requirements for hardware and software. This blog covers key compliance objectives, challenges with OSS vulnerabilities, and best practices for maintaining security throughout the product life cycle.
Click to read
Get key insights from the 2024 Dependency Management webinar with Darren Meyer and Henrik Plate. We discuss how to prioritize vulnerabilities, navigate breaking changes, and leverage public vulnerability databases effectively.
Click to read
This blog covers key steps to simplify FedRAMP vulnerability management, helping you reduce risks and meet compliance timelines. It also provides practical tips to empower developers and streamline fixes for a smoother FedRAMP process.
Click to read
GitHub Actions are open source dependencies - secure them accordingly! Learn how to effectively manage the security risks associated with GitHub Actions with a proactive approach focusing on three key areas: visibility, hardening, and dependency management.
Click to read
Explore the five key categories of reachability and their practical applications in AppSec and development. Learn the differences between SCA and container scanning, and understand how various tools like Function-Level Reachability, Package Baselining, and Internet Reachability play crucial roles in identifying and prioritizing security risks.
Click to read
Explore the challenges of modern vulnerability management and the efficiency of the Vulnerability Exploitability eXchange (VEX) in our latest blog post. Learn how VEX helps identify and communicate the true exploitability of vulnerabilities, streamlining cybersecurity efforts in the face of overwhelming scanner findings.
Click to read
If you’ve been watching the software supply chain security space evolve, you likely know that a lot of the momentum and effort is coming out of the U.S. Federal government. This may seem surprising at first, but it shouldn’t be, when you account for the fact that the Federal government is one of the single largest procurers of technology and software in the world.
Click to read
In this seminar, we will explore cutting-edge trends, challenges, and research in the analysis, security, and management of software supply chains.
The seminar will feature a diverse lineup of speakers from both academia and industry, followed by a panel discussion. This event is tailored for industry professionals, researchers, and students, to foster a rich exchange of ideas and insights.
Location:
TU Delft CS Building
Van Mourik Broekmanweg 6
2628 XE Delft
Agenda:
09:00 - 09:20: Speaker 1 - JavaScript Call Graphs
09:20 - 09:40: Speaker 2 - Security Analysis of Package Repositories
09:40 - 10:20 Speaker 3 - Henrik
10:20 - 10:40 Speaker 4 - TBD
10:40 - 12:00: Panel Discussion
------
PhD Defense
14:30: Layman talk
15:00: Public defense of Joseph Hejderup
16:30: Reception
Location:
Aula Congrescentrum
Mekelweg 5
2628 CC Delft
------
18:30 - 22:30 Defense Party
Location
Exhale - X TU Delft (Rooftop terrace)
Mekelweg 8
2628 CD Delft
Sign up for our newsletter.