
#37 - A conversation about securing the build pipeline with Adnan Khan, Lead Security Engineer at Praetorian
About this episode
On today's episode of The Cybersecurity Defenders Podcast we are joined by security engineer Adnan Khan to talk about securing the build pipeline and explore some common vulnerabilities in enterprise Github configurations.
Organizations using GitHub Actions with self-hosted runners are at risk of attackers gaining an internal network foothold from the Internet if they compromise one developer’s personal GitHub access token. Key configuration adjustments can secure these pipelines and limit the damage from a breach.
Adnan's talk at BSidesSF: Securing the Pipeline: Protecting Self-Hosted HitHub Runners
The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.
Get every episode summarized
Each time The Cybersecurity Defenders Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Cybersecurity Defenders Podcast

How AI adoption in enterprise infrastructure has expanded the attack surface wit...
The Cybersecurity Defenders Podcast

Cybersecurity is a core leadership issue & opportunity with David Chernitzky fro...
The Cybersecurity Defenders Podcast

Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT...
The Cybersecurity Defenders Podcast

Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley I...
The Cybersecurity Defenders Podcast