๐ COSCUP x UbuCon Asia 2026 CFP closes in 3 days โ and today happens to be World Password Day.
๐
CFP Deadline: 2026/5/9 AoE
๐จ Submit your proposal: https://pretalx.coscup.org/coscup-2026/cfp
๐ CFP announcement: https://blog.coscup.org/2026/03/coscup-x-ubucon-asia-2026-coscup-x.html
#COSCUP2026 #UbuConAsia #HITCON #CyberResilience #CyberSecurity #OpenSource #OpenSourceSecurity
โก New Secure Development Talk at BSides Luxembourg 2026!
๐๐จ๐๐๐๐๐ก๐ ๐ฉ๐ฆ. ๐๐จ๐ฌ๐๐ก๐ โ ๐ ๐ง๐๐๐ ๐ข๐ ๐๐๐ฉ๐๐๐ข๐ฃ๐๐ก๐ ๐๐ก ๐๐ก-๐๐ข๐จ๐ฆ๐ ๐ฆ๐๐ ๐ง๐ข๐ข๐ โ Diogo Lemos
Why do Software Composition Analysis tools so often fail in practice? This 40-minute talk takes you inside the journey of building a production-ready, open-source SCA platform designed to fix exactly that problem. Instead of drowning teams in noisy alerts and inconsistent findings, the focus shifts to clarity, prioritization, and actionable risk reduction.
The session explores how to design and implement an SCA system that scales across large organizationsโcovering dependency discovery (including transitive ones), vulnerability aggregation from multiple sources, normalization of inconsistent data, and a risk-based scoring model that helps teams focus on what actually matters. A live demo will show a real repository being scanned, vulnerabilities being identified, and results flowing directly into CI/CD pipelines for actionable enforcement.
Diogo Lemos is an Application Security Engineer with deep experience in building security tooling at scale. Having worked at Checkmarx, Flutter Entertainment, and OLX, he specializes in automation, SCA, SAST, and scalable AppSec programs, and actively contributes to open-source security initiatives.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #SecureDevelopment #SCA #SupplyChainSecurity #AppSec #OpenSourceSecurity
โก New Talk Spotlight at BSides Luxembourg 2026!
๐๐จ๐ฅ๐๐ง๐๐ก๐ ๐ฆ๐๐๐จ๐ฅ๐ ๐ฆ๐ข๐๐ง๐ช๐๐ฅ๐: ๐ง๐๐ ๐๐ฅ๐ง ๐ข๐ ๐ฆ๐๐๐๐๐ง๐๐ก๐ ๐ฆ๐๐๐ ๐๐๐ฃ๐๐ก๐๐๐ก๐๐๐๐ฆ โ Frithjof Hoffmann
Rethink how you build software in this insightful 40-minute session from the Secure Development track. Just like curating an art gallery, selecting dependencies requires careful evaluation, authenticity checks, and long-term consideration. This talk explores how overlooked third-party components can introduce hidden risksโfrom vulnerabilities and malware to licensing and maintenance issues.
Discover practical strategies to assess, manage, and automate dependency selection, while building a trusted and resilient software supply chain. Learn how adopting a โcuration mindsetโ can transform development practicesโhelping teams move beyond blind trust and toward secure, high-quality foundations.
Frithjof Hoffmann is a cybersecurity professional specializing in software supply-chain security, threat intelligence, and risk management. With a strong focus on helping organizations reduce risk and improve visibility, he brings practical expertise in building secure and scalable software ecosystems.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #SecureDevelopment #SupplyChainSecurity #OpenSourceSecurity #AppSec #CyberSecurity
I had another chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity
With all the events unfolding almost every day lately, there's never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it
It's a lot less complicated than it seems, I know I've made this a lot harder than it needs to be
https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. Itโs a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, itโs really not that hard to put some plans together. Itโs easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident.