Managing AppSec Risk Beyond Vulnerabilities. How does your organization protect your developers from malicious supply-chain attacks?

Tuesday, April 29th, 01:00 PM PDT

Location:

The W Hotel San Francisco

About this event:

Hear a senior security researcher’s perspective on the threat landscape in open-source software. Based on extensive research, Veracode’s Senior Principal for Security Research, Dr. Ross Bryant, will share insights on the threats against software developers in open-source software. Learn how to prevent malicious packages from entering your software development environment. Gain a new perspective on the risks that malware poses in open-source packages and how these risks differ from vulnerabilities.

You will learn:

  • Why managing vulnerabilities is not sufficient to protect your organization
  • The domains of risk that malicious open-source packages present
  • How to address the challenge of targeted attacks against your developers

Gain insights on steps you can take to improve and explore practical strategies for getting your security posture against business objectives without sacrificing developer velocity.

Lunch will be provided for participants.

Presenter:

Dr. Ross Bryant

Senior Principal for Security Research

Veracode

Ross Bryant is a Senior Principal for Security Research at Veracode. He was recently the Chief of Research at Phylum, acquired by Veracode in January 2025. Ross has over twenty years of research experience in open-source software threats, cybersecurity operations, and mathematics during his tenure with Sandia National Laboratories, the United States Air Force, and the United States Department of Defense.