In GitHub We Trust: 10 Ways You Could Get Pwned @OWASPGLOBAL
In GitHub We Trust: 10 Ways You Could Get Pwned  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
GitHub's growing popularity poses security risks due to misplaced trust in its content. Developers' reliance on GitHub can introduce backdoors into their software development lifecycle. While public registries are closely monitored, GitHub's vast ecosystem makes it challenging to detect backdoors in open-source projects. This talk discusses the risks and mitigations of this emerging attack vector.

Eyal Paz
OX Security
VP of Research

Eyal Paz is the VP of Research at OX Security, a software supply chain
security startup. His work includes hands-on security research toward a
holistic DevSecOps solution. Before joining OX Security, Eyal spent eleven
years at Check Point working on security research for product innovation
in application security, malware analysis, and phishing prevention. Eyal is
also a sought-after university lecturer on various cyber security topics. He
has a bachelor's degree in Software Engineering and a master's in
Computer Science. Currently, he is a Ph.D. candidate researching the
problem of encrypted traffic classification.
linkedin.com/in/eyal-paz-0852b41a
ox.security/blog/ (blog)
ox.security (company)

Liad Cohen
OX Security
Security Research Team Lead

Liad Cohen is a Security Research Team Lead and a Data Scientist at OX Security. His day-to-day work involves empowering open source security and code security with AI capabilities, developing innovative data-driven AppSec detection systems from ideation to PoCs to production, and making product roadmap a reality, backed by deep pioneer security research. He started his career as a young "script kiddie", later becoming a gifted mathematician. Liad holds a Master of Science degree in Computer Science. He is a Mentor in hackathons and CTFs, publishing academic papers and articles in security journals and presented state of the art security research at BlackHat USA, RSA Conference, OWASP Global and others.
linkedin.com/in/securing
ox.security (company)

Managed by the OWASP® Foundation
owasp.org
In GitHub We Trust: 10 Ways You Could Get PwnedSecuring Apps Without a Budget: Minimal Viable Security Strategies track 2Kernel Alchemy: Crafting Mobile Kernel Code to Evade Modern RASP Protections - Subho HalderOWASP Global Board of Directors - June 2026 Public MeetingAPI Fuzzing in the SSDLC Problems and Possible SolutionsOWASP Global Board of Directors - December 2025OWASP Top 10 for LLMsThe Carrot vs The Stick: Making a Positive Impact on the Security + Developer RelationshipThe Appsec Program I Regret BuildingRunning Your Application Security Program Like a Marathon - Derek FangOWASP Board Finance Summary Full - July 2026Chinese PRC shenanigans in the npm mirror ecosystem
OWASP Foundation |

In GitHub We Trust: 10 Ways You Could Get Pwned

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER