StepSecurity
187 posts

StepSecurity
@step_security
Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner



🎤 BlueHat Speaker Announcement We’re excited to announce that Varun Sharma, Co-founder & CEO, StepSecurity and Ashish Kurmi, Co-founder & CTO, StepSecurity, will be speaking at BlueHat with their session, “Double‑Edged AI: Securing the Software Supply Chain in the Autonomous Era.” In this talk, Ashish and Varun analyze major 2025 software supply chain attacks, including the tj-actions compromise, the Nx s1ngularity attack (the first known malware to weaponize AI coding agents), and the Shai-Hulud npm worm series. They explore how AI is reshaping the threat landscape, acting on both sides by accelerating development while also enabling more sophisticated, self‑propagating attacks. The session concludes with a vendor‑agnostic defense framework covering CI/CD security, credential management, and AI coding agent governance. Attendees will gain practical insight into how to secure modern software supply chains in an era where autonomous systems are increasingly part of both development and attack workflows.









