Schedule
<Talks_That_Break_Boundaries/>
10:50
–
11:10
Cofee Break
12:35
–
13:35
Lunch Break
15:25
–
15:45
Reboot
10:50
–
11:10
Cofee Break
12:35
–
13:35
Lunch Break
15:05
–
15:25
Jozsef Sandor (HU) – PROPS: Learning Stack Patterns for ROP Detection on Legacy ARM-based Devices
Securing the software supply chain sounds straightforward—until you try to do it...
Between SBOMs, signed artifacts, third-party risks, and ever-growing customer demands, even well-resourced teams struggle to keep up. This talk explores the messy, expensive reality of securing the supply chain in the context of today’s secure software development lifecycle (SSDLC).
Through a fictional case study, we’ll follow one company’s attempt to build a solid supply chain security strategy—and all the ways it goes sideways. You’ll walk away with a clearer view of the standards, the gaps, and the trade-offs, plus some practical takeaways you can apply without a massive budget or a 30-person AppSec team.












































