Trouble at the top: can Python extend the chains of trust in infrastructure firmware?
cs.CR
Submitted: 2026-08-17
Updated: 2026-08-17
Code: https://github.com/brettcannon/presentations
Terminology
Sources
- GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
- MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs