BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.devopsdays.org//devopsdays-portland-2026//speaker
 //UW9QFP
BEGIN:VTIMEZONE
TZID:US/Pacific
BEGIN:DAYLIGHT
DTSTART:20250910T000000
TZNAME:PDT
TZOFFSETFROM:-0700
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251102T020000
RDATE:20261101T020000
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260308T030000
RDATE:20270314T030000
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:The Diff That Looked Fine: Catching Malicious IaC Changes Your Sca
 nner Misses - Shalini Sudarsan
DTSTART;TZID=US/Pacific:20260910T100500
DTEND;TZID=US/Pacific:20260910T103500
DTSTAMP:20260824T030353Z
UID:pretalx-devopsdays-portland-2026-TTTQPG@talks.devopsdays.org
DESCRIPTION:Scanners like Checkov and tfsec are great at flagging the misc
 onfigurations we already have rules for\, and nearly useless against the o
 ne someone introduces on purpose. After watching SolarWinds and Codecov tu
 rn CI/CD pipelines into the front door\, I went looking for a better way t
 o catch malicious changes in Terraform\, Kubernetes\, and GitHub Actions p
 airing old-fashioned syntax-tree analysis with a small language model that
  reads a diff in context\, the way a security engineer would. This is the 
 real story of what worked\, what threw so many false positives it nearly b
 roke developer trust\, and where AI earns its keep in DevSecOps versus whe
 re it just adds noise.
LOCATION:Ballroom
URL:https://talks.devopsdays.org/devopsdays-portland-2026/talk/TTTQPG/
END:VEVENT
END:VCALENDAR
