Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Alpha-Omega × Python Software Foundation (PyCon...

Alpha-Omega × Python Software Foundation (PyCon US 2026 Sponsor Presentation)

Avatar for Seth Michael Larson

Seth Michael Larson

June 16, 2026

Transcript

  1. Alpha-Omega “Protect society by catalyzing sustainable security improvements to the

    most critical open source software projects and ecosystems”
  2. What to expect: • Security Focus Areas • What’s the

    Plan? • How YOU can Prepare • Q&A
  3. “Watering Hole Attacks” Shai-Hulud, LiteLLM, Trivy, Phishing API Tokens Accounts

    CI/CD Pipelines Cryptocurrency Ransomware Credentials Repeat 🔁 Malicious Release 📦😈
  4. 7+ vulnerabilities in CPython, pip, uv 1 Critical, 3 High

    Mitigated with PyPI 💡 Hypothesis + OSS-Fuzz
  5. Stop Watering Hole Attacks • Python Package Index: ◦ Trusted

    Reporters (Auto-Quarantine) ◦ More Trusted Publishing providers ◦ Relinquishing Privileges? ( sudo Mode) ◦ “Staged Releases” • CPython: ◦ “Secure Distributions”