
Audience at DevOpsDays Zurich
The audience during Beyond SBOMs at DevOpsDays Zurich 2026.
When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: basic SBOMs alone aren't enough. But when the recent "Mini Shai Hulud" worm and its family of variants began silently tunneling through CI/CD pipelines to infect downstream containers, it proved our entire approach to build-time security needs a massive upgrade.
In this talk, Docker Captain Mohammad-Ali A'râbi explores how modern supply-chain attacks are evolving—from the blast radius of the September 2025 NPM breach to the stealthy, self-propagating nature of the Mini Shai Hulud attacks—and how the next generation of tools can stop them in their tracks.

The audience during Beyond SBOMs at DevOpsDays Zurich 2026.

On stage during the Beyond SBOMs talk at DevOpsDays Zurich 2026.








Selfie with the audience after Beyond SBOMs at DevOpsDays Zurich 2026.

Audience view of the Shai-Hulud section during Beyond SBOMs at DevOpsDays Zurich 2026.


Norse gods on the slides during Beyond SBOMs at DevOpsDays Zurich 2026.

Stage and audience view during the CVE section of Beyond SBOMs.