Loading…
Tuesday October 6, 2026 11:20 - 11:40 CEST
AI-powered vulnerability discovery is here, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze, especially as low-hanging fruit is rapidly plucked.

In this session, maintainers and security team members from Metal3.io and OpenStack Ironic projects share how they used an AI-based vulnerability analysis tool to uncover hidden issues. This domain is often riddled with legacy drivers and requirements to support deprecated protocols, yet built on modern cloud-native architectures where a vulnerability proof is rarely an easily automated, executable crash. For project maintainers, we will share our candid analysis of the typical AI report shortcomings, what to look for in triage, and how to deal with the incoming flow without burning out.
Speakers
avatar for Dmitry Tantsur

Dmitry Tantsur

Senior Principal Software Engineer, Red Hat
Long-term Metal3 and Ironic developer, OpenShift Metal team lead. My point of expertise is bare-metal management and provisioning
avatar for Tuomo Tanskanen

Tuomo Tanskanen

Principal Security Developer, Ericsson Software Technology
Tuomo is a telecom software engineer with 20+ years of hands-on experience across major industry giants. With vast and versatile experience in product security, incident response, and penetration testing, he is currently a Principal Security Developer at Ericsson and is Maintainer... Read More →
Tuesday October 6, 2026 11:20 - 11:40 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link