Loading…
Tuesday October 6, 2026 10:40 - 11:00 CEST
As software development accelerates with the rise of autonomous agents and “Agentic Vibe Coding”, the introduction of vulnerabilities into codebases is scaling correspondingly. While Artificial Intelligence and Large Language Models (LLMs) act as proficient developers, they are frequently trained on potentially insecure data from unverified platforms like GitHub and HuggingFace, making them susceptible to data poisoning and prone to generating insecure code patterns. Furthermore, LLMs do not inherently prioritize using the most secure or updated versions of dependencies, which leaves freshly generated "vibe coded" software vulnerable to zero-day attacks. In this security in practice talk we showcase the challenges we faced over the years in our transition to a DevSecOps model and demonstrate why automated Software Composition Analysis (SCA) and Static Application Security Testing (SAST) in CI pipelines are still foundational to a modern secure coding approach. We explain how proactive controls can be used to scan new code in CI for vulnerable dependencies and implementation-level weaknesses through before merging into production. We show how Reactive controls continuously assess the full codebase so that newly disclosed vulnerabilities are detected after code has already shipped. We then proceed to outline how specific risks introduced by LLMs, such as generating code that violates secure-coding best practices and introduces vulnerable dependencies, can be initially tackled with such a traditional approach, but how this strategy falls short when the scale and speed of development do not align with traditional human review processes and alerting fatigue. To mitigate these threats, we showcase the blueprint for an agentic security pipeline augmented with deterministic SARIF reports guiding LLMs to behave like security-conscious developers and using an “LLM as a Judge” approach to reduce false-positive fatigue. Ultimately, this session emphasizes that security must shift left to the point of generation, ensuring that AI-driven development is constrained by strict automated guardrails rather than blind trust.
Speakers
avatar for Luca Galli

Luca Galli

Senior Application Security Engineer, Open Systems AG
Luca Galli, PhD, is a Senior Application Security Engineer II at Open Systems, where he specializes in application security, DevSecOps, and AI security. He drives the protection of complex multi-language monorepos and leverages AI to automate security pipelines, streamlining vulnerability... Read More →
Tuesday October 6, 2026 10:40 - 11:00 CEST
South Hall 3A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link