World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

September 23–25, 2026

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

The time between a vulnerability being found and being exploited has gone negative - see X, LinkedIn, Hacker News, etc.

AI models now surface flaws faster than maintainers can patch them. The industry’s answer (some at least) is coordinated, pre-disclosure defense: pool findings, patch under embargo, push mitigations before the bug is public. It works. But it works for the people inside the coalition — the banks, hyperscalers, the vendors who can patch on an attacker’s timeline, commercially.

Most of us aren’t in that room. We’re building, scaling, pivoting, and breaking things at machine speed. Our priorities are different, but security affects us, no less than the big guys. I call it “the middle: small security teams, heavy open-source dependencies, no seat at the embargo table” aka most of us. We inherit the same risk on the public side of disclosure — and we’re not idle about it.

This talk is about what coordination looks like from down here. Not a poorer copy of the embargo club — an open response commons: when a disclosure drops, a mitigation gets generated once and propagates across the enforcement points teams already run, at machine speed, instead of every shop reinventing it alone.

I’ll show an early, working v0 built with security partners who aren’t limited to being conventional, and make the case for what we build next. I don’t have all the answers, I’m just a guy trying to solve some problems. This is an invitation to contribute.

Related talks at this congress

Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

GitHub’s Team X-Ray: Your Repository Knows More About Your Team Than Your Team Does

Andrea Griffiths

Senior Developer Advocate

Andrea Griffiths
All sessions at this congress