World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

September 25, 2026 14:50 – 15:20 · 30 min Outdoor Stage

What this session covers

The time between a vulnerability being found and being exploited has gone negative - see X, LinkedIn, Hacker News, etc.

AI models now surface flaws faster than maintainers can patch them. The industry’s answer (some at least) is coordinated, pre-disclosure defense: pool findings, patch under embargo, push mitigations before the bug is public. It works. But it works for the people inside the coalition — the banks, hyperscalers, the vendors who can patch on an attacker’s timeline, commercially.

Most of us aren’t in that room. We’re building, scaling, pivoting, and breaking things at machine speed. Our priorities are different, but security affects us, no less than the big guys. I call it “the middle: small security teams, heavy open-source dependencies, no seat at the embargo table” aka most of us. We inherit the same risk on the public side of disclosure — and we’re not idle about it.

This talk is about what coordination looks like from down here. Not a poorer copy of the embargo club — an open response commons: when a disclosure drops, a mitigation gets generated once and propagates across the enforcement points teams already run, at machine speed, instead of every shop reinventing it alone.

I’ll show an early, working v0 built with security partners who aren’t limited to being conventional, and make the case for what we build next. I don’t have all the answers, I’m just a guy trying to solve some problems. This is an invitation to contribute.

Related talks at this congress

Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technology Advocate @ SUSE

Jeroen van Erp
All sessions at this congress