> Markdown version of [/events/world-congress-2026-north-america/sessions/1683-on-the-public-clock](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1683-on-the-public-clock). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # On the Public Clock: Open-Source Defense When You're Not in the Club - **Event:** World Congress 2026 North America ## Description The time between a vulnerability being found and being exploited has gone negative - see X, LinkedIn, Hacker News, etc. AI models now surface flaws faster than maintainers can patch them. The industry's answer (some at least) is coordinated, pre-disclosure defense: pool findings, patch under embargo, push mitigations before the bug is public. It works. But it works for the people inside the coalition — the banks, hyperscalers, the vendors who can patch on an attacker's timeline, commercially. Most of us aren't in that room. We're building, scaling, pivoting, and breaking things at machine speed. Our priorities are different, but security affects us, no less than the big guys. I call it "the middle: small security teams, heavy open-source dependencies, no seat at the embargo table" aka most of us. We inherit the same risk on the public side of disclosure — and we're not idle about it. This talk is about what coordination looks like from down here. Not a poorer copy of the embargo club — an open response commons: when a disclosure drops, a mitigation gets generated once and propagates across the enforcement points teams already run, at machine speed, instead of every shop reinventing it alone. I'll show an early, working v0 built with security partners who aren't limited to being conventional, and make the case for what we build next. I don't have all the answers, I'm just a guy trying to solve some problems. This is an invitation to contribute. ## Speaker ### [Nicholas Muy](https://www.wearedevelopers.com/@nicholas-muy) VP Engineering Platform and Security at Scrut.io ## Related talks at this congress - [Know Your Enemies: Live Exploit of a PHP Engine Security Breach](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1420-know-your-enemies) — Alexandre Daubois - [Stop Running Mystery Meat in Production](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1726-stop-running-mystery) — Jeroen van Erp - [Give the Agent a Budget, Not a Token](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1695-give-the-agent-a) — Sachin Malhotra - [GitHub’s Team X-Ray: Your Repository Knows More About Your Team Than Your Team Does](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1691-github-s-team-x-ray) — Andrea Griffiths ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)