World Congress 2026 Europe • Jul 10, 2026 • Session details

GenAI Is a Junior Dev With Root Access

Julian Totzek-Hallhuber

Are you trusting a naive junior developer with root access to your codebase? Learn why 45% of AI-generated code introduces critical vulnerabilities that evade standard security scans.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to the generative AI code security report

An inaugural security report maps how differing language models consistently fail basic fundamentals when writing functional application code.

#2 about 2 min

Research methodology for evaluating AI code generation security

Testing four programming languages and over one hundred models reveals baseline performance capabilities against prominent software vulnerabilities.

#3 about 3 min

Analyzing security pass rates across languages and vulnerabilities

Java models exhibit surprisingly low security pass rates compared to other programming languages when natively generating logical code.

#4 about 1 min

The negligible impact of AI model size on security

Both large and tiny language models consistently achieve comparable security benchmark pass rates hovering around fifty percent.

#5 about 3 min

Evolution of security performance in newer generative AI models

Recent language model iterations demonstrate notable performance improvements by raising the overall code security pass rate to seventy percent.

#6 about 4 min

Building a real application using Cursor and vibe coding

An experiment building an application exclusively through conversational prompting exposes how AI assistants casually inject outdated backend dependencies.

#7 about 3 min

Discovering undetected business logic flaws in AI generated applications

Artificial intelligence tools frequently introduce severe logic errors like exposed administrative privileges that entirely bypass classical static testing tools.

#8 about 3 min

Exposing missing access controls through automated penetration testing

Automated penetration testing identifies hidden direct object reference exploits and complex access control failures concealed inside vibe coded components.

#9 about 3 min

Shifting security testing focus toward critical application logic problems

Engineering teams must adopt offensive penetration testing to capture the subtle operational flaws that baseline security scanners routinely miss.

#10 about 2 min

Comparing security pass rates between human programmers and AI

Historical industry metrics illustrate how human software developers statistically compare against artificial intelligence systems for producing consistently secure code.

#11 about 2 min

Using language models to self-detect and flag software vulnerabilities

Evaluating active software frameworks utilizing advanced language models requires painstakingly filtering through pervasive false positives to pinpoint reliable findings.

#12 about 2 min

Propagating vulnerability fixes across multiple development projects automatically

Emerging ecosystem tools intend to capture localized developer prompt corrections and systematically distribute those essential security patches across organizations.

Matching moments

3:31 min

Evaluating the flaws and benefits of AI code generation

Sergio Freire Sergio Freire · Europe 2026 Virtual

2:59 min

Building a vulnerable application for security testing

Malte Lantin Malte Lantin +1 · World Congress 2026 Europe

1:06 min

Addressing security flaws in AI-generated code

Balázs Kiss · World Congress 2023

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

1:10 min

Defending against vulnerabilities in AI generated code

Chris Heilmann +2 · LIVE

3:37 min

Managing security risks in AI-accelerated development processes

Carey Liu Carey Liu · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 25, 2026 · 14:10–14:40

Stage 1

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 5

Vibe Coding Accessibility

Karl Groves

Focused on actively fixing accessibility

Karl Groves
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 25, 2026 · 12:55–13:25

Stage 7

The spectrum of agentic coding: From vibe coding to high-quality software engineering

YK Sugi

Developer Experience Manager at Eventual

YK Sugi
Open session

World Congress 2026 North America

September 23, 2026 · 10:00–17:00

Stage 11

Building Stuff with GenAI - The Open Minded Workshop beyond OpenAI

Andreas Erben

CTO for Applied AI and Metaverse at daenet

Andreas Erben