World Congress 2026 Europe Jul 10, 2026 Session details

GenAI Is a Junior Dev With Root Access

Julian Totzek-Hallhuber

Are you trusting a naive junior developer with root access to your codebase? Learn why 45% of AI-generated code introduces critical vulnerabilities that evade standard security scans.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to the generative AI code security report

An inaugural security report maps how differing language models consistently fail basic fundamentals when writing functional application code.

#2 about 2 min

Research methodology for evaluating AI code generation security

Testing four programming languages and over one hundred models reveals baseline performance capabilities against prominent software vulnerabilities.

#3 about 3 min

Analyzing security pass rates across languages and vulnerabilities

Java models exhibit surprisingly low security pass rates compared to other programming languages when natively generating logical code.

#4 about 1 min

The negligible impact of AI model size on security

Both large and tiny language models consistently achieve comparable security benchmark pass rates hovering around fifty percent.

#5 about 3 min

Evolution of security performance in newer generative AI models

Recent language model iterations demonstrate notable performance improvements by raising the overall code security pass rate to seventy percent.

#6 about 4 min

Building a real application using Cursor and vibe coding

An experiment building an application exclusively through conversational prompting exposes how AI assistants casually inject outdated backend dependencies.

#7 about 3 min

Discovering undetected business logic flaws in AI generated applications

Artificial intelligence tools frequently introduce severe logic errors like exposed administrative privileges that entirely bypass classical static testing tools.

#8 about 3 min

Exposing missing access controls through automated penetration testing

Automated penetration testing identifies hidden direct object reference exploits and complex access control failures concealed inside vibe coded components.

#9 about 3 min

Shifting security testing focus toward critical application logic problems

Engineering teams must adopt offensive penetration testing to capture the subtle operational flaws that baseline security scanners routinely miss.

#10 about 2 min

Comparing security pass rates between human programmers and AI

Historical industry metrics illustrate how human software developers statistically compare against artificial intelligence systems for producing consistently secure code.

#11 about 2 min

Using language models to self-detect and flag software vulnerabilities

Evaluating active software frameworks utilizing advanced language models requires painstakingly filtering through pervasive false positives to pinpoint reliable findings.

#12 about 2 min

Propagating vulnerability fixes across multiple development projects automatically

Emerging ecosystem tools intend to capture localized developer prompt corrections and systematically distribute those essential security patches across organizations.

Matching moments

2:59 min

Building a vulnerable application for security testing

Malte Lantin Malte Lantin +1 · WWC Europe 2026

1:06 min

Addressing security flaws in AI-generated code

Balázs Kiss · WWC 2023

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

1:10 min

Defending against vulnerabilities in AI generated code

Chris Heilmann +2 · LIVE

3:37 min

Managing security risks in AI-accelerated development processes

Carey Liu Carey Liu · WWC Europe 2026

3:28 min

Human accountability in AI-assisted code generation

Daniel Gebler Daniel Gebler +2 · WWC 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić
Open session

World Congress 2026 North America

Vibe Coding Accessibility

Karl Groves

Focused on actively fixing accessibility

Karl Groves
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

The spectrum of agentic coding: From vibe coding to high-quality software engineering

YK Sugi

Developer Experience Manager at Eventual

YK Sugi
Open session

World Congress 2026 North America

Building Stuff with GenAI - The Open Minded Workshop beyond OpenAI

Andreas Erben

CTO for Applied AI and Metaverse at daenet

Andreas Erben