World Congress 2026 Europe Jul 10, 2026 Session details

Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?

Matthew Brady

Could you report an active exploit within 24 hours? The EU Cyber Resilience Act renders traditional AppSec obsolete, demanding real-time intelligence to avoid €15M compliance fines.

Pause
Mute Enter Fullscreen
#1 about 3 min

Understanding the Cyber Resilience Act timeline and scope

An overview of when the regulation takes effect and which digital products fall under its mandatory requirements.

#2 about 2 min

Identifying products and exclusions under the new law

How to determine if software, hardware, or SaaS platforms meet the criteria for compliance or exist as exemptions.

#3 about 2 min

Software product classification levels and compliance penalty structures

Discover how products are classified by critical risk levels and the significant financial penalties imposed for protocol violations.

#4 about 3 min

Mandatory vulnerability reporting and secure product design requirements

Understand the core obligations for rapid vulnerability disclosure alongside adopting secure-by-default architectures and verifiable build materials.

#5 about 2 min

Navigating changes to the European Product Liability Directive

How extended software liability empowers consumers to seek damages and why compliance evidence provides essential legal defense.

#6 about 2 min

Preparing for increased exploit volumes in compromised software ecosystems

Why rising exploit discoveries require adopting a disaster recovery strategy rather than relying solely on prevention mechanisms.

#7 about 3 min

Mapping the complete software supply chain attack surface

Why comprehensive security requires validating build environments and commercial dependencies beyond open source component scanning.

#8 about 3 min

Regulatory obligations for upstream software vendors and providers

How indirect suppliers must produce engineered component lists and vulnerability disclosure reports to fulfill downstream manufacturer demands.

#9 about 4 min

Analyzing software composition risks and shadow AI vulnerabilities

Audits reveal significant rates of unmitigated vulnerabilities and the invisible dangers introduced by AI-generated snippets replacing standard package managers.

#10 about 2 min

Meeting mandatory 24-hour vulnerability disclosure and reporting deadlines

Explore the operational challenge of submitting real-time exploit discoveries and mitigation plans to ENISA without any delay.

#11 about 1 min

Transitioning vulnerability tracking to the European Vulnerability Database

Why upcoming compliance demands shifting incident classification from traditional national sources to the specialized EU tracking system.

#12 about 3 min

Identifying actively exploited vulnerabilities before official public disclosure

Recognize the limitations of public exploit catalogs and the severe reporting delays caused by abandoned governmental scoring metrics.

#13 about 2 min

Leveraging continuous intelligence tracking for rapid vulnerability alerting

How supplemental tracking databases bridge gaps left by public systems to alert teams about unclassified security incidents instantly.

#14 about 3 min

Implementing an auditable and evidenced secure software lifecycle

Why compliant development workflows demand rigorous static analysis, interactive fuzz testing, and exhaustive evidence tracking directly within automation pipelines.

#15 about 3 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Review concrete technical steps to adopt full-scope artifact analysis and dynamic response protocols to meet rapid enforcement expectations.

#16 about 2 min

Addressing active AI incident remediation and broad ecosystem support

An analysis of the risks behind deploying artificial intelligence for first response workflows and expanding tool integration across diverse package ecosystems.

Matching moments

1:03 min

Navigating European software legislation with open regulatory compliance processes

Francisco Carneiro Francisco Carneiro · WWC 2025

2:12 min

Preparing engineering organizations for rapid vulnerability response and remediation

Milin Desai Milin Desai +3 · WWC Europe 2026

1:46 min

Improving tool accuracy and delivering automated vulnerability remediation

Michael Wildpaner Michael Wildpaner · WWC 2025

2:52 min

Implementing effective corporate vulnerability disclosure policies

Chloé Messdaghi · WWC 2021

2:09 min

Actionable security guidance in product validation reports

Carey Liu Carey Liu · WWC Europe 2026

3:10 min

Implementing preventative cybersecurity to mitigate software supply chain risks

Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois