World Congress 2026 Europe Jul 10, 2026 Session details

The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most

Marcus Wermuth

A single typo-squatted package can exfiltrate terabytes of data from a developer's machine unnoticed. Discover why traditional security tools are blind to this front door to production.

Pause
Mute Enter Fullscreen
#1 about 3 min

The hidden dangers of routine package installations

How a simple dependency installation can silently compromise credentials without triggering production alarms.

#2 about 3 min

Why security monitoring misses developer laptops

While production endpoints and cloud infrastructure are heavily monitored, the local developer machine remains dangerously unobserved.

#3 about 2 min

New local attack vectors introduced by AI agents

AI coding tools, MCP servers, and extensions operate with high privileges and alter local environments faster than human review.

#4 about 2 min

Evolving attacks from npm scripts to prompt injection

Attackers are shifting from visible post-install scripts to subtle natural language instructions in AI readmes.

#5 about 4 min

Real incidents of compromised local packages and tools

Recent vulnerabilities in heavily downloaded packages and AI utilities highlight the severe risk of local data exfiltration.

#6 about 3 min

Why existing security and device management tools fail

Standard EDR, SCA, and MDM platforms lack situational awareness for complex local assets like MCP configurations and hidden dot files.

#7 about 3 min

Practical ways to audit local environments manually

Development teams can mitigate risks by running simple inventory commands and enforcing package version cooldown periods.

#8 about 4 min

Discovering unexpected assets through local system scans

Directly scanning a development workstation reveals forgotten dependencies, outdated extensions, and stored plain-text tokens.

#9 about 2 min

Gaining visibility without blocking developer workflows

Generating an upfront asset inventory gives security teams critical oversight without immediately blocking necessary engineering tools.

#10 about 3 min

Securing non-developer workstations and driving organizational adoption

Using concrete incident data helps convince leadership to secure not just engineering machines, but all laptops utilizing AI.

Matching moments

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann +3 · LIVE

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

2:17 min

Security incidents in extension marketplaces and package managers

Chris Heilmann +2 · LIVE

2:40 min

Identifying command injection flaws in developer infrastructures

Vandana Verma Sehgal · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Reinventing Incident Response with AI Agents and MCP

Jayant Tyagi

Lead Member of Technical Staff @ Salesforce

Jayant Tyagi