World Congress 2026 Europe Jul 10, 2026 Session details

The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most

Marcus Wermuth

A single typo-squatted package can exfiltrate terabytes of data from a developer's machine unnoticed. Discover why traditional security tools are blind to this front door to production.

Pause
Mute Enter Fullscreen
#1 about 3 min

The hidden dangers of routine package installations

How a simple dependency installation can silently compromise credentials without triggering production alarms.

#2 about 3 min

Why security monitoring misses developer laptops

While production endpoints and cloud infrastructure are heavily monitored, the local developer machine remains dangerously unobserved.

#3 about 2 min

New local attack vectors introduced by AI agents

AI coding tools, MCP servers, and extensions operate with high privileges and alter local environments faster than human review.

#4 about 2 min

Evolving attacks from npm scripts to prompt injection

Attackers are shifting from visible post-install scripts to subtle natural language instructions in AI readmes.

#5 about 4 min

Real incidents of compromised local packages and tools

Recent vulnerabilities in heavily downloaded packages and AI utilities highlight the severe risk of local data exfiltration.

#6 about 3 min

Why existing security and device management tools fail

Standard EDR, SCA, and MDM platforms lack situational awareness for complex local assets like MCP configurations and hidden dot files.

#7 about 3 min

Practical ways to audit local environments manually

Development teams can mitigate risks by running simple inventory commands and enforcing package version cooldown periods.

#8 about 4 min

Discovering unexpected assets through local system scans

Directly scanning a development workstation reveals forgotten dependencies, outdated extensions, and stored plain-text tokens.

#9 about 2 min

Gaining visibility without blocking developer workflows

Generating an upfront asset inventory gives security teams critical oversight without immediately blocking necessary engineering tools.

#10 about 3 min

Securing non-developer workstations and driving organizational adoption

Using concrete incident data helps convince leadership to secure not just engineering machines, but all laptops utilizing AI.

Matching moments

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann +3 · LIVE

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

2:17 min

Security incidents in extension marketplaces and package managers

Chris Heilmann +2 · LIVE

2:40 min

Identifying command injection flaws in developer infrastructures

Vandana Verma Sehgal · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 14:25–14:35

Outdoor Stage

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 13

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Developer Relations Engineer at Zerops.io

Kristiyan Velkov
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser