World Congress 2026 Europe Jul 10, 2026 Session details

Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World

Adrian Mouat

With AI developing zero-day exploits instantly, can your engineering team keep up? Learn how to deploy defensive generative models to proactively secure your open-source supply chain.

Pause
Mute Enter Fullscreen
#1 about 6 min

Emergence of LLMs capable of autonomous exploit development

Unexpectedly strong AI models like Mythos can autonomously transform vulnerabilities into functional exploits.

#2 about 3 min

Evaluating the real threat against critical infrastructure

While AI apocalypse claims are hyperbolic, previous hacks demonstrate that cyber incidents can impact critical physical infrastructure.

#3 about 4 min

The collapsing patch window for newly disclosed vulnerabilities

The time between vulnerability disclosure and exploitation has virtually vanished due to AI processing speeds.

#4 about 3 min

Leveraging older LLMs defensively for vulnerability hunting

Engineering teams can proactively use current AI models to sweep internal codebases for hidden security flaws.

#5 about 4 min

Building a six-step harness for automated vulnerability discovery

An automated security harness requires threat modeling guardrails and sandbox verification to filter false positives.

#6 about 4 min

Practical mitigation strategies for modern software supply chains

Rebuilding immutable containers, migrating to memory-safe languages, and adopting zero-trust practices minimize the attack surface.

#7 about 2 min

Securing developer infrastructure and eliminating long-lived tokens

Removing static credentials from deployment pipelines prevents severe compromises regardless of codebase vulnerabilities.

#8 about 3 min

The disproportionate impact of AI vulnerabilities on open source

Part-time maintainers face burnout as automated vulnerability discovery generates overwhelming unverified reports.

#9 about 2 min

Coordinating security mitigations with the CISA clearinghouse

Industry coalitions share threat intelligence and develop automated fixes to protect partners against rapid AI exploitation.

#10 about 2 min

Project Akritas and ecosystem-wide security patch coordination

The Linux Foundation provides a maintainer of last resort to fork and secure abandoned open source projects.

#11 about 2 min

Relying on robust test suites for automated AI patching

Automated remediation agents require comprehensive test coverage and human oversight to prevent deployment regressions.

Matching moments

1:20 min

Utilizing industry threat models for AI security

Balázs Kiss · World Congress 2023

2:45 min

Sourcing vulnerabilities and encouraging open source collaboration

Anna Oliveira · Coffee With Developers

2:58 min

Managing vulnerabilities in auto-generated software development processes

Chris Wysopal Chris Wysopal +2 · World Congress 2024

1:39 min

Summarizing strategies for securing the open source ecosystem

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

4:26 min

Addressing unpatched cross-site scripting vulnerabilities in parsers

Vandana Verma Sehgal · LIVE

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · World Congress 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 3

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 24, 2026 · 14:25–14:35

Outdoor Stage

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali