> Markdown version of [/videos/100331-fighting-the-next-wave-of-cybercrime?t=205](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime?t=205). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Fighting the Next Wave of Cybercrime Are autonomous threat actors exploiting your network while you wait for weekly patches? Discover how to aggressively shrink your attack surface and treat AI agents as first-class identities. - **Speakers:** [Michele Zuccala](https://www.wearedevelopers.com/@michele-zuccala), [Misha Bragin](https://www.wearedevelopers.com/@misha-bragin), [Ross Kukulinski](https://www.wearedevelopers.com/@ross-kukulinski), [Frank Schlesinger](https://www.wearedevelopers.com/@frank-schlesinger), [Tomislav Tipurić](https://www.wearedevelopers.com/@tomislav-tipuric) - **Event:** World Congress 2026 Europe - **Published:** July 10, 2026 - **Duration:** 30:27 - **URL:** https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime ## Summary As malicious actors leverage autonomous AI to discover network vulnerabilities in minutes, enterprises face a stark operational speed gap against traditional weekly patching cycles. To structurally close this gap, security teams must pivot from relying solely on cyclical vulnerability scans to aggressively shrinking their public attack surfaces and over-investing in runtime protection. This is especially crucial as deterministic malicious scripts are replaced by "agentic threat actors" that autonomously adapt to network surprises, pivot payloads on the fly, and pose a significantly higher operational risk. Inside the corporate perimeter, the adoption of internal AI agents introduces complex access challenges. Security leaders must treat non-human AI agents as first-class identities, tying each to a designated responsible individual (DRI). To prevent autonomous systems from executing destructive actions, organizations should enforce strict zero-trust network segmentation, comprehensive application-specific audit trails, and just-in-time permissions—even leveraging "LLM-as-a-judge" models for evaluating database mutations. The open-source community is experiencing a parallel challenge, fighting a massive influx of AI-generated code and bounty-hunting pull requests, which necessitates automated, deny-by-default triage pipelines. Furthermore, modern compliance frameworks like Europe's DORA are holding managing directors personally liable for IT failures, pushing enterprises past checkbox compliance into rigorous disaster recovery testing. Yet, maintaining security cannot mean halting productivity. When provisioning controls become too friction-heavy, employees inevitably bypass them, creating a dangerous surge in shadow AI. By providing automated, low-friction access to vetted tools with read-only defaults, security teams can empower their workforce to use AI safely while maintaining the necessary human skepticism and accountability required for true defense-in-depth. **Keywords:** ai-driven cybercrime, agentic threat actors, runtime security protection, zero-trust network segmentation, non-human identity management, LLM-as-a-judge patterns, open source PR flooding, DORA compliance frameworks, shadow AI prevention, designated responsible individual, legacy mainframe zero-trust, just-in-time access permissions, dynamic payload pivoting, automated vulnerability triage ## Chapters 1. **Closing the operational speed gap in enterprise cybersecurity** (00:00) — How organizations pivot their defense strategies to counter the extreme speeds of AI-driven vulnerability scanning. 1. **Securing heterogeneous legacy payment infrastructure against AI** (03:25) — Why highly sensitive legacy payment infrastructures still rely on closed networks and deep fake awareness to maintain security. 1. **Using LLMs to reverse engineer undocumented legacy code** (05:36) — How modern reasoning models assist engineering teams in documenting and reverse-engineering opaque older codebases. 1. **Segmenting networks to isolate critical systems from agents** (06:22) — Why separating critical internal systems from public endpoints minimizes the operational threat profile of autonomous AI agents. 1. **Governing and auditing internal AI agents for security** (07:08) — How assigning explicit identities and just-in-time permissions governs the data access of autonomous internal agents. 1. **Differences between autonomous AI agents and traditional malware** (11:00) — How agentic threat actors dynamically pivot and self-adapt during network encounters unlike deterministic malware scripts. 1. **Handling the surge of AI-generated open-source code contributions** (12:27) — How engineering teams manage the high volume of automated open-source pull requests generated by users chasing bug bounties. 1. **Automating pull request triaging and real-time infrastructure scanning** (14:45) — How enterprise platforms deploy automated assistants to review code changes and conduct real-time infrastructure threat scans. 1. **Navigating DORA compliance and executive liability in security** (16:53) — How European regulatory frameworks hold managing directors personally liable for maintaining continuous cybersecurity resilience. 1. **Using on-premise hosting to simplify enterprise compliance audits** (19:55) — Why adopting self-hosted or open-source deployment models helps organizations bypass lengthy third-party compliance audits. 1. **Prioritizing runtime protection over continuous attack surface reduction** (21:48) — Why security leaders overinvest in speedy runtime responses under the assumption that network breaches are inevitable. 1. **Preventing shadow AI by reducing friction in security controls** (23:08) — How providing fast read-only system provisioning prevents employees from circumventing overly restrictive security protocols. 1. **Distinguishing AI-assisted users from experienced security professionals** (25:59) — Why relying on AI-generated security answers still requires critical skepticism, strict accountability, and deep domain expertise. 1. **Retaining the defender advantage in the cybersecurity race** (29:08) — How defenders maintain a robust operational edge through advanced tooling despite attackers generating exploit code with language models. ## Related Moments - [Current state of security in AI applications](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) (from "Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue") - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") - [Managing security risks introduced by autonomous AI agents](https://www.wearedevelopers.com/videos/1403-five-things-in-tech-that-matter-and-we-have-to-make-work) (from "Five things in tech that matter and we have to make work") - [The necessity of developer intelligence amidst automated attack generation](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) (from "Let’s write an exploit using AI") - [Addressing active AI incident remediation and broad ecosystem support](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) (from "Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?") - [Understanding the landscape of AI capabilities and risks](https://www.wearedevelopers.com/videos/715-a-hundred-ways-to-wreck-your-ai-the-in-security-of-machine-learning-systems) (from "A hundred ways to wreck your AI - the (in)security of machine learning systems") ## Related Articles - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) ## Related Jobs - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Senior AI Agent Software Engineer (Go, Python) (m/f/x)](https://www.wearedevelopers.com/jobs/48277-senior-ai-agent-software-engineer-go-python-m-f-x) at **Dynatrace** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat** - [Staff Software Engineer, Copilot Experiences](https://www.wearedevelopers.com/jobs/ext/164361-staff-software-engineer-copilot-experiences) at **GitHub**