WeAreDevelopers LIVE Sep 25, 2024

Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools

Liran Tal

Is your AI coding assistant quietly introducing critical vulnerabilities? Discover how LLM tools hallucinate insecure packages and learn why you must treat auto-completed code like untrusted user input.

Pause
Mute Enter Fullscreen
#1 about 4 min

Understanding NoSQL injection in basic middleware

How unvalidated user input flows into sensitive methods to cause NoSQL injections.

#2 about 3 min

Analyzing a real-world NoSQL vulnerability in Rocket Chat

Reviewing a widely deployed NoSQL injection affecting password reset policies.

#3 about 3 min

The evolution of code reuse and dependency risks

Tracing how developers adopt external code from forums to package registries and AI assistants.

#4 about 4 min

Core AI security risks and data poisoning

Why trusting language model outputs equates to trusting potentially poisoned training data.

#5 about 3 min

Exploiting exposed language models in commercial applications

How integrating conversational interfaces into products can accidentally expose internal operations.

#6 about 5 min

Path traversal risks in AI-generated file uploads

Discovering hidden path traversal flaws when copying generated file upload code directly into production.

#7 about 4 min

Command injection vulnerabilities in ChatGPT snippets

How generative models encourage risky operations like shell execution without adequate security warnings.

#8 about 3 min

Exploiting hallucinated software packages and package dependencies

The security implications of models recommending phantom packages that attackers can register maliciously.

#9 about 3 min

Path traversal vulnerabilities built by IDE assistants

Reviewing explicit file system access flaws created by typical code autocomplete suggestions.

#10 about 5 min

Cross-site scripting via context-blind HTML escaping

Why generalized sanitization methods fail against context-dependent injection constraints like HTML element attributes.

#11 about 2 min

Prompt injection and data exfiltration inside IDEs

How malicious repository comments manipulate coding assistants to leak sensitive developer data.

#12 about 2 min

How coding assistants amplify existing insecure code

Why autocomplete tools replicate and spread legacy SQL vulnerabilities throughout active projects.

#13 about 2 min

Mitigating AI code risks and OWASP recommendations

Utilizing automated scanning tools and security standards to validate machine-generated logic.

Matching moments

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · WWC 2025

3:37 min

Managing security risks in AI-accelerated development processes

Carey Liu Carey Liu · WWC Europe 2026

4:15 min

Security vulnerabilities introduced by frictionless AI code generation

Angie Jones Angie Jones +3 · LIVE

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann +3 · LIVE

3:53 min

Analyzing software composition risks and shadow AI vulnerabilities

Matthew Brady Matthew Brady · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Developer Liability in the AI Agent Era: Building Responsibly

Alla Barbalat

Freelancer Trade Show Spokesmodel and Tech Event Host

Alla Barbalat
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Reinventing Testing Practices in the AI Era

Eric Deandrea

Java Champion & Senior Principal Software Engineer, IBM

Eric Deandrea
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash