WeAreDevelopers LIVE Apr 30, 2025

WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking

Chris Heilmann , Daniel Cranney , Ramona Schwering

Treat AI like an untrusted junior developer. Blindly relying on "vibe coding" exposes infrastructure to catastrophic vulnerabilities, massive data leaks, and advanced prompt injection attacks.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to security advocacy and automation testing

How automated testing and community feedback loop bridge the gap between product development and actual security needs.

#2 about 4 min

AI adoption and unintentional data exposure risks

Integrating generative models without auditing input workflows exposes proprietary data to widespread malicious extraction.

#3 about 5 min

Security risks of trusting AI-generated code and regex

Relying unconditionally on generated regular expressions introduces severe injection vulnerabilities and sudden compute overloads.

#4 about 3 min

Surge in actively exploited vulnerabilities in 2025

How the proliferation of untested generative code creates a drastic increase in successful cyber attacks.

#5 about 3 min

The dangers of vibe coding and exposed API keys

Drafting programmatic concepts largely through prompts leads to exposed tokens and massive provider bills.

#6 about 5 min

Prompt injections and extracting locked API keys from LLMs

Bad actors exploit indexed linguistic models using jailbreaks and policy puppetry to harvest sensitive environment variables.

#7 about 5 min

Hardware keys and mitigating persistent password vulnerabilities

Transitioning from traditional access constraints to localized hardware authenticators minimizes reliance on easily compromised cloud platforms.

#8 about 2 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Mitigating drastic spikes in localized traffic streams requires specialized firewall tooling independent of host networks.

#9 about 3 min

Monitoring AWS traffic with endpoint auditing tools

Utilizing precise HTTP auditing tools exposes unexpected outbound traffic behaviors from newly provisioned cloud instances.

#10 about 5 min

Employee surveillance data leaks and hardware policies

An open storage bucket leak of millions of employee screenshots highlights widespread corporate hardware privacy violations.

#11 about 2 min

Discovering and mitigating WebSocket hijacking exploits

Securing bidirectional events requires manual network validation because sockets inherently lack standard domain sandboxing guardrails.

#12 about 2 min

Over-filtering inputs and XSS prevention in web editors

Implementing aggressive sanitization measures inadvertently hinders developers from writing valid configuration strings during content creation.

#13 about 7 min

Potential Chrome divestment and the future of open web

A mandated browser divestment introduces severe privacy risks surrounding third-party trackers and targeted advertising networks.

#14 about 5 min

Overcoming sycophantic LLM responses with custom system prompts

Applying persistent semantic memory instructions overrides conversational padding patterns to deliver immediate technical responses.

#15 about 6 min

Assessing authenticity in AI-generated podcasts and virtual avatars

Deploying completely synthetic audiovisual personalities negatively impacts consumer trust compared to genuine human interaction.

#16 about 2 min

Irony in anti-piracy videos using stolen digital assets

Investigators discovered unauthorized font licenses injected inside foundational broadcasting commercial assets.

#17 about 2 min

Final takeaways on verifying code generated by LLMs

Treating generative inputs identically to unproven junior pull requests establishes a baseline barrier against catastrophic logical failures.

Matching moments

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

6:00 min

Navigating web element APIs and emerging software vulnerabilities

Chris Heilmann +3 · LIVE

2:42 min

The rise and risks of agentic software development

Neena Thomas Neena Thomas · WWC Europe 2026

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann +3 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Small LLM in your Browser: Huge Opportunities for Web Applications

Daniel Ostrovsky

UI/UX Architect at Payoneer | AI Architect | Full Cycle Development Expert | Public Speaker | Open Source Contributor |

Daniel Ostrovsky
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

When Humans Stop Writing Code: Rethinking Languages, Compilers, and Responsibility

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Beyond Vibe Coding: Using CLI Tools as Your AI Counterpart in Pair Programming

Ron Veen

Java enthusiast and Special agent for Team Rockstars IT

Ron Veen