Coffee With Developers Nov 10, 2025

Security Blindspots and How to Learn About Them - Anna Oliveira

Anna Oliveira

Think automated scanners catch every vulnerability? Anna Oliveira built Blind Spot, an open-source CLI game, to help developers manually train their eyes to spot what AI misses.

Pause
Mute Enter Fullscreen
#1 about 4 min

Creating a terminal game for security education

How the challenges of learning secure coding inspired an interactive command-line tool.

#2 about 4 min

Exploring the mechanics of vulnerability spotting

How category filters and multiple-choice questions train developers to identify vulnerabilities.

#3 about 3 min

Sourcing vulnerabilities and encouraging open source collaboration

Using OWASP materials and AI tools to generate security challenges for public contribution.

#4 about 3 min

Contributing data sets without learning Go

How developers can add new security challenges using simple YAML configuration files.

#5 about 2 min

Building terminal user interfaces with Bubble Tea

Leveraging the Bubble Tea library to create visually appealing command-line environments.

#6 about 3 min

Sharing side projects and embracing public feedback

The importance of coding for joy and sharing educational tools despite being a learner.

#7 about 3 min

Balancing automated security scanners with manual reviews

Why understanding application context remains crucial despite the rise of automated scanning platforms.

#8 about 4 min

Transitioning from software engineering to security roles

Navigating career mobility hurdles by introducing security practices within current engineering workflows.

#9 about 4 min

Solidifying engineering concepts by teaching others

How building educational tools and explaining concepts deepens personal technical understanding.

#10 about 2 min

Expanding project accessibility through cultural localization

Plans to translate project content to ensure non-English speakers can access security training.

Matching moments

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

6:12 min

Recommended training platforms for developing security mindsets

Thomas Konrad · WWC 2021

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

30 sec

Identifying technical blind spots and exploring open source

Cassidy Williams · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey