Coffee With Developers Mar 4, 2026

How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski

Bozidar Spirovski , Wekoslav Stefanovski

Are you blindly trusting your dependencies? Discover why shipping MVPs leaves your infrastructure vulnerable, and learn how to break your systems before attackers do.

Pause
Mute Enter Fullscreen
#1 about 3 min

Bridging the gap between developers and security tools

A security professional and a developer discuss ways to align their respective workflows for building safer products.

#2 about 3 min

Identifying common and emerging application injection attack vectors

Understanding why vulnerabilities ranging from legacy database queries to modern text prompt manipulations persistently occur.

#3 about 5 min

Exploiting cloud metadata servers and manipulating authentication tokens

How unchecked server requests can expose system metadata and overload application authentication services across cloud architectures.

#4 about 5 min

Using intentionally vulnerable applications for practical security training

An overview of how a custom sandbox environment provides safe, hands-on practice identifying logic and application flaws.

#5 about 2 min

Avoiding supply chain risks within standard software dependencies

Recognizing hidden threats located inside widely adopted package managers and binary compilation tools.

#6 about 4 min

Compromising default application security through rapid development cycles

The dangers of prioritizing immediate functionality and minimum viable products over fundamental infrastructure testing.

#7 about 3 min

Establishing safe access controls for automated intelligence agents

Why granting excessive system permissions to automated language tools introduces severe operational unpredictability.

#8 about 3 min

Integrating fundamental security evaluations into agile development sprints

How relying on temporary code segments that bypass strict testing creates profound, long-term deployment vulnerabilities.

#9 about 6 min

Overcoming magical thinking regarding third-party software library security

Improving infrastructure defenses requires fundamentally questioning the out-of-the-box safety guarantees declared by external deployment dependencies.

#10 about 7 min

Diagnosing recurring credential management failures within production environments

Auditing enterprise configurations consistently reveals mistakes involving static repository secrets and mathematically predictable rotation formulas.

#11 about 3 min

Prioritizing thoughtful software development over immediate technology adoption

A concluding reminder to evaluate long-term potential system impacts rather than blindly integrating unverified trending technologies.

Matching moments

2:40 min

Identifying command injection flaws in developer infrastructures

Vandana Verma Sehgal · LIVE

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · WWC 2025

2:43 min

Understanding common web application vulnerabilities and risks

Jakub Andrzejewski · WWC 2023

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

5:13 min

Identifying sophisticated supply chain attacks and simulated software vulnerabilities

Mohamed Shiralizadeh · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali