Bozidar Spirovski & Wekoslav Stefanovski
How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski
#1about 2 minutes
Bridging the communication gap between developers and security
Security and development teams often work in silos, but collaboration is essential for building secure products from the start.
#2about 3 minutes
An overview of classic and modern injection attacks
The workshop covers a range of vulnerabilities from classic SQL injection and XSS to modern threats like template and AI prompt injection.
#3about 2 minutes
How SSRF exploits cloud metadata services in microservices
Server-Side Request Forgery (SSRF) is a critical vulnerability in cloud-native applications that can allow attackers to access sensitive metadata servers.
#4about 3 minutes
Weaponizing cookies and JWTs for denial of service
Attackers can cause a denial-of-service by bloating JSON Web Tokens (JWTs) in cookies to overwhelm and bottleneck backend authentication systems.
#5about 5 minutes
A practical demo of a command injection vulnerability
A hands-on demonstration shows how a command injection in a file export feature can be used to execute arbitrary commands on the server.
#6about 6 minutes
The dangerous trend of prioritizing speed over security
The pressure to ship features quickly leads to half-baked products and a culture where security is treated as an afterthought, creating significant risk.
#7about 7 minutes
Adopting a proactive mindset for secure development
Developers can prevent vulnerabilities by moving away from "magical thinking" about libraries and actively breaking their own code to find flaws early.
#8about 7 minutes
A horror story of hardcoded and shared secrets
A real-world example illustrates the common but dangerous practice of committing secrets to git and sharing passwords in plain text files.
#9about 5 minutes
How flawed password policies create predictable vulnerabilities
A financial institution's policy of monthly password rotation led to users adopting a simple, predictable pattern that defeated the security measure entirely.
Related jobs
Jobs that call for the skills explored in this talk.
IGEL Technology GmbH
Bremen, Germany
Senior
Java
IT Security
tree-IT GmbH
Bad Neustadt an der Saale, Germany
€54-80K
Intermediate
Senior
Java
TypeScript
+1
Matching moments
04:38 MIN
Hands-on security training for developers
How GitHub secures open source
02:52 MIN
Common web application threats like injection and DoS
Security in modern Web Applications - OWASP to the rescue!
02:26 MIN
Why developers make basic cybersecurity mistakes
Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes
01:20 MIN
When attackers target the developer's own tools
Stranger Danger: Your Java Attack Surface Just Got Bigger
05:38 MIN
Why attackers use prompt injection techniques
Manipulating The Machine: Prompt Injections And Counter Measures
01:43 MIN
Understanding and defending against prompt injection attacks
DevOps for AI: running LLMs in production with Kubernetes and KubeFlow
03:17 MIN
Exploring specific web vulnerabilities and filtering issues
WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking
05:12 MIN
How simple code can hide critical vulnerabilities
Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools
Featured Partners
Related Videos
What The Hack is Web App Sec?
Jackie
The attacker's footprint
Antonio de Mello & Amine Abed
101 Typical Security Pitfalls
Alexander Pirker
Typed Security: Preventing Vulnerabilities By Design
Michael Koppmann
Security in modern Web Applications - OWASP to the rescue!
Jakub Andrzejewski
Security Pitfalls for Software Engineers
Jasmin Azemović
You click, you lose: a practical look at VSCode's security
Thomas Chauchefoin & Paul Gerste
Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor
Feross Aboukhadijeh
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

WeCloudData
Remote
CSS
GIT
HTML
REST
+7

Y-Security GmbH
Azure
Burp Suite
Network Security
Microsoft Active Directory

Punk Security Ltd.
Remote
£30-40K
Junior
Go
Java
.NET
+9

BWI GmbH
Idar-Oberstein, Germany
Linux
JavaScript
Kubernetes





Reflow
Zürich, Switzerland
Remote
CHF60-140K
Azure
DevOps
Heroku
+7