World Congress 2023 Sep 27, 2023

Security Pitfalls for Software Engineers

Jasmin Azemović

Speed without security guarantees catastrophic breaches. Discover why missing input validation remains your application's biggest vulnerability. Learn how to bake DevSecOps directly into your daily workflow.

Pause
Mute Enter Fullscreen
#1 about 5 min

Financial and operational consequences of security breaches

Massive data breaches incur millions in costs and expose critical customer records to malicious external actors.

#2 about 3 min

Establishing foundational security practices and least privilege

Eliminating unnecessary administrative access vastly reduces the system attack surface during routine testing workflows.

#3 about 4 min

Writing secure code and utilizing threat modeling methodologies

Validating active user inputs and applying the STRIDE security framework proactively prevents deep operational system vulnerabilities.

#4 about 2 min

Mitigating risks from supply chain attacks and vulnerable libraries

Exploited open source dependencies like Log4j highlight the absolute necessity for aggressive software supply chain oversight.

#5 about 3 min

Integrating DevSecOps within the software development lifecycle

Embedding automated guardian tools into deployment pipelines aggressively catches compromised credentials and dependencies before production stages.

#6 about 2 min

Securing exposed application programming interfaces against unauthenticated access

Enforcing strict authentication and transport layer encryption prevents malicious external actors from intercepting sensitive API endpoints.

#7 about 4 min

Protecting sensitive endpoint data via active database layer encryption

Encrypting highly specific columns and managing temporal key states protects entire database records during catastrophic system leaks.

#8 about 2 min

Maintaining automated historical audit logs with temporal database features

Storing comprehensive historical state changes inside temporal databases inherently provides tamper-proof logs for deep forensic analysis.

#9 about 3 min

Structuring critical internal and external penetration testing procedures

Hiring unassociated ethical hackers to manually perform varied penetration box tests strictly ensures completely unbiased vulnerability discovery.

#10 about 3 min

Separating personal freelance workloads from secure corporate hardware environments

Managing personal software projects solely on private hardware fully insulates corporate networks from severe legal and security liabilities.

Matching moments

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

2:49 min

Integrating fundamental security evaluations into agile development sprints

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

2:05 min

Making security a foundational feature in software development

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

7:16 min

Addressing developer adoption and future software security risks

Anna Fritsch-Weninger · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey