> Markdown version of [/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai?t=3](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai?t=3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI Chris Wysopal and Helmut Reisinger warn that AI coding assistants multiply hidden vulnerabilities. Discover how precision AI defenses can autonomously neutralize automated threats before they impact production. - **Speakers:** [Chris Wysopal](https://www.wearedevelopers.com/@chris-wysopal), [Helmut Reisinger](https://www.wearedevelopers.com/@helmut-reisinger), [Johannes Steger](https://www.wearedevelopers.com/@johannes-steger) - **Event:** World Congress 2024 - **Published:** August 13, 2024 - **Duration:** 24:14 - **URL:** https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai ## Summary Generative AI is fundamentally shifting the cybersecurity landscape by giving malicious actors unprecedented advantages in "speed, scale, and sophistication." Attackers are now using artificial intelligence to craft highly convincing, automated social engineering attacks, ranging from flawless, multi-lingual phishing campaigns to deepfake executive impersonations that facilitate financial fraud. Because the time required to develop sophisticated ransomware has plummeted from hours to minutes—and the interval between network compromise and data exfiltration has dropped from weeks to hours—protecting systems requires entirely new strategies, such as strictly enforcing multi-factor authentication and adopting real-time defenses over reactive analysis. For software engineering and DevOps teams, the widespread adoption of AI coding assistants introduces equally complex hidden risks. While code generation allows developers to scale their output tenfold, LLMs trained on historical, imperfect repositories inevitably generate flawed and vulnerable code. Treating an AI assistant strictly as "just another developer" means rigorous security testing, threat modeling, and architecture reviews remain non-negotiable. To preserve the velocity gained from generative tools, security operations must implement automated code fixing alongside code generation, seamlessly identifying and neutralizing vulnerabilities inside the continuous integration pipeline before they impact production. Combating this evolving threat surface demands autonomous cybersecurity platforms rooted in "precision AI." Leveraging AI for secure access, runtime protection, and posture management empowers organizations to parse massive datasets, identify anomalies, and reduce the mean time to remediate incidents from several days to mere minutes. While emerging regulations like the EU AI Act impose aggressive 24-hour breach reporting timelines, integrating these defensive AI tools limits manual operational toil. By automating localized vulnerability patches and triaging threat data, human developers and SOC analysts are kept safely "in the loop" for complex incident response. Removing the friction of repetitive security interventions ultimately allows technical teams to focus on impactful innovation, ensuring security professionals and coders are "smiling again." **Keywords:** generative AI attack surface, automated social engineering, deepfake financial fraud, AI code generation vulnerabilities, automated security patching, LLM threat modeling, autonomous cybersecurity solutions, precision AI security, CI/CD pipeline protection, AI security posture management, SOC team productivity, DevSecOps automation, multi-factor authentication strategies, EU AI Act compliance, cloud native application protection ## Chapters 1. **Emergence of generative AI as a new attack surface** (00:03) — The transition from basic machine learning classification to generative models introduces novel security risks. 1. **Speed, scale, and sophistication of modern cybersecurity threats** (01:29) — AI adoption drastically reduces ransomware creation time while amplifying the reach of attacks like deepfakes. 1. **Enhancing social engineering and phishing with generative AI** (03:46) — Attackers leverage automation and precise natural language to scale complex financial scams and deceptive communication. 1. **Mitigating sophisticated threats beyond traditional attack detection methods** (06:51) — Relying on preventive controls like multi-factor authentication becomes crucial when generative phishing evades standard detection. 1. **Consolidating fragmented security tools with precision AI methodologies** (08:27) — Replacing disconnected security toolchains with integrated posture management future-proofs the enterprise vulnerability lifecycle. 1. **Managing vulnerabilities in auto-generated software development processes** (10:23) — Treating AI-generated components like typical developer contributions ensures rigorous threat modeling and continuous security testing. 1. **Integrating automated vulnerability remediation directly into developer workflows** (13:21) — Utilizing code plugins to automatically fix security flaws empowers engineers to maintain product feature focus. 1. **Navigating international AI regulations and rapid incident reporting mandates** (16:07) — New legislative frameworks enforce rapid incident reporting timelines and drive better systemic preparedness across global enterprises. 1. **Boosting security operations center productivity with intelligent data analysis** (19:50) — Sifting through massive data sets with intelligent anomaly detection accelerates incident remediation while keeping humans informed. ## Related Moments - [Evolving threat landscapes and generative ai attack tools](https://www.wearedevelopers.com/videos/1690-tackling-the-risks-of-ai-with-ai) (from "Tackling the Risks of AI - With AI") - [The necessity of developer intelligence amidst automated attack generation](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) (from "Let’s write an exploit using AI") - [Identifying emerging security vulnerabilities in generative AI agents](https://www.wearedevelopers.com/videos/1383-the-state-of-genai-machine-learning-in-2025) (from "The State of GenAI & Machine Learning in 2025") - [Uncovering the hidden risks of generative AI adoption](https://www.wearedevelopers.com/videos/1744-genai-security-navigating-the-unseen-iceberg) (from "GenAI Security: Navigating the Unseen Iceberg") - [Managing security risks in AI-accelerated development processes](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) (from "Automated Security for the Entire SDLC") - [Defending against vulnerabilities in AI generated code](https://www.wearedevelopers.com/videos/1743-wearedevelopers-live-ai-vs-the-web-ai-in-browsers) (from "WeAreDevelopers LIVE – AI vs the Web & AI in Browsers") ## Related Articles - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [WWC24 Talk - Scott Hanselman - AI: Superhero or Supervillain?](https://www.wearedevelopers.com/magazine/469-wwc24-talk-scott-hanselman-ai-superhero-or-supervillain) - [Transforming Software Development: The Role of AI and Developer Tools](https://www.wearedevelopers.com/magazine/527-transforming-software-development-the-role-of-ai-and-developer-tools) ## Related Jobs - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Senior AI Agent Software Engineer (Go, Python) (m/f/x)](https://www.wearedevelopers.com/jobs/48277-senior-ai-agent-software-engineer-go-python-m-f-x) at **Dynatrace**