About This Session
The time between a vulnerability being found and being exploited has gone negative - see X, LinkedIn, Hacker News, etc. AI models now surface flaws faster than maintainers can patch them. The industry's answer (some at least) is coordinated, pre-disclosure defense: pool findings, patch under embargo, push mitigations before the bug is public. It works. But it works for the people inside the coalition — the banks, hyperscalers, the vendors who can patch on an attacker's timeline, commercially. Most of us aren't in that room. We're building, scaling, pivoting, and breaking things at machine speed. Our priorities are different, but security affects us, no less than the big guys. I call it "the middle: small security teams, heavy open-source dependencies, no seat at the embargo table" aka most of us. We inherit the same risk on the public side of disclosure — and we're not idle about it. This talk is about what coordination looks like from down here. Not a poorer copy of the embargo club — an open response commons: when a disclosure drops, a mitigation gets generated once and propagates across the enforcement points teams already run, at machine speed, instead of every shop reinventing it alone. I'll show an early, working v0 built with security partners who aren't limited to being conventional, and make the case for what we build next. I don't have all the answers, I'm just a guy trying to solve some problems. This is an invitation to contribute.
Topics
- AI Models
- Cloud Security
- DevOps
- DevSecOps
- Infrastructure
- Open Source
- OWASP
- Secure Coding
- Security
- Threat Modelling