Loading…
Friday November 6, 2026 10:30am - 11:15am PST
The finding that shifted our thinking on chain analysis was a session-handling weakness rated medium-severity in isolation. Once we traced the chain — an API leaking session identifiers without an access-control check, feeding a deterministic password derivation function — it was a full account compromise. Same code. Two severity tiers apart. Chain context doesn’t refine a finding; it changes what the finding actually is.

We ran a nine-step agentic harness across twenty large production applications at a financial-services organization: systems with years of prior pentest coverage, active bug-bounty programs, and conventional SAST already in CI. The harness surfaced over 400 verified vulnerabilities that the SAST tool did not catch — concentrated in categories pattern-based tools structurally cannot reach: absent authentication gates, authorization logic that exists but never enforces, secrets in configuration files outside the source scan boundary, unsigned token forgery, and multi-step attack chains.

Fewer than one in six findings overlapped between the two tools. SAST found roughly 90 true positives the harness missed — deep DAO-layer SQL injection, JSP template XSS — where its exhaustive per-call-site enumeration beat our coverage. The two tools are additive, not redundant. We nearly didn’t get there: the first run’s precision was too low to hand to any developer. Fixing it required structural changes — adversarial verification, deterministic filtering — not prompt tuning. That near-miss shaped everything that followed. This shift changed the primary metric we track — from how many issues are found to how quickly they are validated and closed in production. We now frame this as Mean Time to Adapt (MTTA) — the time from an initial signal to a validated fix in production.

The architecture is in enough detail to reproduce. The failure modes are specific: hallucinations that survived single-pass verification, chain severity that failed until it was made explicit in pipeline design rather than left to agent judgment.
Speakers
avatar for Venkata Suresh Sanga

Venkata Suresh Sanga

Sr Cybersecurity Engineer, Visa
Venkata Suresh, Sanga is a Sr Cybersecurity Engineer at Visa, where he runs the SAST, SCA, and DAST detection portfolio. His current focus is an agentic harness that cuts the noise those tools produce and is measured by one number: Mean Time to Adapt.

  linkedin.com/in/venkatasu... Read More →
avatar for Milind Daftari

Milind Daftari

Cybersecurity Engineer, Visa
Milind Daftari is a Cybersecurity Engineer at Visa with a Masters in Cybersecurity from New York University who thrives on turning security from a blocker into an enabler. He’s built and owned security from the ground up—shaping secure architectures, automating vulnerability scans... Read More →
avatar for Yuliana Martirosyan

Yuliana Martirosyan

Visa
Do the good by doing right
  
avatar for Daniel Fernandez Coviella

Daniel Fernandez Coviella

Senior Cybersecurity Engineer, Visa
Daniel Fernandez is a Senior Application Security Engineer at Visa, where he focuses on application security, AI security, and secure software engineering at enterprise scale. His work includes integrating AI into the secure development lifecycle, building developer security tooling... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Seacliff AB (Bay Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link