Loading…
Audience: All clear filter
Thursday, November 5
 

11:30am PST

Cage the Confused Deputy: Infrastructure-Layer Defense for Voice AI Agents
Thursday November 5, 2026 11:30am - 12:15pm PST
Deputies, like agentic AI models, do things on your behalf. A confused deputy does more than it should on your behalf. How do you unconfuse an inherently confused deputy? By telling it what it can and cannot do? But what if it gets confused, again?

Current LLM technology is not capable of being completely immune to prompt injection. It is going to happen. This means the security boundaries for voice agents cannot live solely inside the model's instructions. They have to live in the infrastructure around them. The right design assumes the model will be compromised and ensures that when it is, nothing irreversible happens.

This talk will discuss several of the defense-in-depth elements needed to create and deploy secure voice-based AI-powered agents. These elements will include defenses against transcription manipulation, agent goal drift, tool-abuse, data exfiltration through retrieval, and system-prompt extraction. Each control's effectiveness will be measured by: is it still effective even if the language model does exactly what the attacker asked?

You'll leave with a prioritized, vendor-neutral set of controls you can implement now. You will also gain a better understanding of the necessary defense-in-depth elements when deploying any type of agent. And finally, you'll walk away with a single phrase you can apply to every AI system you're responsible for, voice or not: "would this survive a fully compromised LLM?"
Speakers
avatar for Brian Cardinale

Brian Cardinale

Principal Security Researcher, SecureCoders
Brian Cardinale is the Principal Security Researcher at SecureCoders. He holds a CISSP and has spent his career breaking things that aren't supposed to break. Brian built VoiceGoat, the first open-source vulnerable voice AI agent, and leads RedCaller's research into adversarial testing... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)
 
Friday, November 6
 

10:30am PST

Poisoning the Pipeline: Runner Cache Manipulation and OIDC Token Forgery
Friday November 6, 2026 10:30am - 11:15am PST
The modern application security boundary has shifted from the network edge directly into the software delivery pipeline. As organizations embrace cryptographic provenance and OpenID Connect (OIDC) identity federation to eliminate static cloud secrets, attackers have adapted. By exploiting weak isolation boundaries in shared CI/CD runner caches, threat actors can now extract OIDC tokens from execution memory, compromise cloud environments, and inject malicious code that carries valid supply-chain provenance signatures.

In this session, we will break down the mechanics of an advanced post-exploitation pipeline attack. We will move past generic supply-chain advice to look at how ephemeral runner states can be weaponized against cloud infrastructures. Attendees will walk away with an architectural blueprint for securing federated identities in CI/CD and an open-source audit script to evaluate their own pipeline runner configuration risks.
Speakers
avatar for Sneha Rangari

Sneha Rangari

Security Architect, Visa
I am a Cybersecurity Professional with over 7 years of experience in Security Engineering, Security Architecture, Gen AI/ML in security, Third party Vendor applications, Cloud applications and Technology Risk Management. I am CISSP and GMLE certified and currently working with Vi... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

CRA will be Cloud-Scale Engineering Change
Friday November 6, 2026 10:30am - 11:15am PST
 The CRA is coming, and those who want to sell products in Europe will have to change their engineering processes and documentation in dramatic ways. This talk will introduce the CRA, walk through the requirements, the deadlines and the latest guidance documents from the EU.
Speakers
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom C (Street Level)

10:30am PST

From IC to Leader: A Field Guide to Building High-Performing Security Teams
Friday November 6, 2026 10:30am - 11:15am PST
Most security leaders are exceptional technologists, but building and managing a high-performing security team requires an entirely different skill set - one that is rarely taught and almost never documented. This talk closes that gap.

Drawing on 20+ years spanning Big 4 consulting, multiple security org builds from scratch, and security leadership roles across fintech, banking, and SaaS, this expanded session delivers a comprehensive, practitioner-tested playbook for security team leadership.

Attendees leave with actionable frameworks across the full leadership lifecycle: crafting job descriptions that attract elite talent, structured onboarding plans that accelerate time-to-contribution, Agile practices purpose-built for security teams, performance management grounded in four concrete pillars, a live case study walking through how these frameworks interact in practice, and managing up to executives with clarity and confidence.

Beyond the operational mechanics, the talk addresses the human dimensions of leadership that often go unspoken: building psychological safety, navigating conflict, developing a culture of continuous learning, and supporting team well-being to prevent burnout, a persistent challenge in a high-pressure field.

Whether you are a first-time security manager, a seasoned CISO, or a practitioner preparing to lead, this session delivers real-world guidance, not theory. Every framework presented has been used in production at companies ranging from 10-person startups to public companies. Come prepared to take notes, the slides include reusable templates you can apply to your team on Monday.
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Bayview B (Bay Level)

11:30am PST

The Hidden Effort Curve of Remediation: 15,000 Fixes, 500 Projects, 9 Languages
Friday November 6, 2026 11:30am - 12:15pm PST
Every week brings another headline about a new way to find vulnerabilities in open-source and other code. The much-talked-about “Vulnpocalypse” is coming. But the bottleneck was never finding vulnerabilities, it is fixing them. We wanted to know how much effort this will take.

Every security team triages its backlog the same way: sort by CVSS, fix the criticals first. That ranking quietly assumes severity tells you how much work a fix will be. We tested that assumption against data and found it not to be true!!

Using AI-assisted analysis, we measured the remediation effort for 1,127 fixed vulnerabilities across 20 open-source projects: Firefox, Django, PostgreSQL, Keycloak, Tomcat and others that span nine languages. For each one we pulled the actual fix commits, scored the change on a three-part difficulty rubric, and sorted it into Low, Medium, High, or Extra High effort.
This talk walks through the data, shows where severity-first triage misjudges the work, and gives you a class-based way to estimate effort you can try on your own findings immediately. By November the dataset will cover 500+ projects and 15,000+ remediations. Given the timing, we will include data on vulnerabilities surfaced by Mythos-class models and techniques and whether that newer class of findings is harder or easier to remediate.

This is a data-heavy talk. If you are a data geek, you’ll enjoy it.
Speakers
avatar for Michael Cartsonis

Michael Cartsonis

Co-Founder, AppSecAI

Michael Cartsonis is a co-founder of AppSecAI . OWASP OASIS project and co-author of Two Cycles, One Codebase: A New Operating Model for Application Security.

At AppSecAI, Michael leads product strategy for the industry's first AI-powered Fix Automation system that generates valid... Read More →
avatar for Bruce Fram

Bruce Fram

CEO, AppSecAI

Bruce Fram is the CEO of AppSecAI, his and was a six-time venture-backed CEO before including being the CEO of Contrast Security. He started as a hands-on coder, spent two decades running companies instead of writing code, and credits GenAI with handing the ability to answer complex... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom B (Street Level)

2:15pm PST

From Consuming to Contributing: How We Built the Space That Was Missing
Friday November 6, 2026 2:15pm - 3:00pm PST
Many of us naturally drift from consuming OWASP resources to contributing to them. At some point you stop just reading the Top 10 and start showing up at a chapter, submitting a pull request, or volunteering at a conference. But what often gets lost is the "together" part. The shared strategy, the mutual encouragement, a place where experienced contributors can mentor others and people new to contributing can find their footing without having to figure it out alone.

It started when two of us ran into each other at the Boston Application Security Conference. Same organization, same department, had no idea the other was there. That conversation grew into three people, then a cross-regional group, and eventually an initiative with executive sponsorship built around a simple question: what if there was a structured space where people at all levels of OWASP engagement could come together, share what they know, coordinate where to show up, and help each other go deeper?

That is what we built. A space where seasoned contributors have a home for their work and a way to pass it on, and where people curious about OWASP but not sure where to start can learn, get mentored, and take their first real steps. Contribution gets tracked, progress gets shared, and the work gets recognized internally in ways it never was before.

In this talk we share our journey, what the initiative looks like in practice, what we have achieved together so far, and what you can take back to your own organization.
Speakers
avatar for Saquib Saifee

Saquib Saifee

AI Security Engineer, IBM
Saquib Saifee is an AI Security Engineer at IBM working at the intersection of AI security, software supply chain security, and offensive security. He contributes to the OWASP GenAI Security Project on securely using and building MCP servers, participates in the Linux Foundation AI... Read More →
avatar for Caroline Lee

Caroline Lee

Secuirty Engineer, IBM
Caroline is based out of Boston, Massachusetts, and works as a Security Engineer at IBM in CISO Remediation. She holds a Masters in Computer Science with a Specialization in Cybersecurity.
Previously, she has worked on CICD, Application Security, and Cloud Security initiatives in... Read More →
avatar for Gaurang Deshpande

Gaurang Deshpande

Software Developer, Cyber Defense, IBM
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Bayview B (Bay Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.