Loading…
OWASP 25th Anniversary Virtual Conference (September)
Audience: All clear filter
Tuesday, September 22
 

9:00am PDT

Opening Remarks and Keynote
Tuesday September 22, 2026 9:00am - 10:00am PDT

Tuesday September 22, 2026 9:00am - 10:00am PDT
  Keynote
  • Audience All
  • about <br>

10:00am PDT

Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough
Tuesday September 22, 2026 10:00am - 10:45am PDT
The shift toward Software Bill of Materials (SBOM) and its extension, the Artificial Intelligence Bill of Materials (AIBOM), is a fundamental change in how we manage risk, security, and compliance in the modern digital world. As an organization, adopting both of these frameworks doesn't just check a box, it provides a crucial, non-negotiable layer of transparency that is essential for both operational excellence and legal defense.

In short, SBOM gives you a complete, structured inventory of the code and libraries in your software, allowing for fast vulnerability response and license management. AIBOM takes this concept further, providing an inventory of the non-code components of an AI system, the models, training data, and configurations, to manage risks unique to artificial intelligence like bias, data leakage, and adversarial attacks.
Speakers
avatar for Anitha Dakamarri

Anitha Dakamarri

Lead Security Engineer, DFIN
I am Anitha Dakamarri, a seasoned IT professional with over 17 years of experience in the field of information security. My journey began with a Master of Computer Applications from Jawaharlal Technological University, which laid a strong foundation for my career. Over the years... Read More →
Tuesday September 22, 2026 10:00am - 10:45am PDT

10:45am PDT

Guardrails First: Building AI Agents That Won’t Leak Your Secrets
Tuesday September 22, 2026 10:45am - 11:30am PDT
As generative and agentic AI rapidly enters security workflows, practitioners face a difficult choice: leverage AI to enhance efficiency, or risk exposing sensitive data to systems that weren’t designed with security in mind. For me, as a security engineer and pentester, this challenge is especially important - pentesting often involve confidential data, proprietary code, and high-impact vulnerabilities that cannot leave controlled boundaries.

In this talk, I would like to share my own practical lessons learned from designing and deploying AI agents specifically for security testing use cases. When building your own agent for security testing purposes, you often face a lot of issues, related to privacy, data protection, efficiency and cost-optimization. In my talk we’ll explore how to build AI agents with strong guardrails from the ground up: isolating execution environments, minimizing data exposure, utilizing obfuscation practices without a negative impact on performance, implementing secure prompt handling, and enforcing strict boundaries between sensitive inputs and model interactions. I’ll also cover architectural patterns that enable safe augmentation of pentesting workflows without introducing new attack surfaces or compliance risks and what is more important, do not cost you an arm and a leg.

Attendees will gain insights from practical experience into how to safely integrate AI into daily workflows, whether they are building internal tools, experimenting with agentic systems, or securing AI-enabled applications. This session is designed for security professionals, developers, DevOps engineers and everyone who want to utilize the power of AI without turning it into a new source of security risks.

The goal is simple: build AI agents that work for you, not against you.
Speakers
avatar for Ihor Sasovets

Ihor Sasovets

Lead Security Engineer, TechMagic
I am a Lead Security Engineer at TechMagic with previous experience in test automation, security testing automation, a contributor of OWASP API Top 10 (2019), speaker at various community meetups. I have more than 4 years of experience with AWS.

I am passionate about cloud securit... Read More →
Tuesday September 22, 2026 10:45am - 11:30am PDT

11:30am PDT

How a Clean Security Audit Became a Breach Notification Six Months Later
Tuesday September 22, 2026 11:30am - 12:15pm PDT
Pre-deployment security reviews cover what you configured. They do not cover what your environment looks like six months later after multiple teams have touched it, new services have been granted access, and permissions have accumulated in ways nobody explicitly decided. Most organizations treat a clean security review as a checkpoint rather than a snapshot, and that distinction matters a great deal when something goes wrong.

This session is built around a real incident. A cloud environment passed its security review. IAM configurations were reasonable at the time of review. What the review did not cover was any mechanism to detect when those configurations drifted over time through legitimate activity: new role bindings added by different teams for different features, each individually justifiable, collectively dangerous. Six months later that drift became the entry point for a breach.

The talk walks through the full incident arc: what the environment looked like before and after, what the attack activity looked like in audit logs and why existing alerts did not fire, and what the architecture looked like after being rebuilt with configuration drift detection as a first-class concern. All tooling demonstrated is native to the cloud platform, no third-party products. Attendees leave with the specific log queries, alerting configurations, and policy controls that would have caught this incident before it became one.
Speakers
avatar for Advait Patel

Advait Patel

Senior Site Reliability Engineer, Broadcom

Advait Patel is a Senior Site Reliability Engineer at Broadcom and the creator of DockSec, an open-source, AI-powered Docker security analyzer. With over 8+ years of experience in cloud-native security, DevSecOps, and secure software supply chains, he is passionate about building... Read More →
Tuesday September 22, 2026 11:30am - 12:15pm PDT
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.