Loading…
OWASP 25th Anniversary Virtual Conference (September)
Type: Planning and Design clear filter
Tuesday, September 22
 

10:00am PDT

Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough
Tuesday September 22, 2026 10:00am - 10:55am PDT
The shift toward Software Bill of Materials (SBOM) and its extension, the Artificial Intelligence Bill of Materials (AIBOM), is a fundamental change in how we manage risk, security, and compliance in the modern digital world. As an organization, adopting both of these frameworks doesn't just check a box, it provides a crucial, non-negotiable layer of transparency that is essential for both operational excellence and legal defense.

In short, SBOM gives you a complete, structured inventory of the code and libraries in your software, allowing for fast vulnerability response and license management. AIBOM takes this concept further, providing an inventory of the non-code components of an AI system, the models, training data, and configurations, to manage risks unique to artificial intelligence like bias, data leakage, and adversarial attacks.
Speakers
avatar for Anitha Dakamarri

Anitha Dakamarri

Lead Security Engineer, DFIN
I am Anitha Dakamarri, a seasoned IT professional with over 17 years of experience in the field of information security. My journey began with a Master of Computer Applications from Jawaharlal Technological University, which laid a strong foundation for my career. Over the years... Read More →
Tuesday September 22, 2026 10:00am - 10:55am PDT

11:00am PDT

OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis
Tuesday September 22, 2026 11:00am - 11:55am PDT
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with design.
Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves:

What are we working on?
What can go wrong?
What are we going to do about it?
Did we do a good job?

In order to support that second question in particular, we have created the next version of OWASP Cornucopia (see: https://cornucopia.owasp.org/card/webapp/AZ2/3.0/en).

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional, and formal development processes. It is language, platform, and technology-agnostic.
The formerly titled “Cornucopia — Ecommerce Website Edition” is now “Cornucopia — Website App Edition”. This edition was originally created in August 2012, released as v1.0 in February 2013, and has undergone several minor updates/releases over the following ten to fifteen years. This has been substantially updated in v2.0, in which the most noticeable change was an update of the OWASP ASVS mapping from ASVS v3.0 to v4.0, together with the creation of translations into six languages (EN, ES, FR, NL, NO-NB, and PT-BR) due to the efforts of past and current volunteers.

The new version, available in 10 languages (EN, ES, FR, HI, NL, NO-NB, PT-PT, PT-BR, RU, UK), will include all new cards and text that cover all OWASP ASVS 5.0 requirements and connect them to more than 200 unique common attack patterns (CAPEC). Each of the common attack patterns will have a unique set of ASVS requirements, which means that you never need to stop playing the game! You will always be able to return to the same card to discover new threats and security requirements to consider when building your software. Additionally, we are publishing the OWASP Cornucopia Companion Edition (see: https://cornucopia.owasp.org/edition/companion/AAIA/1.0/en that comes with 6 companion suits (see: https://cornucopia.owasp.org/edition/companion ) covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO). A suit in the companion deck may replace (or be used in addition to) suites in the existing Website Edition so that the players can add a specific focus to their threat modeling: For example, say you are building an LLM application and want to perform threat modeling specifically for LLM. You would then use the OWASP Cornucopia Website Edition and the LLM companion suite as your elected OWASP Cornucopia focus area.

What’s more, it is now possible to create your OWASP Cornucopia Threat Model in OWASP Threat Dragon using their brand new EoP Games diagram (see: https://www.threatdragon.com/
Speakers
avatar for Johan Sydseter

Johan Sydseter

co-leader of OWASP Cornucopia, Johan (Uncle Joe) Sydseter - The guy with the long hair, not the beard
Johan Sydseter is one of the co-leaders of OWASP Cornucopia and the co-creator of the OWASP Cornucopia Mobile App Edition. he is a living AppSec Pokémon, application security engineer, developer, architect and DevOps practitioner. He has 15 years of experience building and designing... Read More →
Tuesday September 22, 2026 11:00am - 11:55am PDT

4:00pm PDT

The Sentinel-Aura Architecture: Orchestrating Agentic AI for Autonomous Endpoint Remediation
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
As infrastructure grows beyond human scale, traditional manual patching is no longer a viable security posture. This session introduces a research-driven framework for Autonomous Infrastructure Healing.

Instead of treating security as a static checklist, we explore a model where the system functions as a self-correcting organism. By wrapping Microsoft Intune and Microsoft Entra with a custom Agentic AI orchestration layer, we can transform Windows 11 endpoints into self-healing assets. I will discuss the methodology of the "Red-to-Green" transition—using Automation and Agentic AI to interpret security telemetry and execute sub-60-second remediations without human intervention. This is a visionary look at how Microsoft Security Copilot and autonomous agents will redefine the future of the regulated workplace.
Speakers
avatar for Harshavardhan Malla

Harshavardhan Malla

Information Systems Security Engineer, Arizona Department of Transportation
Information Systems Security Engineer | Arizona Department of Transportation (ADOT) | Cloud Security & Compliance Automation | 3× Co-Founder (Digitailor)Harshavardhan Malla is an Information Systems Security Engineer at the Arizona Department of Transportation (ADOT), supporting... Read More →
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.