All Deep Dives For Infosec Conference Talks Covering Secure Software Development. Talks analyzed in full.
Learn how Google's Workspace security team built a defense-in-depth architecture against indirect prompt injection and rogue agent actions in production GenAI systems.
Learn how to build a Cedar-based policy harness that hooks into Gemini CLI, Claude Code, and Cursor to enforce ABAC rules, track PII taint, and block AI agent data exfiltration.
Learn how NVIDIAs Project Marinade uses LLM coding agents to inject realistic, tunable vulnerabilities into real codebases - giving you ground-truth benchmarks to evaluate your security tools.
Discover how 37 AI-assisted IDE vulnerabilities across 15+ vendors enable zero-click RCE, prompt injection chains, and silent config poisoning — and how to test your tools.
Discover how LLMs now autonomously find and exploit zero-day vulnerabilities in the Linux kernel and Ghost CMS — and what the AI capability curve means for defenders right now.
Learn how to architect a unified Personal AI Infrastructure (PAI) stack with Council multi-agent debate, the PAI algorithm, and Arbo pipelines to amplify your security engineering practice.
Learn how OpenAI engineers built LLM-powered security reviewers, living threat models, and a daily dependency scanner using ~40 lines of GitHub Actions YAML and checked-in Markdown files.
Learn how Stripe built and deployed two production AI security agents with multi-agent architecture, LLM-as-judge eval pipelines, and phased rollout.
Learn how Adobe built a RAG-powered security guidance platform delivering org-specific recommendations across Jira, Slack, and IDE at scale.
Discover how Google's Big Sleep and Code Mender use agentic AI to find and patch deep memory safety bugs with zero false positives.
Learn how malicious VS Code extensions bypass Microsoft's safeguards to steal credentials and execute code on developer machines — and the only defense that actually works.
Learn to assess AI code generation security risks—from package hallucination to IP liability—and apply governance controls that protect your SDLC.
Learn why server-side HTML sanitization is structurally broken and how client-side tools like DOMPurify eliminate parser differential XSS bypasses.