AI & Product Security: Attack Vectors, Model Risks, and Defensive AI 🔒 Cloud & CI/CD TechSpot Panel
Автор: On The Spot Development
Загружено: 2025-12-08
Просмотров: 53
Описание:
The discussion focuses on how AI is shaping cybersecurity, from new attack paths in LLMs, agents, and RAG pipelines to how AI can improve code security, incident response, and overall defense.
The experts break down tangible risks, emerging threats, and what teams should expect as AI-driven systems become part of everyday engineering.
🎤 𝐏𝐚𝐧𝐞𝐥𝐢𝐬𝐭𝐬:
• Dror Zalman, Product Manager at Orca Security / drorza
• Sergey Pronin, Head of Cybersecurity at Booksy / sergey-pronin
• Alexey Krasnov, Staff Cloud Security Engineer at Capitalcom / alexey-krasnov-6a958173
• Kiryl Surahatau, Head of JS Department at Oxagile / androlein
👇 𝐓𝐢𝐦𝐞𝐬𝐭𝐚𝐦𝐩𝐬:
0:00 – Intro
0:18 – Biggest misconceptions about AI security, trust boundaries, hallucinations, and skill gaps
2:17 – Risks in open-source models and training data
3:19 – Model-tool interaction as a new attack surface
4:34 – AI as an attack vector: prompt injection, RAG and vector DB semantic leakage
6:39 – Using AI for defense: attack-path discovery, defense-in-depth, incident response
9:53 – Multi-agent systems and compromised components
11:53 – MCP security and excessive permissions
14:28 – Identity and least privilege for AI agents
17:20 – Auditability, compliance, and AI SBOM concerns
20:52 – Delegation, daily use of AI, and future workflows
23:43 – Current AI-enhanced security tools in practice
27:01 – Multi-layer review: LLM + classical tooling
29:08 – AI model sprawl vs. user education
31:14 – AI-powered code review inside CI/CD
33:22 – Treating AI agents as “employees”
35:17 – Productivity and cost benefits of AI adoption
38:24 – Model poisoning and compromised packages
41:16 – Guardrails, static analysis, and treating AI as a dependency
42:32 – Closing remarks
👀 𝐎𝐭𝐡𝐞𝐫 𝐭𝐚𝐥𝐤𝐬 𝐟𝐫𝐨𝐦 𝐭𝐡𝐞 𝐂𝐥𝐨𝐮𝐝 & 𝐂𝐈/𝐂𝐃 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐓𝐞𝐜𝐡𝐒𝐩𝐨𝐭:
• 🕵️♂️ Security risks in GitHub Actions (by...
• 🔎 Insider Threats in GitLab, Jenkins & K8s...
🌟 TechSpot events are driven by On The Spot Development.
More about TechSpot: https://onthespotdev.com/techspot
Open positions for engineers in Poland: https://onthespotdev.com/careers
#cloudsecurity #aiagents #cicd #aisecurity #llmsecurity #promptinjection #modelcontextprotocol #cybersecurity
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: