Everyone is diving headfirst into the AI pool. The problem is they're diving into the shallow end. LLMs are being packed into every nook and crannie, mostly places nobody wanted it or asked for it. I'm going to be taking a baseball bat to LLMs - their hallucinatory nature and the extra instructions we're saddled with we don't get to see.. I'll be showing logs of how they literally talk themselves into lying to you. It's bad. Bring a helmet. Prompt engineering has become harness engineering, and now its "memory and context engineering". Openclaw and now codex are storing local files and 'memories' to try and handle the 'context window problem'. Moltbook has 3 million 'agents'. Openclaw is being used as a c2 now. TeamPCP is infecting every npm package they can with backdoors - weekly at this point! Just in 2026 alone we have more than tripled the number of supply chain bugs in tooling used in the LLM landscape The attack surface is growing so rapidly we can barely keep track of it. This talk will explore all this new attack surface, and cover some of the things you can do about it, and how to avoid the landmines and pitfalls when using LLMs.
Dan Tentler
Dan is the founder of Phobos Group, a boutique information security consulting and architecture firm, specializing in assessment work, security architecture, remediation efforts, advisory and simulation services. Dan's been at this a long time. Come talk to him about Phobos Airlock!
Security Fest is an inspiring and unique IT security conference held in Gothenburg, Sweden. The event is an excellent opportunity to learn more about IT security, and a great way to connect with both the renowned international speakers, and the other attendees.
Contrairement à ce que certains titres racoleurs laissent entendre, Signal n’est pas en cause ici.
Le problème vient bien de iOS. Lorsque les aperçus de notifications sont activés (et ils le sont par défaut), le contenu des messages reçus est stocké en clair dans une base de données locale du système iOS, sur ton téléphone quoi.
Oui : en clair. Pour une marque qui met en avant le côté respect de la vie privée de ses utilisateurices, c’est quand même fort de kawa.
Ces données sont enregistrées dans une base SQLite interne liée aux notifications. Et surtout, elles restent stockées même si
After decades of gluing together software from a random set of libraries and frameworks, industry wide attacks on the software supply chain have proven this approach is unsustainable, and it's time to shift our thinking on how we write and ship software. In this session we will explore the various tools used to secure the software supply chain, and through a collection of live demos, learn how to put them to use in the real world.
Kelsey Hightower
Google, Inc.
As a curious and motivated self-learner, I gained an interest in computing at a young age, and started my IT career by opening a small consulting shop 20 years ago. From those beginnings my career progressed quickly, eventually passing through the halls of Google, Puppet Labs, New Relic and CoreOS. I am a system administrator by trade, a programmer by necessity, but a problem-solver at heart. With a passion for helping others, many successful speaking and teaching engagements under my belt, and a proven track record of getting things done and enabling others, I hope to solve the many problems facing IT culture by equipping people with the mental and computational software they need to succeed in the competitive world of technology.
Free, fast, and offline PDF toolkit for professionals. Edit, convert, and process PDFs entirely in your browser with no data uploads. 100% client-side processing.
The professional PDF toolkit that runs entirely in your browser. Powerful WASM engine, no server uploads, simply secure.
Todo : il y a des bonnes citations à relever