BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The API Made Me Do It - Do Bad APIs Lead AI to Gener
 ate\n   Vulnerable Code?\n   Tags: Intermediate | AppSec Village | Creator
  Talk/Panel\n   When: Saturday\, Aug 8\, 16:10 - 16:40 PDT\n   Where: LVCC
 W Level 1 Hall 2 604 (Appsec Village) Main Stage - [1]Map\n\n   Descriptio
 n:\n\n   We blame the bot when AI-generated code is vulnerable\, but what 
 if it\n   is just using the dangerous APIs we left on the table?\n\n   Thi
 s talk tests whether API design can steer AI coding agents toward\n   safe
 r code. The same agent builds the same Java/Spring task app twice:\n   onc
 e in a normal environment\, and once in a constrained one with\n   secure-
 by-default scaffolding\, deny-by-default settings\, safer\n   abstractions
 \, and bans on risky APIs.\n\n   The app includes authentication\, authori
 zation\, task ownership\, file\n   upload\, SSRF-prone link previews\, and
  simulated paid features. The\n   prompts describe product behavior\, not 
 security advice\, so the\n   comparison focuses on environment design rath
 er than better prompting.\n\n   Both projects are analyzed with CodeQL and
  manual review to compare\n   SAST findings\, authorization flaws\, unsafe
  file handling\, SSRF risks\,\n   abstraction bypasses\, and cases where w
 rappers hide risk instead of\n   reducing it.\n\n   SpeakerBio:  Yariv Tal
 \n\n   Yariv Tal is a senior developer\, security researcher\, and cofound
 er of\n   Secure From Scratch\, a venture dedicated to teaching developers
  secure\n   coding from the very first line of code.\n\n   A summa cum lau
 de graduate of the Technion\, Yariv brings four decades\n   of programming
  experience and years of university lecturing and\n   bootcamp mentoring t
 o the field of application security.\n\n   He lectures on secure coding in
  academia and the private sector\, leads\n   the OWASP-untrust project\, a
 nd researches the intersection of AI and\n   application security\, with a
  focus on secure code generation\, LLM\n   evaluation\, and secure-by-cons
 truction development.\n\n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20260808T234000Z
DTSTART:20260808T231000Z
LOCATION:AppSec Village - LVCCW Level 1 Hall 2 604 (Appsec Village) Main St
 age
SUMMARY:The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable 
 Code?
END:VEVENT
END:VCALENDAR
