Let’s write an exploit using AI

Tuesday
 
26
 
November
2:25 pm
 - 
3:05 pm

Speakers

Julian Totzek-Hallhuber

Julian Totzek-Hallhuber

Manager Solution Architects EMEA/APAC
Veracode

Synopsis

AI is on the rise and will, inevitably, help developers to be more efficient.

But it is not only developers who benefit from these tools; it's hackers too.

AI doesn't care if you are a defender or an attacker. This means bad actors can leverage the amazing capabilities of AI tools to write exploit code – even if they are not full-stack developers or penetration testers. This is concerning and underscores why code security is critical for the safety of society and organisations.

When used responsibly, AI can help solve the greatest obstacle to successful software security programs: the imbalance that exists between the effort developers spend finding flaws and the time to fix them.

In this session, I will show how I used AI to write an exploit for a publicly know vulnerability. I’m not a “real” developer and only coding for fun. AI made it very simple for me to write a full working exploit.

I will also demonstrate the positive side of AI. How AI can help prevent 'bad' code from becoming a bigger issue. Attendees will come away with in-depth information on the security implications of AI-assisted coding.

Acknowledgement of Country

We acknowledge the traditional owners and custodians of country throughout Australia and acknowledge their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the elders past, present and emerging.

Acknowledgement of Country