Security Native Europe

One year after Mythos - the impacts on security

Capacity: 60
in-person
Event date
Nov 26, 26
06:00 PM - 10:07 PM CET
Location
Puzzle ITC, Hönggerstrasse 65
About this event

What did the AIs really change in our field?

#securitynative Europe premiers in Zurich - hosted by Puzzle ITC

4 short talks and a moderated panel with all speakers will distill actionable consequences:

  • Where does AI concretely help
  • What are the most misguided AI usecases and what to avoid
  • What dangers are concretely new - and how to defend against them

Agenda

  • 18:00 Doors open
  • 18:30 Introduction
  • 18:45 Talks:

1. Daniel Borkmann : Defending at Machine Speed: Current State and Outlook of eBPF for Security

In the era of "Mythos" and equivalent advanced LLMs, the speed of vulnerability discovery and exploitation has fundamentally changed. Security fixes and attack-surface hardening must land on production systems "yesterday". Yet, our infrastructure - from Kubernetes fleets, VMs, to embedded devices - remains bottlenecked by long patch-and-reboot cycles.

eBPF is the natural vehicle for on-the-fly live mitigations, but how capable is the foundation for building such mitigations? This talk explores the current state of eBPF for security, focusing heavily on BPF LSM, hardening capabilities, live patching, and provides an outlook for ongoing and future kernel work in this area.

2. Mark Cheret: Your Agent Has Org Admin
Least privilege was policy long before it was enforced practice. I spent years arguing to close that gap. Being right about scope doesn't move a roadmap. Then people holding privileged access started running coding agents on their machines daily. One misstep could put us in the newspaper, not just the security incident tracker. Suddenly, it mattered to everyone with org admin privileges. So we cut it. And cleaned up a lot more standing privileges while we were at it. AI made the cost of not securing it unpayable. After years, that turned out to be the only argument that ever worked.

3. Benjamin Koltermann: Why your Agent is better at solving CTF challenges then you will ever be

Capture the Flag is the supreme discipline of hacking and cyber security. With the rapid evolution of AI and the release of increasingly capable security models, this discipline is now being infiltrated by AI agents. But why are these agents so good at solving CTF challenges, even when zero-day exploits are involved? In this talk, we show how AI agents actually approach and solve challenges, and what makes them so powerful in CTF competitions.

4. Talk (we re still confirming their details)

20:15-20:40 “Panel Discussion"

20:45-22:00 Networking – Discussion with experts and peers, share your experiences, and connect with the #securitynative community.

How to join?

Bring your questions, your experience, and your curiosity.

This meetup is sponsored by the CNCF and hosted by Puzzle.ch. It is in-person, not-recorded and the CNCF code-of-conduct applies.

To avoid disappointments and to politely acknowledge the catering costs of our hosts and sponsors, we will charge CHF 10 for any persons, who RSVP but do not actually attend. By signing-up, you accept this no-show-policy. Seats are limited to 60 and there is a waitlist.

Organizers