Breaking
Tech NewsDeveloping Story

CodeSecCon 2026: DevSecOps Under the AI Lens

SecurityWeek's virtual CodeSecCon brings 1,500+ devs and security pros together to tackle AI-era application security today.

··3 hours ago·4 min read
people sitting on chairs inside stadium
Photo by Product School on Unsplash

More than 1,500 registered attendees are gathering today for CodeSecCon, SecurityWeek's virtual event aimed at developers and cybersecurity professionals. The program is built around a single question: how do you secure applications when AI is writing more of the code?

The agenda runs through the morning and afternoon with sessions covering secure coding, cloud security, and a heavy emphasis on AI-assisted development. The event is designed to address the most pressing challenges in software security, according to the organizers.

Why Security Teams Are Tuning In

The event's marketing materials highlight three core goals for attendees: developing secure applications, reducing software vulnerabilities, and enhancing collaboration between security and development teams to foster a DevSecOps culture. There is also a specific focus on how to safely integrate AI into applications and reduce the risk of sensitive data exposure.

The opening keynote, titled “From Security Bottleneck to Revenue Growth Engine,” is being delivered by Joseph Frisk, CISO at Dine Brands, and Gareth Davies, Chief Product Officer at Auth0. The session's framing suggests a shift in how security leaders position their work—not as a cost center, but as a value driver.

Agentic Development Under Scrutiny

A recurring theme is the security gap in agentic development—where AI agents write and deploy code autonomously. Mike McGuire, Product Marketing Manager at Wiz, is scheduled to present “Closing the Security Gap in Agentic Development” at 11:30 AM ET.

Later in the day, Khushboo Bhatia, AI & Data Solution Architect at Google, will cover “Securing Agent Runtimes, Preventing Jailbreaks, and Stopping Over-Permissioned Code.” The session addresses a specific set of risks: AI agents that can be tricked into malicious actions or given too much access.

Hardening WordPress With Real Lessons

At 12:40 PM ET, Haim Michael, a Software Developer, will present “Hardening WordPress: Practical Security Lessons from Real Incidents.” The session promises to go beyond generic advice and look at actual cases where WordPress sites were compromised.

The talk is a nod to WordPress's ubiquity as a target, and the practical lessons are likely to resonate with the many developers who manage WordPress-based applications.

Cloud Security Takes Center Stage

Christina DePinto, Senior Product Marketing Manager at Datadog, will speak at 12:00 PM ET on “The Cloud-Powered Enterprise: Securing Your Cloud.” The session focuses on practical steps to secure cloud-native environments, a topic of universal relevance as more workloads move to the cloud.

At 3:05 PM ET, Jitendra Singh, Senior Software Engineer at Microsoft, will present “Beyond Encryption: Protecting Sensitive Telemetry in Cloud-Native Applications.” The session implies that encryption alone is not sufficient; telemetry data—which can reveal application secrets—requires additional safeguards.

AI Gateways and Control Planes

Chris Bao, Senior Software Engineer at Schlumberger, will speak at 1:15 PM ET on “AI Gateway as a Security Control Plane: Content, Access, and Operational Controls.” The session explores how to control what AI models can access and produce, which becomes critical as AI models are integrated into more workflows.

The talk is one of several that address the challenge of governing AI interactions, including content filtering, access controls, and operational monitoring.

Enforcing Least Privilege on Autonomous Developers

Karan Bansal, Global Head of AI and Security Innovation at ArmorCode, will present at 2:15 PM ET on “Hardening AI Coding Agents with Hooks: Enforcing Least Privilege on Autonomous Developers.” The session explores how to constrain AI coding agents so they operate with minimal permissions, reducing the blast radius of a compromised agent.

This is a practical approach to a growing problem: AI agents that have too much access can cause significant damage if they are exploited or make mistakes.

A Blueprint for Human-AI Collaboration

Ravikumar Dwivedi, Senior Vice President of Software Engineering at JPMorgan Chase, will present at 2:45 PM ET on “Securing AI-Assisted Development: A Three-Body Model for Human-AI Code Collaboration.” The session proposes a model to define clear roles for humans and AI in the development process.

This could serve as a blueprint for how organizations can safely integrate AI into their development pipelines while maintaining human oversight.

Key Numbers From the Agenda

  • 1,500+ registered attendees
  • 9 scheduled sessions
  • 8 named speakers

Why It Matters for Your Pipeline

The breadth of topics—from WordPress hardening to AI agent security—highlights a core tension: the traditional separation between development and security is no longer viable. As AI becomes a coding partner, the need for collaboration and shared responsibility intensifies.

For attendees, the practical takeaways—such as least privilege for AI agents, secure cloud configurations, and robust telemetry protection—could directly impact how they build and secure applications. But the bigger takeaway is that security must be woven into every stage of development, not bolted on at the end.

This event signals that the conversation is shifting from “whether” to “how” to integrate security into every stage of development. The challenge for organizations will be translating these insights into everyday practice, ensuring that the lessons learned today become the standard for tomorrow’s software.

#codeseccon#devsecops#ai-security#application-security#virtual-event

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories