RomHack Camp 2026

Luis Rubiera

CTO, open source believer, and full time challenger of "that's how it's always been done." I'm fascinated by how the past explains the present, and how technology quietly rewrites both. For years I've been trading ideas about SaaS, security, and open source from stages and classrooms, nudging people to rethink how we build and who we build with. I run a cybersecurity company with one foot planted firmly in the future, still convinced AI can be a force for good.


Session

10-04
10:00
40min
When Even AI Writes the CVE
Luis Rubiera

We used to treat every CVE as an alert. Each one meant dropping what we were building, classifying severity, chasing versions, lighting up the dashboard in red. Endless noise. That works when a serious vulnerability is a monthly event. It doesn't anymore. In 2025 the Linux kernel was the single most reported product on the planet, with thousands of CVEs, roughly ten every day, from one project. And its maintainers don't even rank them by severity, so you can't sit back and wait for the "important" ones. Then the AI era poured fuel on the fire: 2026 is on track for 66,000 CVEs, and a single AI model (Claude Mythos) recently surfaced thousands of high severity flaws that remain 99% unpatched. The flood is now machine speed.

When a CVE lands every few minutes, you can't sound the alarm every time. So we stopped. Today patching is just part of the workflow, and we fight AI with AI: automation ingests and rolls out the patches, while AI triages the flood down to what is actually exploitable for each deployment. This talk shows how a small team keeps hundreds of Keycloak clusters and thousands of vulnerabilities under control, everywhere and anytime, without adding a single delay to the product roadmap.

Cybersecurity and Hacking
STAGE 2 (Ghost in the Shellcode)