2026-10-02 –, STAGE 2 (Ghost in the Shellcode) Language: English
Sometimes, the perfectly engineered solution isn’t what you need. We discuss how, at the beginning of 2026, we moved quickly to build a review bot that helped stem the flow of vulnerabilities entering the codebase in the era of vibe coding. We’ll cover the ROI, costs, and practical challenges involved, along with lessons learned about model choice and how reusing existing harnesses helped us move faster.
Presented at AI for Security event @ DEFCON34.
Andrea Cappa (zi0Black) is Security Lead at Aptos Labs, where he oversees all things security. A former penetration tester at Shielder, he now spends his time exploring how AI can be applied to security in real-world environments, as well as the human factors behind security incidents and system failures.