

AI coding agents need real access to code and credentials to work, and attackers already exploit it: developers using AI assistants leak secrets at roughly twice the baseline rate. Join this session for concrete ways to grant, track, and contain agent access, beyond writing an AI policy.
Online
Online
AI coding agents need real access to code and credentials to work, and attackers already exploit it: developers using AI assistants leak secrets at roughly twice the baseline rate. Join this session for concrete ways to grant, track, and contain agent access, beyond writing an AI policy.
AI coding agents need real access to code and credentials to work, and attackers already exploit it: developers using AI assistants leak secrets at roughly twice the baseline rate. Join this session for concrete ways to grant, track, and contain agent access, beyond writing an AI policy.
AI deployment makes secrets management harder, not easier. Agents need real access to code, test, and validate, so you can't design the secrets problem away. You can only decide how that access is granted, tracked, and contained.
Right now, most organizations are failing that test: developers using AI coding assistants leak secrets at roughly twice the baseline rate, AI service credential leaks grew 81% year over year, and 24,008 unique secrets were found in public MCP configs alone (State of Secrets Sprawl 2026). Attacks like s1ngularity and the Shai-Hulud variants already turn AI CLIs into their own exfiltration and propagation mechanism.
This session is for AppSec and DevSecOps engineers who need answers more concrete than "write an AI policy", and want to learn how to protect their workflows from rogue agents.