A private dinner dialog for CISOs and AppSec leaders. No slides. No pitch. Ten seats at one table, and everyone at it shares.
Why now: since June, Washington and the AI labs have started holding models back over what they can do to software, and the open models anyone can download are only months behind.
By invitation only. Chatham House Rule applies.
This series exists because the ground under application security is moving faster than any conference agenda. Each city has taken the conversation somewhere the last one could not. All of it under Chatham House Rule, so what follows is theme, not attribution.
Silicon Valley asked what a finding is actually worth. The room converged on an uncomfortable ratio: the volume of findings is exploding while the number that an attacker could actually use stays small. One dataset discussed put it at 7 of 100. Programs built to triage the other 93 are spending their best people on noise.
New York asked what happens when both sides are armed. Defenders run AI to find issues, then queue them for human triage. Attackers now run AI that finds and weaponizes in a single loop. The triage step your program depends on is a step the adversary no longer takes. The line that stuck: your program is not slow because it is poorly built. It is slow because it is playing the wrong half of a contest that used to be fair.
Charlotte asked who wrote your application in the first place. For most of the room the honest answer was nobody in the building. Applications are assembled from vendor platforms, SaaS, open source, and now generated code. When the code is not yours, code review is not available to you. The only security artifact that crosses a company boundary is proof that an attack path works, or proof that it does not.
Since then, the attacker side has moved faster than anyone at the table expected. Austin picks up there.
A model found more than 10,000 high or critical flaws, then was held back from general release because its maker says no one has safeguards strong enough to prevent misuse. What changes when exploit discovery is autonomous?
A June executive order gives the government up to 30 days with frontier models before release, then routes them to trusted partners first. OpenAI has already slowed launches over cyber risk. Who gets these models first, and are your defenders on that list?
The strongest open-weight model is about four months behind the frontier on cyber tasks. In testing, its safeguards were bypassed most of the time, and every time once stripped. Self-hosted, it runs with no logs and no account to suspend. How do you defend against a capability that cannot be revoked?
An attacker running these models works around the clock. Most defense programs still test once a year, while APIs and AI-generated code change daily. If proof of exploitability matters more than a pile of findings, what does it take to produce that proof continuously, and who owns it when no single team owns the attack surface?
There is no keynote and no vendor presentation. A moderated roundtable where the agenda above is a starting point and the room decides where it goes. Ten voices, every one of them heard. What is said stays in the room; what is learned leaves with you.
Leads APIsec with a focus on proactive application security. Twenty years in security leadership at McAfee, Intel and Thales, having been part of creating the DLP market, Secure Communications market, and Machine Learning on Big Data market. Faizel has facilitated every prior session in this series.
The first three cities filled by referral before invitations finished going out. Share your details to request a seat, and tell us: what would you do differently if your adversary had Mythos today?