Artificial intelligence is transforming the way security vulnerabilities are discovered and reported. While AI makes it easier than ever to identify potential issues, it also creates a new challenge: a growing number of inaccurate or low-quality AI-generated vulnerability reports that require careful evaluation.
In this live event, Marco Ippolito from the Node.js Security Team shares how AI is impacting modern security workflows and how teams can adapt their processes to separate real security risks from incorrect findings.
Through real-world examples, you will explore common patterns in AI-generated vulnerability reports, understand why domain expertise remains essential for security analysis, and learn how security teams improve their triage processes to handle increasing volumes of reports.
You will gain practical insights into modern Node.js security practices and learn how developers, maintainers, and security teams can respond effectively to the challenges introduced by AI-assisted vulnerability analysis.
Node.js developers who want to understand how AI is changing vulnerability discovery and security analysis.
Security engineers who want to improve their vulnerability triage processes in an AI-driven environment.
Open source maintainers who want to handle increasing numbers of AI-generated security reports more effectively.
evaluate AI-generated vulnerability reports and identify relevant security findings.
distinguish real vulnerabilities from false positives created by AI analysis.
adapt security triage processes for the increasing volume of vulnerability reports.
understand the limitations of AI in security analysis and why expert review remains essential.
Marco Ippolito is a Senior Security Engineer at HeroDevs, active contributor and member of the Node.js Technical Steering Committee. He specializes in Node.js security, JavaScript ecosystems, and open source development. As an international speaker and former Microsoft MVP, he contributes to major Node.js projects and also serves as a delegate in TC39.
Mit der Fullstack Membership greifst du auf alle entwickler.de-Inhalte zu — Live-Events, Tutorials, Kurse und deine Konferenzsessions inklusive.
Bereits Member? Anmelden
Du bist bereits ein Fullstack Member? Dann logge dich auf entwickler.de ein und nimm direkt am Live-Event teil. Zum Event
Kostenloses Live-Event: Java Security im KI-Zeitalter mit Simon Ritter | 28. Juli