Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Thursday September 17, 2026 12:30 - 12:55 CEST
AI is accelerating vulnerability discovery, finding more security issues than any team can fix by hand. The obvious next step is letting AI fix them too, but pushing automated changes into production is difficult, and the trust bar is super high.

Over the past year, we built and shipped two autonomous remediation agents raising PRs against hundreds of production repositories: one for SAST findings in first-party code, and one for SCA findings in third-party libraries. While developers can already fix vulnerabilities by going back and forth with a general-purpose AI assistant, our goal is to make that loop faster and more trustworthy.

That trust came from unglamorous engineering: teaching our agents how to build and test an application, trace data flows to reject risky fixes, and resolve breaking changes when modernizing legacy code. Along the way, we’ll share common patterns we’ve seen across rejected PRs, and what we had to iterate on to get hundreds of them merged.

We are open sourcing both agents for the community. The volume of CVEs keeps growing, automated remediation will become a must, and existing solutions don't yet solve this problem at the level we need.
Speakers
avatar for Amine Boudraa

Amine Boudraa

Senior Product Security Engineer, Thomson Reuters
Amine Boudraa is a Senior Product Security Engineer at Thomson Reuters specializing in application security. He builds AI agents, MCP servers, and automation that help engineering teams stay fast while ensuring the time they spend addressing security issues is meaningful and impa... Read More →
avatar for Ruchita Kshirsagar

Ruchita Kshirsagar

Senior Product Security Engineer, Thomson Reuters
Ruchita Kshirsagar is a cybersecurity professional with 9+ years of experience in application security and software development. A Senior Product Security Engineer at Thomson Reuters, she specializes in SAST/DAST/SCA, DevSecOps, threat modeling, container security, vulnerability management... Read More →
avatar for Nihit Gupta

Nihit Gupta

Senior Product Security Engineer, Thomson Reuters
Nihit is a passionate and enthusiastic Product Security Engineer with over 4 years of experience in software development and security. Skilled in SAST and SCA remediation, architecting Secure-SDLC environments, and cloud security. He enjoys working on projects that can enhance software... Read More →
avatar for Gianfranco Romani

Gianfranco Romani

Senior ML Engineer, Thomson Reuters
Gianfranco Romani is an Senior ML Engineer on Thomson Reuters' Cybersecurity team, leading strategy and delivery of AI security tools. He focuses on automated vulnerabilities discovery/remediation and securing enterprise LLM apps. Previously at Thomson Reuters Labs, he built AI products... Read More →
Thursday September 17, 2026 12:30 - 12:55 CEST
Auditorium (Ground Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link