Talk All Audiences 10:30 - 11:00 August 09, 2026

Filipi Pires

Most vulnerabilities aren't found because teams lack tools they persist because the cost of fixing them is too high. A finding without a concrete, context-aware fix is just noise developers learn to ignore. This talk walks through three real-world attack scenarios a secret leaked into git history, a compromised dependency in a supply chain attack, and an injection vulnerability introduced in a PR and shows how each is detected, mapped to OWASP Top 10:2025, and automatically remediated using AI running entirely on local infrastructure. No source code leaves the machine. The AI receives the vulnerable code block, CWE identifier, CVSS score, and OWASP category and returns a fix that is specific, correct, and ready to apply. Attendees leave with a working open-source tool and a new mental model for what AppSec remediation can look like.

Filipi Pires

Head of Technical Advocacy

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador and Application Security Specialist. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges.

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires