BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//CFP.DEV//CFP.DEV shortcodes//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Voxxed Days Zürich 2026
X-WR-RELCALID:c426493a-54d4-472b-b975-6f3aaa7163fa
X-WR-TIMEZONE:Europe/Brussels
BEGIN:VEVENT
UID:cfp-1151-13576@cfp.dev
DTSTAMP:20261005T213056Z
SEQUENCE:0
STATUS:CONFIRMED
DTSTART:20260324T120000Z
DTEND:20260324T124500Z
SUMMARY:Who to blame? The AI\, The Programmer\, or The Prompt?
DESCRIPTION:This interactive session transforms AI security education into 
 an engaging courtroom-style debate. We&#39\;ll present five critical vulne
 rabilities affecting modern AI development tools\, and after each case stu
 dy\, the audience becomes the jury—voting on who&#39\;s responsible: the
  careless user\, the negligent developer\, or the inadequate service provi
 der.We&#39\;ll dissect real CVEs including GitHub Copilot&#39\;s wormable 
 RCE (CVE-2025-53773)\, MCP server command injections (CVE-2025-53107\, CVE
 -2025-5277)\, GitHub&#39\;s private repository leak via prompt injection\,
  and Microsoft Copilot&#39\;s zero-click data exfiltration (CVE-2025-32711
 ). Each case reveals technical root causes through collaborative analysis.
 The conclusion challenges the &quot\;blame game&quot\; itself: these vulne
 rabilities expose fundamental architectural weaknesses in agentic AI syste
 ms where traditional security models fail. We&#39\;ll establish that secur
 ing AI tools demands a shared responsibility framework—developers must c
 ode defensively\, providers must architect securely\, and users must under
 stand AI-specific risks. The session culminates with actionable best pract
 ices for each stakeholder.\nSpeakers: Makan Sepehrifar\nTrack: Security
URL:https://vdz26.voxxeddays.ch/talk/who-to-blame-the-ai-the-programmer-or-
 the-prompt/
LOCATION:Room 3\nARENA Cinemas\, Sihlcity\nZürich\, Switzerland
CATEGORIES:Security
END:VEVENT
END:VCALENDAR
