Great International Developer Summit (GIDS)

Who Is Securing the Code Your AI Wrote? - Biswajit De

29:43 · 21 Apr 2026 – 24 Apr 2026 · YouTube

About this talk

This talk examines the critical security risks inherent in AI-generated containers, particularly focusing on the vulnerabilities present in typical Ollama containers that contain numerous unnecessary packages. The speaker discusses real exploit scenarios, including CVE-2024-37032, which showcases how a simple HTTP request can lead to a full container takeover. The session emphasizes the importance of removing superfluous components to mitigate risks and addresses threats from supply chain attacks like Shai-Hulud. Through detailed examples, SBOM analysis, and exploit walkthroughs, the talk illustrates the necessity of foundation-first security in AI-driven development, highlighting strategies to minimize exposure at the base layer.