Day 1
Coding responsibly with GenAI
What is security?
Threat and risk
Cyber security threat types – the CIA triad
Consequences of insecure software
What is responsible AI?
Security and responsible AI in software development
The OWASP Top Ten 2025
A01 - Broken Access Control
· Access control basics
· Case study – Broken authz in FIFA platform during 2026 World Cup
· Confused deputy
o Insecure direct object reference (IDOR)
o Path traversal
o Lab – Insecure Direct Object Reference
o Path traversal best practices
o Lab – Experimenting with path traversal in GenAI
o Authorization bypass through user-controlled keys
o Case study – Remote takeover of Nexx garage doors and alarms
o Lab – Horizontal authorization
o Unrestricted file upload
o Good practices
o Lab – Unrestricted file upload
· Server-side Request Forgery (SSRF)
o Case study – SSRF in Ivanti Connect Secure
A02 - Security Misconfiguration
· Configuration principles
· Python configuration best practices
o Configuring Flask
· Web security configuration issues
o Content Security Policy
o Fetch directives
o Source allowlisting
o Strict CSP: using nonces and hashes
o CSP best practices
· Cookie security
o Cookie attributes
· Secrets management
o Hard coded passwords
o Best practices
o Lab – Hardcoded password
· XML entities
o DTD and the entities
o Entity expansion
o External Entity Attack (XXE)
- File inclusion with external entities
- Server-Side Request Forgery with external entities
- Lab – External entity attack
- Preventing XXE
- Lab – Prohibiting DTD
- Case study – XXE vulnerability in Ivanti products
- Lab – Experimenting with XXE in GenAI
Day 2
The OWASP Top Ten 2025
A03 - Software Supply Chain Failures
· Using vulnerable components
· Assessing the environment
· Hardening
· Untrusted functionality import
· Malicious packages in Python
· Supply chain security and the Software Bill of Materials (SBOM)
· SBOM examples
· Case study – The Polyfill.io supply chain attack
· Vulnerability management
o Patch management
o Vulnerability management
o Vulnerability databases
o Lab – Finding vulnerabilities in third-party components
o DevOps, the CI / CD build process and Software Composition Analysis
o Dependency checking in Python
o Lab – Detecting vulnerable components
· Security of AI generated code
o Practical attacks against code generation tools
o Dependency hallucination via generative AI
o Case study – A history of GitHub Copilot weaknesses (up to mid-2025)
o Case study – Agentic coding and code security (mid-2025 onward)
A05 - Injection
· Input validation
o Input validation principles
o Denylists and allowlists
o Case study – Denylist failure in urllib.parse.urlparse()
o What to validate – the attack surface
o Where to validate – defense in depth
o When to validate – validation vs transformations
· SQL injection
o SQL injection basics
o Lab – SQL injection
o Attack techniques
o Content-based blind SQL injection
o Time-based blind SQL injection
o SQL injection best practices
- Input validation
- Parameterized queries
- Lab – Using prepared statements
- Case study – SQL injection against US airport security
· Code injection
o Code injection via input()
o OS command injection
- Lab – Command injection
- OS command injection best practices
- Avoiding command injection with the right APIs
- Lab – Command injection best practices
- Lab – Experimenting with command injection in GenAI
- Case study – Shellshock
- Lab - Shellshock
- Case study – Command injection in Ivanti security appliances
· HTML injection - Cross-site scripting (XSS)
o Cross-site scripting basics
o Cross-site scripting types
- Persistent cross-site scripting
- Reflected cross-site scripting
- Client-side (DOM-based) cross-site scripting
o Lab – Stored XSS
o Lab – Reflected XSS
o Case study – XSS to RCE in Teltonika routers
o XSS protection best practices
- Protection principles - escaping
- Lab – XSS fix / stored
- Lab – XSS fix / reflected
- Case study – XSS vulnerabilities in DrayTek Vigor routers
Day 3
The OWASP Top Ten 2025
A06 - Insecure Design
· The STRIDE model of threats
· Secure design principles of Saltzer and Schroeder
o Economy of mechanism
o Fail-safe defaults
o Complete mediation
o Open design
o Separation of privilege
o Least privilege
o Least common mechanism
o Psychological acceptability
· Client-side security
o Frame sandboxing
- Cross-Frame Scripting (XFS) attacks
- Lab – Clickjacking
- Clickjacking protection best practices
- Lab – Using CSP to prevent clickjacking
A07 - Authentication Failures
· Authentication
o Authentication basics
o Multi-factor authentication (MFA)
o Case study – The InfinityGauntlet attack
· Password management
o Storing account passwords
o Password in transit
o Lab – Is just hashing passwords enough?
o Dictionary attacks and brute forcing
o Salting
o Adaptive hash functions for password storage
o Lab – Using adaptive hash functions in Python
o Lab – Experimenting with adaptive hash functions in GenAI
· Password policy
o NIST authenticator requirements for memorized secrets
o Password database migration
A08 - Software and Data Integrity Failures
· Subresource integrity
o Importing JavaScript
o Lab – Importing JavaScript
o Case study – The British Airways data breach
· Insecure deserialization
o Serialization and deserialization challenges
o Integrity – deserializing untrusted streams
o Deserialization with pickle
o Lab – Deserializing with Pickle
o Case study – The security of the machine learning supply chain
o Case study – The first wave of supply chain attacks: RCE via pickle (2022)
o Case study – Compromising the Hugging Face Hub repository
o Integrity – deserialization best practices
A10 - Mishandling of Exceptional Conditions
· Error and exception handling principles
· Error handling
o Returning a misleading status code
o Information exposure through error reporting
- Information leakage via error pages
- Lab – Flask information leakage
- Case study – Information leakage via errors in Apache Superset
· Exception handling
o In the except block. And now what?
o Empty except block
o Lab – Exception handling mess
Wrap up
Secure coding principles
· Principles of robust programming by Matt Bishop
And now what?
· Software security sources and further reading
· Python resources
· Generative AI – Resources and additional guidance.