Check the online version, I often update my slides.

Talk detail

… but not waking up is not an option, now confirmed.

What to do in the age when time from security bug discovery to exploitation dropped to zero. It's not just due to the AI going mainstream, we had it coming for quite some time already. Yeah, of course, you have to update very quickly, but not that quickly, ha. We'll talk managing dependencies, what package managers are doing about it, what you can do, I mean have to do, about it.

Don't forget your CI and libraries your website loads from a random CDN, that's also what the attackers like to (ab)use. You have probably heard about the HTML integrity attribute (and keep not using it), but that's not all there is. Oh man, they say the description should be 200 words, but that's like the whole talk, so I'll just fill the rest with something and hope they don't notice – also a form of a supply chain attack, lorem ipsum. One hundred and seventy three words, this will have to do.

Date and event

November 20, 2026, TechMeetup Ostrava 2026 (talk duration 45 minutes)

Michal Špaček

Michal Špaček

I build web applications and I'm into web application security. I like to speak about secure development. My mission is to teach web developers how to build secure and fast web applications and why.

Public trainings

Come to my public trainings, everybody's welcome: