What Developers Think They Know: Fixing the False Confidence Behind Persistent Vulnerabilities

No ratings

Presented at 0xcon 2025 by

Despite decades of secure coding guidance, we still see SQL injection, Cross-Site Scripting (XSS), and insecure configurations in modern applications. Why? It’s not a lack of awareness, but a gap between what developers think they know and what they actually apply. This talk goes beyond checklists and “shift-left” slogans. Drawing on first-hand training and consulting experience, it reveals why traditional “secure SDLC” guidance often fails, and how recurring issues stem from cultural flaws rather than just coding mistakes. From coding faults to systemic design flaws, we’ll explore how recurring security issues stem from false confidence, weak feedback loops, and poor accountability. Attendees will leave with strategies for reshaping the SDLC to empower developers, reduce noise for security teams, and shift red teams away from patch-cycle purgatory, towards lasting security improvement.