n|u Security Community Meetup - October 2025
Presenting our October 2025 meetup, on all things security!
We're back with something new in line for you.
Session 1. Security Reading Ring
A new initiative, where we conduct a casual, discussion-driven session to unpack recent security research. This is a first of its kind session to bring effective research to the forefront. For this meetup, we will discuss this paper - One Bug, Hundreds Behind: LLMs for Large-Scale Bug Discovery. So please read this and come!
Session 2. Readme.md to RCE: How a Comment Owned the Build
Modern developer workflows increasingly rely on AI-assisted tools – PR reviewers, IaC linters, even build-time fixers. This convenience quietly introduces a new attack surface: prompt injection inside the software supply chain. In this talk, Deepam will show how a seemingly harmless README change can hijack an AI reviewer’s context and trick it into suggesting a malicious Dockerfile edit. Once a developer merges the suggestion, the injected command propagates into the CI/CD pipeline. It executes at build time - bypassing static scanners and SBOM-based checks because the malicious step never appears in the source code until it’s too late.
See you there!
Dev & Ali
