Infrastructure Doesn’t Lie: Using Infra Signals to Detect Shadow AI Built Applications
Balachandra Shanabhag April 17, 2026 AI app builders now enable production apps to ship without repositories, CI/CD, or security review, often by non-traditional developers outside established engineering workflows. These Shadow AI apps bypass AppSec pipelines and governance, creating a growing blind spot in enterprise environments. This talk demonstrates how DNS, TLS, and hosting signals can detect shadow AI apps that existing controls miss.

▶︎
Scaling AppSec Through Humans & Agents

▶︎
Inside the Modern Threat Landscape - Attacker Wins, Defender Moves, and Your Priorities

▶︎
Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

▶︎
Passkeys Explained: Are They Actually Better Than Passwords?

▶︎
Beyond Vibe Coding: Building Reliable AI AppSec Tools

▶︎
How I Use Aspirin to Unclog Arteries

▶︎
Conan O’Brien Delivers the Commencement Address | Harvard Commencement 2026

▶︎
Don’t Harsh my Vibe: From Theory to Practice in Securing AI-Generated Code

▶︎
But what is quantum computing? (Grover's Algorithm)

▶︎
Attacking AI - Jason Haddix - NDC Security 2026
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
▶︎
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

▶︎
From Controls to Confidence: Why Security Programs Fail Without Adoption

▶︎
The Agent Development Lifecycle: Build, Test, Deploy, Monitor | Interrupt 26

▶︎
Make Insecure Code Hard to Write: The IDE Guardrails Playbook

▶︎
Lessons from npm's Dark Side: These Are Not the Packages You're Looking For

▶︎
Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026

▶︎
you need to learn MCP RIGHT NOW!! (Model Context Protocol)

▶︎
Why Google Just Gave Away Gemma 4 for Free

▶︎
First findings from Project Glasswing

▶︎
