
OWASP Stockholm - Secure Agentic SDLC & Autonomous Pentesting Coverage
About the event
Join us for a packed in-person OWASP event at Scila AB with talks on Security in the Agentic SDLC (Software Development Life Cycle) and The Coverage Failure in Autonomous Pentesting.
📢 Important news: Meetup will be decommissioned at the end of the year, so RSVP will be moving to our OWASP Chapter page then. To stay updated on future events, join the chapter here: 🔗 [https://owasp.org/chapters/stockholm](https://owasp.org/chapters/stockholm)
🗓️ When: 14th of October, 17:30 - 20:00 📍 Where: Scila AB - Sveavägen 17, 111 27 Stockholm.
🚀 Agenda: 17:30 - 18:00 Gathering and meeting industry peers. 18:00 - 18:05 Intro. 18:05 - 18:40 Talk 1 18:40 - 19:00 Break and mingling. 19:00 - 19:40 Talk 2 19:40 - 20:00 Closing words & meeting industry peers.
🌟More about the talks: A Simple Guide To Security in the Agentic SDLC *Ernest Bartosevic* The SDLC we built assumes security happens at gates: threat modeling during design, a review on the PR, scanning after deploy. That only works if humans have the time to look and actually care while juggling 30 different tasks.
Many people will tell you we are "cooked" - but security has adapted before. We rebuilt the whole practice when waterfall gave way to agile. This talk is a practical guide to turning coding agents into the guardians of your security, rather than the source of your next incident. It covers which gates still stand, which ones need to move, and how to give agents the context, guardrails and feedback loops to enforce *your* policies, so AI becomes a co-pilot you can trust.
The Coverage Failure in Autonomous Pentesting *Yacine Souam* Most autonomous pentesting systems use either a fixed pool of specialist agents or a single agent that recursively spawns copies. Both fail by losing control of breadth: fixed pools spread effort evenly, while pure recursion goes depth-first, burns budget on early leads, and leaves major surfaces untested. The research reframes pentesting as an explore/exploit search problem. A dedicated coverage agent continuously maps the attack surface, identifies gaps, and routes work to an orchestrator that preserves breadth while spawning specialists only where needed.
The talk covers the harness internals behind this approach: persona-isolated browser contexts for Broken Object Level Authorization (BOLA) and cross-tenant testing, an independent reporter agent that reproduces findings on live targets, recursive delegation with depth governance, and a capability layer that keeps agent context scoped.
It presents benchmarks against public AI pentest tools and a frontier-model baseline, then closes on two questions: how to evaluate agent-spawning systems, and whether specialist agents can be persisted and reused.
About the speakers Ernest Bartosevic Ernest is a Solutions Engineer at Semgrep. He helps teams secure code written by developers and AI agents, catching issues early in the IDE, the agentic loop or the CI/CD pipeline, with dev-friendly findings and minimal friction. Before Semgrep, Ernest spent seven years in defensive security, covering SOC operations, detection engineering and threat intelligence. When he's not securing code, he's probably brewing coffee, hanging out with his cats or tinkering in his home music studio.
Yacine Souam Yacine is an R&D engineer at Escape (YC W23), building AI agents for automated pentesting, and a co-author of the OWASP AI Exchange. Before Escape, he worked in security research, finding vulnerabilities across AI systems from Nvidia, Hugging Face, and Ollama.





