LLM et cybersécurité

LLM et cybersécurité

🎙 Thibault Fontaine 👥 12K 📅 April 10, 2026 ⏱ 18 min 👁 42 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

vibe codingLLM securityvulnerabilitiesDevSecOpsNIS2

Summary

In this talk, Thibault Fontaine, a cybersecurity professional and educator, discusses the security implications of using large language models (LLMs) for coding, a practice known as ‘vibe coding’. He acknowledges the widespread adoption of LLMs among developers but highlights that the generated code is often vulnerable. He cites a Veracode study showing that 45% of AI-generated code contains vulnerabilities, and mentions an Anthropic report on an AI-driven attack with minimal human intervention. Fontaine also discusses the acceleration of vulnerability exploitation, referencing Vincent Stubble’s statement that 30% of exploited vulnerabilities are exploited on the same day they are disclosed. He emphasizes the need to treat LLMs as external developers, applying security practices such as static code analysis, dependency checks, and secret management. He introduces the upcoming NIS2 directive and its requirements for essential entities. The talk concludes with a Q&A session where he addresses ethical concerns and the evolution of penetration testing.

151 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the practical security risks of using LLMs for coding, supported by references to real-world incidents and studies. The argumentation is coherent, moving from the problem (vulnerable code) to solutions (secure development practices). However, the speaker relies heavily on anecdotal evidence and general knowledge, and some claims lack specific citations. The discussion of NIS2 is relevant but brief, and the Q&A section adds practical perspectives on the future of penetration testing.

85 words

Title / Content Match

The title accurately reflects the content, which discusses the intersection of LLMs and cybersecurity, focusing on risks and mitigation strategies.

Quality & Reliability

7/10

The speaker is a cybersecurity professional and educator, providing practical insights and referencing known incidents and tools. However, the talk is largely based on personal experience and general knowledge, with limited specific citations and no formal peer-reviewed sources.

Key Moments

Cited Sources

  • Anthropic's report on AI-driven attack — Mentioned as a report by Anthropic's security team on the first documented AI-driven attack with minimal human intervention.
  • Veracode study on AI-generated code vulnerabilities — Referenced as a study by Veracode testing around 100 AI models on 80 coding tasks, finding 45% of generated code vulnerable.
  • Firefox team using Claude 4.6 to find vulnerabilities — Mentioned as an example of using LLMs to find and fix vulnerabilities, with 22 vulnerabilities found in two weeks.

Concurring Sources

  • Veracode study on AI-generated code vulnerabilities — The speaker's claim that AI-generated code is often vulnerable is consistent with broader industry reports.

Contribution & Novelties

The talk provides a practical perspective on the security risks of LLM-generated code, emphasizing the need for secure development practices. It bridges the gap between the enthusiasm for ‘vibe coding’ and the reality of vulnerabilities. The speaker’s recommendation to treat LLMs as external developers is a useful mental model.

Pour aller plus loin :

97 words

Radar Profile

The radar profile shows a balanced performance across information quantity, quality, technical depth, and reliability, with slightly lower scores in technical depth and reliability due to the informal nature of the talk.

Reliability 6/10