Speaker Details
Yunus Aydın
Security Engineer @ Trendyol
Yunus Aydin is a security engineer at Trendyol, specializing in vulnerability research, threat detection, and securing software supply chains. With extensive experience in identifying critical security flaws, Yunus has contributed to multiple high-impact security findings, including those related to package management platforms and domain hijacking risks. Their work spans areas like mobile security, cloud services, and DevOps security, with a focus on automating security measures to minimize risks. Yunus is passionate about advancing security practices in the development community and educating others on emerging threats and mitigation strategies.
Outside of security research, Yunus enjoys sharing knowledge through blog posts, speaking at conferences, and collaborating with peers to improve security tools and methodologies.
Your AI Just Leaked a Secret
Friday, 13 November 2026, 14:40 - 15:20
AI-assisted "vibe coding" is accelerating software development, but it also introduces subtle security risks. This research presents a three-month analysis of thousands of public GitHub repositories, using AI to examine commit messages as a side channel for detecting secret exposure. By identifying patterns such as "remove secret" or "fix leaked token," the study uncovers how sensitive data is briefly committed and later removed. The findings highlight how AI-generated code contributes to these leaks and demonstrate how commit metadata can enhance traditional secret detection and mitigation strategies.
