Program



Track A(Hall D)
2026.8.11 13:00 ~ 13:40
mail share facebook share twitter share linkedin share band share kakao
What Can We Trust in AI-Generated Code? Software Supply Chain Governance Driven by SBOM, VEX, and Real-World Exploit Intelligence

Lsware Joonseok Park Managing Director


The spread of AI coding tools has dramatically accelerated code production, but unverified open source of unknown provenance and AI-generated code snippets are flowing into systems unchecked, opening a new blind spot in supply chain security. OWASP Top 10 2025 newly designated "Software Supply Chain Failures" as a core threat, while the EU Cyber Resilience Act begins vulnerability reporting in September 2026 and Korea signals mandatory public-sector SBOM submission by 2027?turning SBOM from a recommendation into a condition of market entry. Yet responding to the thousands of vulnerabilities an SBOM surfaces is impossible. This session presents strategies for securing trustworthy SBOMs, prioritizing risk through real-world exploit intelligence such as EPSS and CISA KEV, and leveraging VEX (Vulnerability Exploitability eXchange) to filter for vulnerabilities that actually affect the product and to document justified non-remediation?building a "chain of trust" that extends from identification to automated control and policy governance, illustrated with global regulatory trends and field cases from finance and manufacturing.