Session
Defending Bare-Metal: Lessons Learnt from AI Security Analysis of Metal3 and OpenStack Ironic
AI-powered vulnerability discovery is here, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze, especially as low-hanging fruit is rapidly plucked.
In this session, maintainers and security team members from Metal3.io and OpenStack Ironic projects share how they used an AI-based vulnerability analysis tool to uncover hidden issues. This domain is often riddled with legacy drivers and requirements to support deprecated protocols, yet built on modern cloud-native architectures where a vulnerability proof is rarely an easily automated, executable crash. For project maintainers, we will share our candid analysis of the typical AI report shortcomings, what to look for in triage, and how to deal with the incoming flow without burning out.
Tuomo Tanskanen
Principal Security Developer at Ericsson
Helsinki, Finland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top