<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=671514874707498&amp;ev=PageView&amp;noscript=1">

June 17 at 5pm CEST | 8am PT

Advanced Security Strategies for Java and Spring Applications

Web-conference for engineers focused on real-world solutions for enhancing Java security, managing AI threats, and learning about zero-day responses.

Img_4 1

Topics

Passwordless login in Spring, with Passkeys

Daniel Garnier-Moiroux Daniel Garnier-Moiroux

Passwords. They're everywhere, they get leaked... A security nightmare! A work-around is to delegate authentication to a third party, for example using OpenID Connect. But sometimes you can't or don't want to do that - can you go password-less, with user-friendly flows?

Since version 6.4, Spring Security offers passkeys support. It allows for seamless authentication, using your device's authentication mechanisms, such as Windows Hello, Apple's FaceID and their Android equivalents.

In this session, we will shortly go over the theory behind passkeys. Then we will show demos on how to integrate one-time tokens and passkey support to an existing application, while discussing the specific challenges of those approaches.

AI Meets Cybersecurity:
From Classic Threats to Prompt Injections

Marharyta Nedzelska Marharyta Nedzelska

Cybersecurity has always mattered, but in the age of AI, it’s even more critical. Learn how to navigate through classic and novel threats such as prompt injections, secure your code, and use tools like SonarQube to stay safe in a world where AI changes the threat landscape.

Zero-Days, One Team: How BellSoft Fixes What’s Broken

Pasha Finkelshteyn Pasha Finkelshteyn

Backporting security fixes isn't glamorous — but it's critical. In this talk, you'll learn how the BellSoft team keeps multiple Java and Linux versions secure, balances stability with urgency, and collaborates with the open source community to deliver timely, reliable updates. From obscure CVEs to tricky legacy code, we’ll share what it really takes to keep things safe and running.

What You'll Learn

2 hours that could save you months of security headaches

🔐 Passwordless Authentication

Go Beyond Passwords with Spring Security
  • Implement passkey authentication using Spring Security 6.4+
  • Leverage device biometrics (FaceID, Windows Hello, fingerprint)
  • Create seamless, secure user experiences without password risks

🤖 AI-Era Security
Threats

Navigate New Attack Vectors and Defenses
  • Understand prompt injection attacks and AI-specific vulnerabilities
  • Use modern security tools like SonarQube for AI-aware code analysis
  • Adapt traditional security practices for AI-integrated applications

⚡ Zero-Day Response

Master Critical Vulnerability Management
  • Learn enterprise-grade security backporting strategies
  • Balance stability with urgent security updates
  • Collaborate effectively with open source security communities

Headliners

Daniel Garnier-Moiroux

Software Engineer for Spring Engineering at Broadcom
@kehrlann

Asset 1@2x-1     

Daniel Garnier-Moiroux is a software engineer on the Spring Commercial team at Broadcom, where he focuses on Kubernetes-native SSO products and contributes to Spring Security and the broader Spring ecosystem. Previously, he worked at Pivotal Labs and VMware Tanzu Labs, helping customers build modern software and engineering practices. Daniel also teaches computer science at Mines ParisTech and regularly speaks at international conferences about Java, Spring, and software development.

Daniel Garnier-Moiroux

Marharyta Nedzelska

Staff Software Engineer at Sonar
@jMargaritaN

Asset 1@4x-2      

Marharyta Nedzelska is a Staff Software Engineer at SonarSource and a Google Developer Expert for Kotlin. She’s passionate about code quality and has contributed to developer tooling and static analysis in the JVM ecosystem. Before joining SonarSource, she worked on high-load microservices at Wix and was an active organizer of the Kyiv Kotlin User Group.

Marharyta Nedzelska

Pasha Finkelshteyn

Developer advocate for Liberica JDK
@asm0di0

Alpaquita col-wh 2    LibericaJDK-logo-white   bellsoft-logo

Pasha Finkelshteyn is a Developer Advocate for Liberica at BellSoft, focused on data engineering and the JVM ecosystem. He writes and speaks about Java, Kotlin, Python, and Clojure, with a passion for helping developers navigate complex systems. Before joining BellSoft, he spent four years at JetBrains, creating content and giving talks on big data and Kotlin. Pasha is a regular speaker at international conferences and an active contributor to the developer community.

Pasha Finkelshteyn_

A web series by BellSoft where we share our passion for innovations that move the world forward.

jrushlogo

lightninghuge_2

 

lightning_2

Best Format:

  • 2 hours
  • 3-speaker only
  • Short, concise, and eventful presentations
  • Post-talk Q&A with experts

 

lightning_2

Expert Headliners: 

  • Only new and exciting Java technologies
  • Only renowned experts from the community
  • Only senior engineers that develop on Java

FAQ

What is JRush?

A series of free online seminars on Java development and all the latest trends of the industry.

What makes JRush stand out?

We aim to provide no-nonsense compact interactive speakings with valuable insights. All the data, including the presentations and code snippets, are available for download.

Is JRush free?

The event is free for all subscribers.

What does the subscription provide?

Access to all previous videos, presentations, and data; an opportunity to take part in future live events.

How can I subscribe?

Click the button, fill the form, share your email.

Is JRush an online-only event?

We invite people from all over the world, and we like to give them equal participation opportunities, so we made JRush an online-only event with interactive tools for submitting your commentaries and questions.

Is my contact information secure?

We guarantee the privacy of your information. We will never collect or share it with third parties.

Rush with us!

Leave your details to get a broadcast link before JRush and a recording after the conference ends.

You will automatically join the BellSoft community and get a subscription to the JRush series.

Form_BG3_v2