The target on developers' identities has never been bigger. They hold access to source code, CI/CD pipelines, and cloud infrastructure — and attackers know it. Target lost 860GB of source code through a single compromised credential. Recruitment fraud campaigns have pivoted from developer access to cloud admin in under 10 minutes. These aren't code vulnerabilities — they're access problems. And as AI agents join human developers, contractors, and service accounts in the SDLC, the attack surface is expanding faster than static security tools can track. Security teams need real-time visibility into who has access and what they're actually doing — not just what's in the code.
Segment Resources:
https://www.blueflagsecurity.com/blog/860gb-of-source-code-stolen-no-one-knows-who-did-it-thats-the-problem https://www.blueflagsecurity.com/resources/securing-the-software-supply-chain-addressing-identity-toolchain-and-code-risks
Make sure to schedule a free SDLC Risk Assessment with BlueFlag Security - 30 minutes to deploy. 48 hours to results. Please visit https://securityweekly.com/blueflagrsac.
Read the interview summary from SC Media here: https://www.scworld.com/resource/blueflag-securitys-raj-mallempati-on-why-breaches-start-with-identity
- 0:00 - Welcome to RSAC 2026 – Developer Security Trends
- 0:22 - Why Identity & Access Management Still Matters
- 0:48 - The Hidden Root Cause of Vulnerabilities (Not Just CVEs)
- 02:29 - Human vs Non-Human Identities & AI Agents Explained
- 02:56 - Why Enterprises Know the Risk But Ignore It
- 04:01 - The Visibility Problem in DevSecOps
- 04:35 - Least Privilege & Reducing Attack Surface
- 06:17 - Understanding Toxic Interactions in Security
- 06:52 - Insider Risk vs External Threats in Dev Environments
- 08:19 - Correlating Data Across Dev Tools for Better Security
- 08:33 - Managing Shadow AI & Developer Tool Sprawl
- 09:27 - The Rise of Unsanctioned LLMs in Development
- 11:35 - Overprivileged Access – The 5% Usage Reality
- 12:13 - How CISOs Can Secure Without Slowing Developers
- 13:45 - Balancing Security with Developer Productivity
- 14:02 - Zero Trust & Least Privilege in Practice
- 14:30 - Developer Freedom vs Security Governance
- 14:45 - What is Developer Risk & Governance Platform?
Raj Mallempati is CEO & Co-founder of BlueFlag Security. Prior to launching BlueFlag, he most recently served as COO CIEM at Microsoft, through Microsoft’s acquisition of his prior company CloudKnox Security (acquired 2021). Prior to joining CloudKnox, Raj was the Senior Vice President of Marketing at Malwarebytes. Raj has also held positions as the Vice President of Global Marketing at MobileIron, Vice President of Product Marketing at Riverbed Technology, and was the Director of Marketing and Business Strategy at VMware. He holds an MBA from The Wharton School, University of Pennsylvania, MS, Computer Science from the University of Texas, and a B.Tech from Indian Institute of Technology, Madras.
