Podcasts about appsec

  • 205PODCASTS
  • 1,739EPISODES
  • 41mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 30, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about appsec

Show all podcasts related to appsec

Latest podcast episodes about appsec

Hacker Valley Studio
Giving Your AI Agent Its Own Identity with Ashish Rajan

Hacker Valley Studio

Play Episode Listen Later Sep 30, 2026 32:18


Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's. Ashish got into identity after failing his OSCP three times: if he couldn't break in, he wouldn't let anyone else in. Now he reviews Ron's own setup, where Hacker Valley's AI agent, Jennifer Romani, has her own accounts just like an employee. Ashish explains how that call changes from a one-laptop small business to an enterprise where every developer's machine acts like five. They also cover the Gemini breach headlines, swarms of agents and AI Security Lab, which Ashish describes as what OWASP is for AppSec, but for AI security. The uncomfortable truth: defenders have the same models attackers do, but attackers don't wait for a pull request review. Ashish calls that a people problem, not a technology problem. He also shares the question he asks before handing anything to an AI agent: can this be reversed? Impactful Moments 00:00 - Introduction 02:30 - Busting a myth: AI identity isn't solved 05:30 - Three OSCP attempts and a pivot to IAM 07:00 - Why AI identity is more complex than ever 09:15 - Hot or not: giving an AI agent its own accounts 11:10 - One laptop, five machines in the enterprise 12:50 - AI gateways and developer observability 14:05 - Where Ashish would spend his AI security budget 18:20 - Why defenders don't hack themselves first 19:05 - The real problem is people 22:15 - Swarms of agents are coming 23:50 - What AI Security Lab is building 26:35 - Never share your credit card with AI 28:40 - Ron's callback: can it be reversed? Links Connect with Ashish Rajan on LinkedIn: https://www.linkedin.com/in/ashishrajan/ Listen to Ashish's first Hacker Valley Studio episode: https://www.podbean.com/pw/pbblog-bpaij-51b280 –  Check out our upcoming events: https://www.hackervalley.com/livestreams  Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  Become a sponsor of the show: https://hackervalley.com/work-with-us/ 

Reimagining Cyber
Application Security in the AI Era - #221

Reimagining Cyber

Play Episode Listen Later Sep 30, 2026 27:45


AI is changing application security at breakneck speed — and it's not just about generating code faster.In this episode, Keelin Conant's guest is Diogo Rispoli, an application security leader, architect, and longtime industry expert. They explore what happens when AI agents start writing, testing and fixing code, and even talking to each other. The episode also digs into rogue agents, exploitability, AI-powered testing, the limits of auto-remediation, and why security teams need to look beyond the code itself.Plus, Diogo looks ahead to 2030 and asks a big question: will finding vulnerabilities even be the job of AppSec anymore?As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

Application Security PodCast
Why AI Code Review Will Replace Human Review Faster Than You Think

Application Security PodCast

Play Episode Listen Later Sep 29, 2026 49:11


Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company. The founder of Manicode Security returns to explain why AI didn't kill AppSec education but supercharged it, why vague prompting on frontier models turns companies into "token furnaces," and why prompt injection is the one genuinely new vulnerability class of the AI era. He walks Chris and Robert through his full AI coding workflow, from reverse engineering an architecture file to security rules and planning-mode build plans that make AI output deterministic. The three debate whether AI will finally eliminate SQL injection, whether AppSec vendors can survive without integrating cyber models, and when humans still need to step in: the moment an agent tries something its policy doesn't allow. Plus: the one habit every security leader should teach developers now.This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.About Security CompassAI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.→ Learn more about securing the AI-DLC with Security CompassThis episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Jim Manico:→ Jim Manico on LinkedInMentioned in this episode:→ Manicode Security→ Manicode Forge→ OWASP Artificial Intelligence Security Verification Standard (AISVS)→ OWASP AISVS on GitHub→ Claude Code→ OllamaFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00:00 - Cold open: the era of code review is ending00:00:47 - Meet Jim Manico00:01:03 - Welcome and what gets Jim away from screens00:05:29 - How AI changed developer security education00:07:03 - Teaching developers to use AI well00:09:26 - Where AI and AppSec stand: the token furnace00:12:08 - Separating signal from hype00:14:24 - Integrate with cyber models or die: the future of AppSec tools00:18:34 - Are AI coding assistants creating new vulnerabilities?00:20:02 - Prompt injection: the one truly new class00:21:15 - Will AI eliminate the OWASP Top 10?00:24:18 - Local models and Apple's hardware edge00:28:32 - Jim's AI coding workflow, step by step00:33:57 - The end of human code review00:38:31 - Can we trust AI code review, and when do humans step in?00:44:56 - Where companies really are with AI00:47:02 - One change for security leaders: planning mode00:48:19 - Wrap up

Application Security PodCast
Vulnerability Jail and the AI-Era AppSec Engineer

Application Security PodCast

Play Episode Listen Later Sep 22, 2026 44:59


Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of engineers shipping 10x more code: a "vulnerability jail" that locks non-compliant teams out of the main branch, AI-reviewed extension requests, and homegrown agents that hunt for entire classes of vulnerabilities instead of one bug at a time. He and Chris debate whether AI has killed classic SAST and DAST, whether code review still needs a human in the loop, and whether bug bounty programs still make sense when the researchers on both sides are running the same models. Plus: one concrete move every AppSec leader can make this quarter.This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.About Security CompassAI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.→ Learn more about securing the AI-DLC with Security CompassThis episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Jeevan Singh:→ Jeevan Singh on LinkedInMentioned in this episode:→ Rippling→ Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident)Follow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00:00 - Cold open: vulnerability jail00:00:55 - Meet Jeevan Singh00:01:11 - Welcome and Robert's AI lab00:02:37 - What gets Jeevan away from the machines00:04:51 - Hardware projects with his son00:06:20 - What's changed for the AppSec engineer since AI00:08:17 - Shipping production code and fixing whole vulnerability classes00:09:13 - Why AppSec has to become less collaborative00:10:02 - From democratized vuln management to vulnerability jail00:11:50 - How engineering reacted and the feature flag jail precedent00:14:05 - From manual jail to automated checks00:15:30 - An AI bot that reviews SLA extensions00:16:06 - Can AI wipe out an entire vulnerability class?00:17:36 - Building an anti-SSRF library and rolling it out00:19:40 - Which AppSec skills matter now00:22:28 - Validating all that AI-generated code00:22:57 - Agents that hunt for vulnerability classes00:24:38 - Is this the death of classic AppSec tools?00:26:51 - Code review and humans in, on, and out of the loop00:28:00 - Objective-based agents that find RCEs00:28:59 - Build vs. buy for AppSec teams00:31:29 - Advice for teams of one to five AppSec engineers00:32:58 - Cutting SLAs to 3, 5, 7, and 10 days00:34:31 - Parachuted in as the only AppSec engineer00:37:59 - One investment to make this quarter00:39:09 - The Hugging Face and OpenAI agent incident00:40:13 - Is bug bounty dead?00:42:19 - Key takeaways: be an engineer, run toward AI00:43:53 - Wrap-up

Resilient Cyber
The Model Writing Your Code Shouldn't Be Securing It

Resilient Cyber

Play Episode Listen Later Sep 21, 2026 30:56 Transcription Available


Jonathan Rende of Checkmarx on why the model writing your code cannot also be the control that validates it, and why rules-based and AI-driven scanning turn out to find almost entirely different bugs.In this episode I sit down with Jonathan Rende of Checkmarx. Jonathan worked with Fortify and SPI Dynamics back in the day, spent most of the last decade leading product teams in developer and DevOps tooling, and came back to security eighteen months ago because, as he puts it, this is the heart of the hurricane. His argument is that AI is a bigger disruption than the internet, SaaS, or mobile were, not because of any single capability, but because it hits roles, process, and productivity all at once.We get into the two waves he has watched play out with CISOs and their CEOs, why the pendulum has swung back toward program and posture questions in the last quarter, what his research team found when they benchmarked deterministic and probabilistic scanning side by side, and why he thinks agentic AppSec raises the profile of the security team rather than automating it away.In this episode:● Why the first half of 2026 became a real inflection point rather than another AI talking point● The two waves: engineering told to run at any cost, then the pendulum swinging back toward posture and program design● Why functional AI-generated code and secure AI-generated code are still two different things● Separation of church and state, and the conflict of interest in letting the model that generates code also validate it● Benchmarking deterministic and AI-based scanning across dozens of open source projects, and why the overlap stayed consistently under 10%● Fidelity, F1 scores, and the absence of real standards or shared benchmarks in AppSec● Why an incentive to reduce risk and an incentive to sell tokens are not the same incentive● Why agents free AppSec professionals for higher-order work, and why this is not a dark factory● Shadow IT becoming shadow AI, and early scans where half surfaced models, agents, and MCP servers security teams did not know existed● Why new threat vectors show up first in fast-moving unregulated companies while regulated ones see more code-level issues● Low-priority vulnerabilities chained into real impact, and why backlogs now matter as much as incoming code● What to change first: metrics defined up front, in-workflow AppSec, and security reviews that went from annual to monthlyChapters:0:00 Intro0:18 Fortify, SPI Dynamics, and a decade in developer tooling1:24 Why he came back to AppSec2:54 Why the first half of 2026 was the inflection point5:27 Two waves, and the pendulum swinging back9:08 Functional AI code versus secure AI code11:58 Layered defense and the condensed lifecycle15:04 What agents free AppSec teams to actually do17:50 Separation of church and state20:15 Fidelity, F1 scores, and not selling tokens23:25 New threat vectors and organizational maturity25:47 Shadow AI and what the inventory scans found27:58 What to change first in your AppSec program30:44 ClosingConnect with Jonathan:LinkedIn: https://www.linkedin.com/in/jonathanrende/Checkmarx: https://checkmarx.comResilient Cyber: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#appsec #aisecurity #devsecops #shadowai #vulnerabilitymanagement #ciso

Defense in Depth
How AppSec Needs to Change For the Speed of AI

Defense in Depth

Play Episode Listen Later Sep 17, 2026 26:20


All links and images can be found on CISO Series Check out this post by Anand Singh, CSO, Symmetry Systems, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is Ryan Barrett, svp, security, Intermedia Cloud Communications. In this episode: Risk by default, not by decision Identity, not just speed Building security into the pipeline, not around it Letting the machine make the fix A huge thanks to our sponsor, ThreatLocker An AI-generated attack may be new, but it still needs to execute, access data, and move through your environment. ThreatLocker applies enforceable controls at each of those points, limiting what attackers can do regardless of how their code was created. Book a demo at threatlocker.com/ciso.

Application Security PodCast
Your AppSec Bottleneck Is a People Problem

Application Security PodCast

Play Episode Listen Later Sep 7, 2026 48:03


What makes a security champions program successful—and why do so many fail? Lisi Hocke explains how psychological safety, cognitive load, power sources, and community can help create sustainable programs. We also explore reducing security wait times, gaining organizational support, the role of AI, why champions meetings shouldn't be recorded, and the importance of putting people first.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more at Corgea.com.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.Learn more about Corgea.FOLLOW US ON SOCIAL MEDIA:➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security Podcast~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

InfosecTrain
COASP: Offensive AI Security Explained

InfosecTrain

Play Episode Listen Later Sep 4, 2026 42:19


Artificial Intelligence is creating a completely new cybersecurity attack surface. But can traditional penetration testing identify AI-specific vulnerabilities? In this masterclass episode, InfosecTrain explores EC-Council's Certified Offensive AI Security Professional (COASP) certification, covering AI red teaming, prompt injection vectors, and offensive security for modern AI pipelines.The "course titled" EC-Council COASP Certification Training prepares penetration testers to exploit and defend AI systems.

Paul's Security Weekly
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

Paul's Security Weekly

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-398

Paul's Security Weekly TV
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Nidhi Aggarwal, Gil Geron, Braden Russell - ASW #398

Paul's Security Weekly TV

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Show Notes: https://securityweekly.com/asw-398

Application Security Weekly (Audio)
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

Application Security Weekly (Audio)

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-398

Application Security Weekly (Video)
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Nidhi Aggarwal, Gil Geron, Braden Russell - ASW #398

Application Security Weekly (Video)

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Show Notes: https://securityweekly.com/asw-398

KuppingerCole Analysts
Analyst Chat #314: Can You Trust AI to Verify AI Code?

KuppingerCole Analysts

Play Episode Listen Later Aug 31, 2026 36:08


AI writes the code. But who checks it, and who is accountable when it goes wrong? In this episode, Matthias is joined by two colleagues: Guillaume Teixeron, bringing 20 years of experience on the product side of identity and authentication, and Jonathan Care, KuppingerCole Analysts' Director of Practice AI. Together they tackle the security gap opening up between how fast AI generates code and how slowly organizations are catching up on assurance, provenance, and accountability. Key Topics: ✅ AI in software development: from hype to structural baseline — but governance is still improvised✅ Three tectonic shifts in AppSec: provenance, scale, and non-human identity✅ Why organizations have industrialized code production but not code assurance✅ The core question: can you trust AI to verify AI-generated code?✅ Agent autonomy in production pipelines — the next flashpoint nobody has resolved yet✅ How regulation (CRA, NIS2, DORA) will settle the provenance argument before the market does ⚡ "We have industrialized code production. We have not industrialized code assurance." Jonathan Care on why the security control set was built for human-authored code moving at human speed — and neither assumption is true anymore.

KuppingerCole Analysts Videos
Analyst Chat #314: Can You Trust AI to Verify AI Code?

KuppingerCole Analysts Videos

Play Episode Listen Later Aug 31, 2026 36:08


AI writes the code. But who checks it, and who is accountable when it goes wrong? In this episode, Matthias is joined by two colleagues: Guillaume Teixeron, bringing 20 years of experience on the product side of identity and authentication, and Jonathan Care, KuppingerCole Analysts' Director of Practice AI. Together they tackle the security gap opening up between how fast AI generates code and how slowly organizations are catching up on assurance, provenance, and accountability. Key Topics: ✅ AI in software development: from hype to structural baseline — but governance is still improvised✅ Three tectonic shifts in AppSec: provenance, scale, and non-human identity✅ Why organizations have industrialized code production but not code assurance✅ The core question: can you trust AI to verify AI-generated code?✅ Agent autonomy in production pipelines — the next flashpoint nobody has resolved yet✅ How regulation (CRA, NIS2, DORA) will settle the provenance argument before the market does ⚡ "We have industrialized code production. We have not industrialized code assurance." Jonathan Care on why the security control set was built for human-authored code moving at human speed — and neither assumption is true anymore.

The Security Podcast of Silicon Valley
102. CISO does not spell CEO (with Chris Kirschke)

The Security Podcast of Silicon Valley

Play Episode Listen Later Aug 25, 2026 41:13


Chris Kirschke spent 27 years in security operations before a venture studio's general partner asked him to run a company. His first answer was that CISO does not spell CEO. He took the job anyway, and Kyberis AI now runs a threat graph that pulls in any OpenCTI-compliant feed, commercial or OSINT, and exposes it to security agents through MCP. Jon and Chris start with what has to be true before any of that works. Chris borrows the thesis Jason Clinton laid out at Anthropic. If you can't trust the inputs, you'll never trust the output, and that holds whether the thing consuming the input is an L1 analyst, a 2003 IDS, or a threat-hunting agent. Then the good part. Chris has enabled write access on a production system exactly once in his career. Cisco NetRanger, shunning turned on, signature matched, ACL written to the downstream router. He watched a production system go from hero to zero in 7 minutes, and finding a way to power cycle a router that size took him longer than the outage. Sean Gray was in the data center with him, still in college. That's the story sitting under the question Chris now puts to anyone selling autonomous remediation. Are you actually going to give an agent write access? Also in this one. The engineer at Gartner who wired an anti-CISO agent to his own Gartner login, his tech stack, and his team's engineering bandwidth, so he can ask Claude to explain to his boss why they're not doing the shiny thing yet. Why Chris thinks the case for AppSec being dead is horseshit, and why the SIEM isn't going anywhere either. The hoodie-or-suit question he'd hand his younger self. And the product he'd write an angel check for tomorrow, which has nothing to do with security and everything to do with understanding what his teenage daughters just said to him.   Chris's ask is simple. Go to developer.kyberis.ai and start building. Brought to you by YSecurity, the security team that works next to yours. Your first 8 hours with 40+ security engineers are free at ysecurity.io/startups. Chris Kirschke: https://www.linkedin.com/in/kirschke/ Kyberis AI: developer.kyberis.ai   Jon McLachlan: https://www.linkedin.com/in/jon-mclachlan/ YSecurity: https://ysecurity.io   

Cybercrime Magazine Podcast
Securing The Build. AI, AppSec, & Exposure Management. Azi Cohen & Asaf Saar, Mend.io.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 24, 2026 14:27


Cybercrime Magazine attended Black Hat USA 2026, where we caught up with executives from leading companies across the industry, including Mend.io. In this episode, host Sam White speaks to CEO Azi Cohen and EVP of Product Asaf Saar. Securing The Build is brought to you by Mend.io, the leading application security solution, helping organizations reduce application risk efficiently. To learn more about our sponsor, visit https://mend.io.

DevSecOps Podcast
#08 - 12 - The surprising game that transformed AppSec training

DevSecOps Podcast

Play Episode Listen Later Aug 24, 2026 46:24


Transform your approach to cybersecurity training with this insightful episode featuring Max Alejandro Gomez Sanchez Vergaray, a pioneer in integrating gaming into application security. Discover how Max's innovative methodology not only translates complex security principles into engaging formats but also empowers teams to prioritize cybersecurity without the usual resistance. If you're in tech, especially in software development or security, this episode is a must-listen!Max shares his journey from leading a top banking application security program to launching his own consulting firm focused on secure software development. He reveals the secret behind the success of the OWASP Cornucopia game—a tool that makes learning about security engaging and impactful. You'll learn how to leverage gamification to enhance security awareness and foster a culture that values cybersecurity as an integral part of development.You'll discover:- How to implement OWASP Cornucopia in your organization and the surprising benefits it offers.- The importance of integrating security into your product backlog to ensure it's not an afterthought.- Practical tips for overcoming common challenges in security training, especially in environments resistant to change.- The role of fun in training and how it can lead to better retention and engagement among team members.Why does this matter? In today's digital landscape, the consequences of neglecting security can be catastrophic. By adopting innovative strategies like gamification, you not only mitigate risks but also build a more informed and proactive team. This episode opens the door to new possibilities in your approach to cybersecurity, emphasizing that learning can—and should—be enjoyable.Tune in for this essential discussion that promises to reshape your understanding of security training. Perfect for tech leaders, developers, and anyone involved in cybersecurity!Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.Support: Nova8, Checkmarx, Snyk, Conviso, Gold Security, CyberSec Games and PurpleBird Security.

InfosecTrain
Can AI Be Hacked? Real Exploits Explained

InfosecTrain

Play Episode Listen Later Aug 24, 2026 71:59


Artificial Intelligence is transforming cybersecurity, but it also introduces critical attack surfaces already being exploited. In this session, InfosecTrain breaks down how AI systems get hacked, covering prompt injection, model poisoning, and practical defense frameworks to help security teams protect machine learning pipelines effectively.The "course titled" Practical AI Security Engineering Program provides hands-on expertise to defend your AI architecture.

Application Security PodCast
The Future of Open-Source Threat Modeling

Application Security PodCast

Play Episode Listen Later Aug 17, 2026 40:14


This episode is sponsored by Corgea.Design it. Build it. Ship it. Corgea secures it.Learn more: Corgea.comYou don't have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. We dig into the tension among speed, compliance, and real risk, and what it means to “fight the AI” so that critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting — helping security and engineering teams find risk earlier, fix what matters, and ship securely.Learn more about Corgea → Corgea.comFOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Paul's Security Weekly
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Paul's Security Weekly

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Audio)
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

The Shared Security Show
OpenAI Says Its AI Hacked Another Company on Its Own

The Shared Security Show

Play Episode Listen Later Aug 3, 2026 23:16


OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions?Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story harder to evaluate, what companies should learn before deploying AI agents into production environments, and why permissions, logging, containment, and incident response matter more than marketing language about models acting on their own.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show **OpenAI says its AI technology acted on its own in an ‘unprecedented' hack of another company https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3Luta Security: OpenFace: The Hugging Face Breach and What to Do About It https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-itCloud Security Alliance: Hugging Face Incident Initial Post Mortem https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem** Watch this episode on YouTube **https://youtu.be/Fwb0jsgJxf4** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

Paul's Security Weekly TV
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Paul's Security Weekly TV

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Video)
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Cloud Security Podcast
Why Runtime Agents Are Replacing Static Posture Checks

Cloud Security Podcast

Play Episode Listen Later Jul 28, 2026 44:31


The attack window from the discovery of a vulnerability to its exploitation has shrunk to less than 24 hours and sometimes down to just 25 minutes. Is your security team prepared for the speed of AI-driven attacks?In this episode, Ashish sits down with Sarit Tager, who leads Cortex Cloud product management at Palo Alto Networks, to discuss why the post-Mythos era is forcing Cloud Security and AppSec out of their traditional silos. Sarit explains how AI coding agents prioritize generating code over securing it, which can sometimes result in flaws like accidentally deleting production databases within two weeks.We also explore how English has become the new primary programming language, effectively making everyone a potential developer. Sarit breaks down why relying solely on cloud posture management is no longer enough and why deploying active runtime agents is now mandatory to block real-time exploits.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠⁠Sarit's Linkedin ⁠⁠Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠(00:00) Introduction: The Convergence of Cloud and AppSec(01:50) Sarit Tager's Background: From VP of Engineering to Palo Alto Networks(03:00) Why English is the New Programming Language(06:00) The Problem with LLMs Suggesting AppSec Fixes That Break Functionality(09:30) How AI Agents Can Accidentally Delete Production Databases(11:40) The Attack Window Shrinking to 25-30 Minutes(14:00) The Post-Mythos Fear and the Token Cost Challenge(16:30) Why You Must Deploy a Runtime Agent (Posture is Not Enough)(18:30) Why AI Coding Agents Put Security Second(24:00) Breaking the Silos: The Rise of Holistic Product Security(36:00) How AI Empowers Non-Experts to Investigate Across Security Domains(40:30) Fun Questions: 50 Countries, No Social Media, and Japanese FoodThank you to Palo Alto Networks for sponsoring this episode:Learn more about Palo Alto Networks Cortex Cloud.

Application Security PodCast
Isaac Evans - AppSec in the Age of AI

Application Security PodCast

Play Episode Listen Later Jul 28, 2026 49:09


Send us Fan MailIn this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central security control point, replaced by deep background jobs that hunt for vulnerabilities using large models and real-time plugins that sit inside coding agents and force them to regenerate code until it meets an organization's security bar. We dig into what this means for the role of the security engineer, why customization is replacing universal rule sets, and how trust, verification, and the limits of reasoning about model behavior remain the hardest problems in the room. We also talk about vibe coding at scale, the return of business logic flaws as SQL injection becomes easier for models to catch, and why Isaac sees more opportunity than threat in this shift, even as he expects a wave of new vulnerabilities and cleanup work along the way.FOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcastThanks for Listening!~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Absolute AppSec
Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies

Absolute AppSec

Play Episode Listen Later Jul 28, 2026


In this episode, sponsored by GuardSquare (guardsquare.com), Ken Johnson and Seth Law discuss OpenAI's reported Hugging Face security incident, questioning whether the model demonstrated genuinely novel offensive capability or mostly chained known vulnerability patterns at high inference cost, while also considering the defense-contract and marketing angles around "dangerous" frontier models. The main technical discussion returns to AppSec fundamentals through an article on preventing IDOR, emphasizing authorization as a core control, the difficulty of role and tenant isolation in complex systems, and the need for framework-level patterns, typed IDs, tenant checks, and thorough authorization testing. They also cover Krebs' reporting on LG banning residential proxy SDKs from smart TV apps, explaining how free TV apps can turn consumer devices into proxy infrastructure and why IoT app ecosystems need stronger review. The episode closes with DEF CON logistics, Hacker Tracker updates, and upcoming guest plans.

Relating to DevSecOps
Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

Relating to DevSecOps

Play Episode Listen Later Jul 24, 2026 46:40


Send us Fan MailAI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.

Paul's Security Weekly
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

Paul's Security Weekly

Play Episode Listen Later Jul 21, 2026 72:06


Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system. Resources: https://objective-see.org/blog/blog_0x86.html https://objective-see.org/products/lulu.html https://objectivebythesea.org/v9/index.html Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-392

Paul's Security Weekly TV
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

Paul's Security Weekly TV

Play Episode Listen Later Jul 21, 2026 72:06


Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system. Resources: https://objective-see.org/blog/blog_0x86.html https://objective-see.org/products/lulu.html https://objectivebythesea.org/v9/index.html Show Notes: https://securityweekly.com/asw-392

Application Security Weekly (Audio)
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

Application Security Weekly (Audio)

Play Episode Listen Later Jul 21, 2026 72:06


Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system. Resources: https://objective-see.org/blog/blog_0x86.html https://objective-see.org/products/lulu.html https://objectivebythesea.org/v9/index.html Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-392

Application Security Weekly (Video)
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

Application Security Weekly (Video)

Play Episode Listen Later Jul 21, 2026 72:06


Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system. Resources: https://objective-see.org/blog/blog_0x86.html https://objective-see.org/products/lulu.html https://objectivebythesea.org/v9/index.html Show Notes: https://securityweekly.com/asw-392

Absolute AppSec
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

Absolute AppSec

Play Episode Listen Later Jul 14, 2026


In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture Management (ASPM) consolidation. Cameron strongly advocates for utilizing ASPM as a distinct, single pane of glass dashboard to deduplicate vulnerabilities and streamline executive reporting by product suite. However, the hosts contrast this ideal against the messy reality of organizations dealing with a "Frankenstein" mix of loosely bootstrapped open-source scanning tools and competing vendor plugins. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. Cameron and Kurt stress the necessity of shifting away from abstract CVSS scores toward custom, runtime-informed risk appetites and impact analysis—prioritizing the hardening of high-risk corporate assets over low-reachability internal flaws. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. Ultimately, the panel laments that AppSec teams are effectively functioning as corporate incident responders because Security Operations Center (SOC) analysts lack product-level insight. The episode concludes with a review of automated agent statistics and a fun look ahead to the future emergence of meta OWASP top-ten risk lists.

Resilient Cyber
Building an AI AppSec Engineer

Resilient Cyber

Play Episode Listen Later Jul 11, 2026 31:04


JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

Cloud Security Podcast
The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

Cloud Security Podcast

Play Episode Listen Later Jul 9, 2026 42:44


Traditional SCA and SAST tools are notorious for drowning security teams in false positives, historically flagging nine out of ten alerts incorrectly. But while generative AI seems like a magic bullet, simply wrapping an out-of-the-box LLM around your code can result in confident hallucinations and astronomical costs extrapolating to as much as $52 million a year for a large enterprise using frontier models.In this episode, Ashish sits down with Harry Wetherald, CEO and co-founder of Maze, to discuss the evolution of AI-native AppSec and Cloud Security. Harry breaks down the critical difference between vulnerability reachability (is the code active?) and true exploitability (can an attacker actually trigger it logically?). He also explains why the historical walls between cloud security and application security teams are finally crumbling as AI acts as a perfect translator between the two domains.If your team is debating "Build vs. Buy" for AI security tools, this episode is essential. Harry shares the biggest red flags to watch out for in AI vendors (beware the "black box"), how to intelligently route across models to optimize token costs by 100x, and how a true "security brain" orchestrates multiple investigations to provide reliable context across your entire environment.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠Harry's Linkedin ⁠Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction to AI in AppSec(01:50) Harry Wetherald's Background and the Founding of Maze(02:30) Reachability vs. Exploitability Explained(04:45) The "Build vs. Buy" Dilemma for AI Security Tools(08:30) Bridging the Gap Between Siloed AppSec and CloudSec Teams(11:30) Evaluating Out-of-the-Box LLMs vs. Specialized Security Tools(14:20) Solving the Historic AppSec False Positive Problem(18:50) AI Vendor Red Flags: The Danger of "Black Box" Products(20:50) How to Build a True AI-Native Security Architecture(24:45) The Hidden Cost of AI Models: Why Optimization is Crucial(28:00) When to Keep a Human in the Loop for Remediation(34:00) Building a "Security Brain" to Inform AI Coding Agents(39:20) The Launch of Maze Code for Deep Cloud and Code Investigations

Absolute AppSec
Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards

Absolute AppSec

Play Episode Listen Later Jul 7, 2026


In episode 326 of Absolute AppSec, sponsored by mobile application security provider GuardSquare (guardsquare.com), the hosts start with a deep-dive into pre-show discussions about the shifting macroeconomic landscape of AppSec jobs. They analyze an industry-wide trend where corporate hiring is pivoting away from external third-party consultancies and contractors. Instead, maturing organizations are forming internal product security "tiger teams" and hiring dedicated security software engineers across general development lifecycles to handle the exponential volume of code generated by artificial intelligence. Turning to AI-driven engineering, they dissect a research paper tracking security vulnerability mitigations through large language model (LLM) feedback. The paper reveals a distinct degradation in code quality and an explosion of "false positives" or unreachable flaws after the fourth or fifth iteration due to compressed context windows and "context drift." Ken highlights his own grueling experience benchmarking AINative software. He heavily cautions that letting models self-score or automatically review code introduces dangerous biases, reinforcing the absolute baseline requirement for humans to critically audit all LLM outputs. Finally, they examine Open Web Docs' new web security guidelines community group, comparing its browser-centric standard party focus to OWASP's broader, audit-driven charter. They close by promoting an upcoming July podcast collaboration with Coffee, Chaos, and ProdSec.

Paul's Security Weekly
How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388

Paul's Security Weekly

Play Episode Listen Later Jun 23, 2026 70:01


Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus on actions can be more effective than roles. One of the biggest challenges in securing agents along with all of the other identities that organizations manage is how fragmented that management has become. But a unified engineering view of identities is just a start. Once you're able to shift to a practice where access is granted based on attributes and limited durations, then your environment becomes more resilient to mistakes and unexpected actions, not to mention the security concerns that come with agents acting on their own. Who Is Responsible for an AI Agent's Actions? As AI agents gain the ability to access systems, invoke tools, and take action on behalf of users, organizations need clear frameworks that define responsibility for machine-driven decisions and outcomes. This segment examines how accountability, delegation, and attribution can be established across users, developers, security teams, and business stakeholders. Neha will explore how governance models support transparent, auditable agent-driven workflows while helping organizations manage risk and maintain trust. This segment is sponsored by P0 Security. Visit https://securityweekly.com/p0idv to learn more about them! The rapid rise of agentic AI and non-human identities is fundamentally reshaping the future of identity security, challenging traditional IAM and PAM models built around predictable human behavior. In this executive interview at Identiverse 2026, Amit Masand discusses how autonomous systems, AI agents, and machine identities are creating new operational and governance challenges for modern enterprises. Drawing from more than two decades of industry experience, the conversation explores the growing complexity of continuous governance in a world where identities increasingly operate at machine speed. Segment Resources: https://www.idmexpress.com/post/preventing-cybersecurity-incidents-through-managed-services https://www.idmexpress.com/post/cyberark-securing-aws https://www.idmexpress.com/post/turning-roadblocks-into-breakthroughs-a-custom-oracle-pam-integration-story Contact IDMEXPRESS! Secure Your Tomorrow, Today: https://securityweekly.com/idmidv Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-388

Paul's Security Weekly TV
How AI Is Reshaping Identity Security at the Infrastructure Layer - Ev Kontsevoy, Neha Duggal, Amit Masand - ASW #388

Paul's Security Weekly TV

Play Episode Listen Later Jun 23, 2026 70:01


Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus on actions can be more effective than roles. One of the biggest challenges in securing agents along with all of the other identities that organizations manage is how fragmented that management has become. But a unified engineering view of identities is just a start. Once you're able to shift to a practice where access is granted based on attributes and limited durations, then your environment becomes more resilient to mistakes and unexpected actions, not to mention the security concerns that come with agents acting on their own. Who Is Responsible for an AI Agent's Actions? As AI agents gain the ability to access systems, invoke tools, and take action on behalf of users, organizations need clear frameworks that define responsibility for machine-driven decisions and outcomes. This segment examines how accountability, delegation, and attribution can be established across users, developers, security teams, and business stakeholders. Neha will explore how governance models support transparent, auditable agent-driven workflows while helping organizations manage risk and maintain trust. This segment is sponsored by P0 Security. Visit https://securityweekly.com/p0idv to learn more about them! The rapid rise of agentic AI and non-human identities is fundamentally reshaping the future of identity security, challenging traditional IAM and PAM models built around predictable human behavior. In this executive interview at Identiverse 2026, Amit Masand discusses how autonomous systems, AI agents, and machine identities are creating new operational and governance challenges for modern enterprises. Drawing from more than two decades of industry experience, the conversation explores the growing complexity of continuous governance in a world where identities increasingly operate at machine speed. Segment Resources: https://www.idmexpress.com/post/preventing-cybersecurity-incidents-through-managed-services https://www.idmexpress.com/post/cyberark-securing-aws https://www.idmexpress.com/post/turning-roadblocks-into-breakthroughs-a-custom-oracle-pam-integration-story Contact IDMEXPRESS! Secure Your Tomorrow, Today: https://securityweekly.com/idmidv Show Notes: https://securityweekly.com/asw-388

Application Security Weekly (Audio)
How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388

Application Security Weekly (Audio)

Play Episode Listen Later Jun 23, 2026 70:01


Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus on actions can be more effective than roles. One of the biggest challenges in securing agents along with all of the other identities that organizations manage is how fragmented that management has become. But a unified engineering view of identities is just a start. Once you're able to shift to a practice where access is granted based on attributes and limited durations, then your environment becomes more resilient to mistakes and unexpected actions, not to mention the security concerns that come with agents acting on their own. Who Is Responsible for an AI Agent's Actions? As AI agents gain the ability to access systems, invoke tools, and take action on behalf of users, organizations need clear frameworks that define responsibility for machine-driven decisions and outcomes. This segment examines how accountability, delegation, and attribution can be established across users, developers, security teams, and business stakeholders. Neha will explore how governance models support transparent, auditable agent-driven workflows while helping organizations manage risk and maintain trust. This segment is sponsored by P0 Security. Visit https://securityweekly.com/p0idv to learn more about them! The rapid rise of agentic AI and non-human identities is fundamentally reshaping the future of identity security, challenging traditional IAM and PAM models built around predictable human behavior. In this executive interview at Identiverse 2026, Amit Masand discusses how autonomous systems, AI agents, and machine identities are creating new operational and governance challenges for modern enterprises. Drawing from more than two decades of industry experience, the conversation explores the growing complexity of continuous governance in a world where identities increasingly operate at machine speed. Segment Resources: https://www.idmexpress.com/post/preventing-cybersecurity-incidents-through-managed-services https://www.idmexpress.com/post/cyberark-securing-aws https://www.idmexpress.com/post/turning-roadblocks-into-breakthroughs-a-custom-oracle-pam-integration-story Contact IDMEXPRESS! Secure Your Tomorrow, Today: https://securityweekly.com/idmidv Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-388

To The Point - Cybersecurity
AppSec Needs AI Employees, Not More Tools with Shan Kulkarni

To The Point - Cybersecurity

Play Episode Listen Later Jun 16, 2026 29:48


Absolute AppSec
Episode 324 - Three Week Trap, Malicious Extensions

Absolute AppSec

Play Episode Listen Later Jun 16, 2026


In episode 324 of Absolute AppSec, co-hosts Ken Johnson and Seth Law share a mix of security model critiques. Starting with industry dynamics, Ken recaps his recent presentation at OWASP Nova regarding the limits of human-scale AppSec, recounting a dramatic storm during the talk where patio chairs pelted the high-rise glass. The conversation pivots sharply to Anthropic being forced to pull its "Fable" and "Mythos" cybersecurity models offline due to government sanctions and fears surrounding unpreventable universal jailbreaks. Ken and Seth criticize the company's disingenuous "FUD-based" marketing, which falsely suggested that AI could entirely replace security practitioners. Seth reviews his own blog post regarding the "three-week demo trap", detailing critical, ignored requirements for AI products—such as evaluation, statistical reproducibility, and token cost economics—noting that executing enterprise testing via frontier models can easily exceed $5,000 a day. Transitioning back to fundamental baseline defense, the hosts dissect an article on bypassing Visual Studio Code extension blocks. They emphasize that since modern CDNs pull zipped extensions from distinct domains, blocking the main marketplace URL is completely ineffective. Consequently, they advocate for rigorous data classification, layered on-premise model hosting, and stricter boundary controls on developer endpoints to combat fast-evolving supply chain threats.

Telecom Reseller
Checkmarx on Next-Generation SAST and the Channel Opportunity, Podcast

Telecom Reseller

Play Episode Listen Later Jun 15, 2026 11:45


By Doug Green “AI is generating code, but it's not generating secure code.” In this episode of the Technology Reseller News podcast, Doug Green speaks with Jonathan Kozimor, Vice President of Channel Americas at Checkmarx, about the company's next-generation SAST engine and the growing opportunity for MSPs and channel partners in application security. Kozimor says software development has changed dramatically. Developers are producing more code, AI is accelerating that process, and traditional security models are struggling to keep up. The old approach of writing code, scanning it, and fixing issues later is no longer enough. Checkmarx's new SAST engine is designed to reduce noise, false positives, and lack of context by helping teams focus on the vulnerabilities that matter most. “The industry does not need more vulnerability data,” Kozimor says. “Security teams already have plenty of findings. What they need is intelligence, and they need faster fixes.” The podcast also explores findings from recent Checkmarx research, including the gap between security awareness and execution. Kozimor notes that many organizations understand the risks, but still struggle to operationalize security at the speed of modern development. Looking ahead, Kozimor says AppSec must become more automated, more intelligent, and more deeply embedded in the development lifecycle. AI will play a role, but it must be paired with governance, security policy, and human oversight. For channel partners, the opportunity is clear. Customers need help modernizing AppSec, managing change, and embedding security into development workflows without slowing innovation. “This is where the partner ecosystem is fundamental to customer success,” Kozimor says. Learn more at www.checkmarx.com

No Password Required
No Password Required Podcast Episode 73 - Mudita Khurana

No Password Required

Play Episode Listen Later Jun 9, 2026 28:13


Show Summary:    Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this” No Password Required Season 7: Episode 6 - Mudita Khurana   Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team. In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months. Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to. In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas.   Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/     In this episode: Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37) The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00) Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23) The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41) Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29) How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26) The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47) Mudita's favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13) Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36) Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21) Timestamp Highlights: (00:25) Mudita's 10-year journey into cybersecurity starting from India (02:26) Mentorship's critical role in her growth and her admiration for Vandana Verma (09:29) Transition from management back to technical roles and why staying close to the work matters (15:31) How AI fosters layered, modular security systems for faster adaptation (17:06) The importance of community and trusted information sources in security (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days (25:19) Leh, Ladakh: Mudita's ideal remote work location nestled in Himalayan beauty Resources & Links: Vandana Verma - Influential mentor in cybersecurity ThreatLocker - Supporter of this podcast Cyber Florida – The Mother Ship

Application Security PodCast
Josh Grossman--AI & SAST: Is it a match?

Application Security PodCast

Play Episode Listen Later Jun 2, 2026 40:29


AI coding tools are accelerating development fast, but they're also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. FOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcastThanks for Listening!~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Resilient Cyber
Securing the Agentic SDLC

Resilient Cyber

Play Episode Listen Later May 29, 2026 49:24


In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle.We dive into:

Smart Software with SmartLogic
The State of Code Quality with Saša Jurić

Smart Software with SmartLogic

Play Episode Listen Later May 28, 2026 55:33


In this episode of Elixir Wizards, hosts Charles Suggs and Emma Whamond sit down with Saša Jurić, Elixir mentor and author of Elixir in Action, to discuss software craftsmanship in the age of AI. As AI coding tools become increasingly capable, Saša argues that the real challenge isn't generating code, it's maintaining quality, clarity, and shared understanding within a codebase. We explore the difference between correct code and good code, and why code is more than a set of instructions for a machine to execute. Code is also documentation, communication, and a long-term investment that future developers must be able to understand and maintain. Saša shares his concerns about the growing "theater of pull requests," where teams go through the motions of code review without creating meaningful opportunities for learning, feedback, or knowledge sharing. The hosts and Saša talk about practical ways to work effectively with AI, including taking smaller steps, carefully reviewing AI-generated code, and using AI as a collaborative tool rather than an autonomous developer. Throughout the discussion, Saša challenges the industry's obsession with speed and makes the case that the principles of good software development (incremental progress, clear communication, and human judgment) remain important in the age of AI. Key Topics Discussed The difference between correct code and good code Code as communication, documentation, and shared understanding The "theater of pull requests" and ineffective review practices How AI is changing software development workflows Using AI as a collaborator rather than a replacement Why smaller, incremental changes lead to better outcomes Human oversight in AI-assisted development Balancing development speed with maintainability Pull request size and review effectiveness Commit history as a tool for storytelling and context The risks of accumulating technical debt faster with AI Testing and validating AI-generated code Refactoring AI-generated solutions for clarity Applying agile principles to AI-assisted workflows The role of experience and judgment in software design Why software craftsmanship still matters in the age of AI Links mentioned Code Complete by Steve McConnell https://khmerbamboo.wordpress.com/wp-content/uploads/2014/09/code-complete-2nd-edition-v413hav.pdf Harness AI for DevOps, Testing, and AppSec https://www.harness.io/ Claude Code https://claude.com/product/claude-code Claude Code GitHub https://github.com/anthropics/claude-code Pull Request for Oban https://github.com/oban-bg/oban/pull/331 SMPP https://en.wikipedia.org/wiki/Short_Message_Peer-to-Peer OpenAI Codex https://chatgpt.com/codex/ Opus AI https://opus.ai/ Tidewave https://tidewave.ai/ Credo Static Code Analysis https://github.com/rrrene/credo https://smartlogic.io/podcast/elixir-wizards/s11-e09-static-code-analyzer-elixir-credo-ruby-rubocop/ Link to Sasa's X post https://x.com/sasajuric/status/2029522378196238503 Saša Jurić “Tell Me A Story” at Goatmire https://www.youtube.com/watch?v=GOrKfCs-mr0 https://meks.quest/blogs/the-theatre-of-pull-requests-and-code-review Looks Good to Me: Constructive Code Reviews by Adrienne Braganza https://www.manning.com/books/looks-good-to-me Towards Maintainable Elixir: Testing https://medium.com/very-big-things/towards-maintainable-elixir-testing-b32ac0604b99 TDD, Where Did It All Go Wrong (Ian Cooper) https://youtu.be/EZ05e7EMOLMSpecial Guest: Saša Jurić.

Paul's Security Weekly
AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384

Paul's Security Weekly

Play Episode Listen Later May 26, 2026 59:40


We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project's latest research, including new landscape guides and evolving approaches to securing generative and agentic AI systems. The conversation explores critical gaps in GenAI data security, the rise of AI-assisted development, and the immense growth of the OWASP community and sponsor ecosystem. Looking ahead, he outlines the most urgent risks and priorities shaping AI and agentic security in 2026. Then Merritt Maxim discusses how AI is affecting Identity and Access Management. Expect to hear this topic a lot throughout 2026, especially as the industry tries to figure out what's different or special about securing agent identities. We close with a chat with Janet Worthington about the impact of agents on the SDLC and how orgs are updating their controls to deal with code generated by humans and LLMs alike. Segment Resources: https://genai.owasp.org https://genai.owasp.org/resources/ https://www.scworld.com/podcast-episode/3905-keeping-up-with-the-owasp-genai-project-scott-clinton-asw-381 This segment is sponsored by The OWASP GenAI Security Project. Visit https://securityweekly.com/owasp to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-384

Paul's Security Weekly TV
AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Scott Clinton, Janet Worthington, Merritt Maxim - ASW #384

Paul's Security Weekly TV

Play Episode Listen Later May 26, 2026 59:40


We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project's latest research, including new landscape guides and evolving approaches to securing generative and agentic AI systems. The conversation explores critical gaps in GenAI data security, the rise of AI-assisted development, and the immense growth of the OWASP community and sponsor ecosystem. Looking ahead, he outlines the most urgent risks and priorities shaping AI and agentic security in 2026. Then Merritt Maxim discusses how AI is affecting Identity and Access Management. Expect to hear this topic a lot throughout 2026, especially as the industry tries to figure out what's different or special about securing agent identities. We close with a chat with Janet Worthington about the impact of agents on the SDLC and how orgs are updating their controls to deal with code generated by humans and LLMs alike. Segment Resources: https://genai.owasp.org https://genai.owasp.org/resources/ https://www.scworld.com/podcast-episode/3905-keeping-up-with-the-owasp-genai-project-scott-clinton-asw-381 This segment is sponsored by The OWASP GenAI Security Project. Visit https://securityweekly.com/owasp to learn more about them! Show Notes: https://securityweekly.com/asw-384

Application Security Weekly (Audio)
AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384

Application Security Weekly (Audio)

Play Episode Listen Later May 26, 2026 59:40


We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project's latest research, including new landscape guides and evolving approaches to securing generative and agentic AI systems. The conversation explores critical gaps in GenAI data security, the rise of AI-assisted development, and the immense growth of the OWASP community and sponsor ecosystem. Looking ahead, he outlines the most urgent risks and priorities shaping AI and agentic security in 2026. Then Merritt Maxim discusses how AI is affecting Identity and Access Management. Expect to hear this topic a lot throughout 2026, especially as the industry tries to figure out what's different or special about securing agent identities. We close with a chat with Janet Worthington about the impact of agents on the SDLC and how orgs are updating their controls to deal with code generated by humans and LLMs alike. Segment Resources: https://genai.owasp.org https://genai.owasp.org/resources/ https://www.scworld.com/podcast-episode/3905-keeping-up-with-the-owasp-genai-project-scott-clinton-asw-381 This segment is sponsored by The OWASP GenAI Security Project. Visit https://securityweekly.com/owasp to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-384

Paul's Security Weekly
The State of AI & AppSec - Keith Hoodlet - ASW #383

Paul's Security Weekly

Play Episode Listen Later May 19, 2026 62:56


This year has been a dichotomy of established secure design fundamentals and burgeoning chaos of LLM-driven vuln discovery. Keith Hoodlet returns to share his latest observations on what the recent news about Mythos, models, and harnesses means for appsec. He walks through the problems of misalignment, the potential development doom that looms behind a volume of vulns, and what modern code creation looks like. Along the way we touch on the economics of tokens and the principles behind secure software. Keith gave a preview of his upcoming presentation (May 22nd) on these topics. Check out https://securing.dev/about/ for the slides and more of his writing on appsec. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-383

mythos llm appsec keithhoodlet