Your Opinion on AI Doesn't Matter. Learned Fragility Does
What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E.
Listen to the episodeTopic
Securing systems built on large language models, and what changes when the attacker writes the input and the model writes the code.
What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E.
Listen to the episodeJim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeThree years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeMost fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents.
Listen to the episodeIs traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeAI security has no shortage of standards — the problem is turning them into something a team can actually use.
Listen to the episodeYou don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement…
Listen to the episodeAI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeWhen every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how…
Listen to the episodeTraditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeGitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse?
Listen to the episodeIf AI writes all the code and the developer barely reads it, where does AppSec fit?
Listen to the episodeAI is multiplying the amount of software organizations produce, but security teams are not multiplying with it.
Listen to the episodeOpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy.
Listen to the episodeAppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up.
Listen to the episodeMost products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes…
Listen to the episodeSarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter.
Listen to the episodeWhat happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough?
Listen to the episodeFormer CISO Jim Routh discusses his perspective on retirement and career fulfillment in cybersecurity.
Listen to the episodeSteve Wilson, the author of 'The Developer's Playbook for Large Language Model Security’ is back to dive into topics from his book like AI hallucinations, trust, and the future of AI.
Listen to the episodeEitan Worcel joins the Application Security Podcast, to talk automated code fixes and the role of artificial intelligence in application security.
Listen to the episodeArshan Dabirsiaghi of Pixee joins Robert and Chris to discuss startups, AI in appsec, and Pixee's Codemodder. io.
Listen to the episodeDr. Katarina Koerner, a renowned advisor and community builder with expertise in privacy by design and responsible AI, joins Chris and Robert to delve into…
Listen to the episodeThe first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeHow do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
Listen to the episodeJames Mckee is a developer (MCPDEA) and security advocate (CISSP) whose biggest responsibility is leading developer security practices.
Listen to the episodeRob van der Veer has a 30-year background in software engineering, building AI businesses, creating software, and assessing software.
Listen to the episodeGraham Holmes is the founder and owner of AoP CyberSecurity, LLC whose mission is to enable organizations to “create scalable and effective strategies for trustworthy outcomes.
Listen to the episodeArtificial intelligence can help analyze security data, but the systems using it also need protection themselves.
Listen to the episode