『Absolute AppSec』のカバーアート

Absolute AppSec

Absolute AppSec

著者: Ken Johnson and Seth Law
無料で聴く

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
エピソード
  • Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit
    2026/09/01
    In episode 332, the discussion focuses on how artificial intelligence is reshaping the Software Development Lifecycle (SDLC). The episode analyzes Anthropic's blog post regarding an "AI-native SDLC," evaluating its vision of replacing traditional development bottlenecks with AI workflows. The commentary critiques Anthropic's reliance on simple Markdown files for tracking development decisions, noting that replacing deterministic tools with probabilistic LLMs in core SDLC processes introduces significant reliability risks, context drift, and excessive token costs. The conversation turns to OpenAI's "Collective Call for Cyber Defense" initiative, examining its push for frontier AI model regulation and critiques of open-weight models, which are viewed as an effort to establish vendor lock-in. Exploring the concept of "Rumor as the Exploit," the discussion highlights how public mentions or minor disclosures of vulnerabilities now allow AI-driven testing harnesses to rapidly discover and generate working exploits across unmaintained software ecosystems. To counter this accelerated threat landscape, the episode evaluates defensive strategies, including runtime verification, reachability analysis, and cooling-off periods for new package releases, emphasizing that security defenders must move beyond thin wrapper solutions and build robust systems combining deterministic controls with model capabilities. Episode sponsored by Guardsquare (guardsquare.com).
    続きを読む 一部表示
    1分未満
  • Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks
    2026/08/25
    Sponsored by Guardsquare (guardsquare.com), Episode 331 focuses heavily on the growing role of AI agents in application security and how organizations should build and defend against agentic systems. Ken and Seth argue that effective AI security systems should combine deterministic tooling with the probabilistic reasoning of LLMs rather than handing an entire security workflow to a model. Deterministic steps can map repositories, identify dependencies, reconstruct code relationships, and narrow the areas requiring investigation, while LLMs provide reasoning and creativity where those capabilities add value. Preparing for AI-assisted attackers, emphasizing secure development practices, guardrails, sandboxing, pre-production testing, and faster detection and response. The episode also examines HTTP request smuggling and CRLF-based attacks, including how differences in request parsing between proxies and backend services can create authorization bypasses and other exploit chains. Seth and Ken emphasize identifying the critical vulnerability within an exploit chain and discuss how service-oriented architectures can increase risk when components interpret the same request differently. Finally, they question whether bug bounty programs adequately reward researchers for discovering complex, high-impact vulnerabilities, especially as AI agents increasingly automate vulnerability discovery.
    続きを読む 一部表示
    1分未満
  • Episode 330 - w/ Jeevan Singh - Vulnerability Jail
    2026/08/18
    In this special episode of Absolute AppSec, we cover a topic which started as a solution proposed by Rippling Security's Jeevan Singh: Vulnerability Jail. As Jeevan describes it: "In this new AI world, we have seen many more vulnerabilities, and we struggled to get Engineering to fix them all in a timely fashion. This changed when we created Vulnerability Jail. If any vulnerability goes over SLA, your team is placed in Jail, preventing them from merging PRs into the main/default branches. We implemented Vulnerability Jail, updated our SLAs and got buy-in from Eng Leadership for our new Vulnerability Management program. As a result, we have now fixed the same number of vulnerabilities in one month as the team did in the previous year. The speed is still accelerating."" What do we think of the Stick approach to Vuln Management? What are the solutions to the rapid production by AI as well as the vulnpocalypse, Alex Gaynor's term to describe the way that "new technological innovation enables (or indirectly results in) finding a very large number of vulnerabilities in pre-existing software, which renders all previous assumptions and beliefs about the volume of extant vulnerabilities incorrect." Will "Vulnerability Jail" save us from the vulnpocalypse? Episode sponsored by GuardSquare (guardsquare.com)
    続きを読む 一部表示
    1分未満
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません