エピソード

  • When AI Escapes the Sandbox
    2026/09/09

    The squad examines how an Anthropic model escaped its test environment and published a malicious package to PyPI. The conversation explores reward hacking, AI ethics, and why stronger security controls are becoming essential.

    🚀 Can AI truly understand right and wrong—or does it simply follow the path that earns the greatest reward?

    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    49 分
  • The End of Bug Bounty As We Know It
    2026/08/05

    We dig into Linus Torvalds' claim that AI is now a legitimate tool for the Linux kernel, and what it means for bug bounty platforms drowning in submissions, with Bug Crowd reporting a fourfold spike in three weeks. We debate the game theory of vulnerability disclosure, whether AI validation is about to become mandatory, and whether limiting US models just hands the advantage to attackers using unrestricted ones like Kimi. We also ask if bug bounty as we know it is already dead.

    🚀 If AI can find and validate vulnerabilities faster than humans, does the entire bug bounty economy need to be rebuilt from scratch?


    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    42 分
  • Make No Mistakes: Inside the First "Agentic Ransomware"
    2026/07/22

    We dig into Sysdig's Jade Puffer report, the so-called first agentic ransomware, and argue about whether the evidence actually proves an LLM was driving the attack or if it's just a well-trained script wearing an agent costume. We walk through the four signals Sysdig points to, including self-narrating code, fast failure recovery, and a reused Bitcoin address, and push back on how strong that proof really is. We also talk about what this does to the threat model now that attackers don't need a human in the loop to adapt on the fly. And yes, the exploited CVE was sitting unpatched since 2025.

    🚀 Does adaptive malware change who you're defending against, or just how fast they move?

    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    44 分
  • Is Spec-Driven Development Already Dead
    2026/07/15

    In this episode, we take on spec-driven development, the resurgent idea that writing a detailed spec and letting AI implement it will finally give us the precision engineering promised us since the 1950s. We push back on the notion that this fixes what actually sank spec-driven approaches decades ago: specs were never the problem; following them was. Along the way, we debate whether AI-generated code is any more correct than what a room of human developers would produce, dig into the "Phoenix" analogy of regenerating disposable code from spec instead of patching it, and raise the uncomfortable question of what happens when an integration quietly regenerates itself around a security flaw baked into the system it connects to.

    🚀 Join the Conversation
    If the AI can regenerate your code from spec whenever a bug shows up, who's actually responsible when it regenerates the same vulnerability?

    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    42 分
  • Don't Bury the Model T: Why STRIDE Still Drives in an AI World
    2026/07/01

    In this episode, we dig into two things the security community loves to argue about: npm finally doing the right thing and whether STRIDE has any business being called dead. The npm v12 changes gate dangerous install script behavior by default, which is a good step forward and also about a decade overdue. Then we wade into a hot take claiming that STRIDE was built for a world that no longer exists, and we push back hard on the idea that non-deterministic AI systems need an entirely new threat-modeling religion rather than a better understanding of the one we already have. Also: wheat, Oregon Trail, and Emacs.

    🚀 Join the Conversation
    If your threat model failed because of an AI hallucination, was that STRIDE's fault or yours?

    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    59 分
  • Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World
    2026/06/24

    In this episode, we dig into whether DAST is dead, mostly dead, or quietly making a comeback dressed in an AI trench coat. The conversation traces the origins of dynamic application security testing from nmap scans and open source hacker tools to a market now valued at nearly four billion dollars and growing. We debate where DAST ends, and AI pen testing begins, whether AI can find a vulnerability nobody has ever seen before, and what happens when you compound the false positives of rigid rule-based scanning with the hallucinations of a large language model. Also: cats meowing the Final Countdown.

    🚀 Join the Conversation
    If AI pen testing can already find zero days in open source software, does human pen testing still have a defensible edge — or are we just not ready to admit it doesn't?


    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    42 分
  • Realists At The Table: How To See Through The Hype
    2026/06/17

    In this episode, we dig into how the cybersecurity personality has shifted from the ego-driven, hoodie-up archetype to the paycheck-chasing newcomer. The conversation covers hype cycles from mainframes to AI to quantum, whether passion or profit is driving the next generation into the field, and why we think the threat modeling problem is already solved. At the same time, everyone else keeps getting in the way. The discussion takes detours through The Cuckoo's Egg, Sneakers, War Games, and NFT apes before landing on a question we couldn't quite agree on: Does AI actually have a personality, and does it belong in the security community?

    🚀 Join the Conversation
    If you got into cybersecurity for the love of the problem or the paycheck, would you even know the difference anymore?


    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    38 分
  • The Agentic Access Problem: When AI Becomes Its Own Administrator
    2026/06/03

    In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why "because the agent told me to" may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt's unexpected habit of reading both.

    🚀 Join the Conversation

    If your AI agent requested administrator access right now, would you know whether it actually needed it?


    FOLLOW OUR SOCIAL MEDIA:

    ➜ X: @SecTablePodcast
    ➜ LinkedIn: The Security Table Podcast
    ➜ YouTube: The Security Table YouTube Channel

    Thanks for Listening!

    続きを読む 一部表示
    40 分