Christian • Husband • Dad • Granddad | CEO, Stealth • GP, @Kerr_Ventures | Host: @AppSecPodcast + @SecTablePodcast | AppSec • Threat Modeling • AI Security

North Carolina
"The era of code review is coming to an end." @manicode on why humans reviewing code will hurt your company, token furnaces, and the one truly new vulnerability class of the AI era. New episode is live. #AppSec #AI appsecpodcast.com/why-ai-cod…
1
2
4
156
Honored to have been part of the beginning of something that has grown to such a wide reach! And you feature so many heavy hitters...
My first podcast was on March 17, 2017. I had no idea what I was doing or getting myself into. But as I'm getting ready to celebrate my 500th show, 9 1/2 years later, I wanted to give a special shout out to my first-ever guest: Chris Romeo! @edgeroute #FDSD500
1
1
179
Can AI learn ethics—or can it only learn rules? A model may know that an action is prohibited without understanding why it is wrong. Does that distinction matter? #AISecurity #AIEthics #TheSecurityTable
1
2
2
34
AI pentesting isn't automatically cheap. @JamesBerthoty on how token costs balloon fast with frontier models — and why efficiency, not raw capability, may be the real moat for AI-native security vendors.
1
1
106
“If we don’t do something about this, the senior programmers of today will be the last of their kind.” If AI writes the code, how will the next generation develop the skills needed to understand and review it?
1
2
116
Great conversation as always with James. He is connected to what is going on in the world of #AI and #AppSec.
Traditional DAST runs predefined checks. AI pentesting can generate contextual tests based on how an application actually works. @JamesBerthoty explores autonomy, token costs, bug bounties, and the future of DAST. Is traditional DAST finally dead? buff.ly/H3KKjhT
1
96
“Fight the AI.” Not because AI is bad. Because hitting “accept” every time AI suggests something is an easy way to stop thinking. Use AI as a coach. Ask why. Ask it to teach you. Make it work for you—not the other way around.
1
1
1
171
AI security has no shortage of standards. But are they working together? Rob van der Veer explores responsible AI, agentic red teaming, OWASP, and the industry's need for more coordination. Do we need more standards—or better alignment?
1
1
3
114
AI can generate threats. But can it generate judgment? Can it recognize that a system shouldn't exist? Can it bring experience from something that hasn't happened before? That's where the human-in-the-loop still matters.
1
2
2
190
First time reporting to a CEO? 3 simple things to learn: - admit your mistakes. CEOs make even more of them. They get it. - end excuses. Those don't work anymore. - when you bring up a problem, make sure you also bring a solution. Do just this, you'll excel.
15
11
139
12,880
New episode 🎙️ Linus says AI is now a real tool for the Linux kernel. Bug bounty platforms are drowning in submissions. We ask: is bug bounty as we know it already dead? 🚀 Does the whole vulnerability economy need a rebuild? piped.video/qTGRNiNUv-U
1
1
49
Semgrep CEO Isaac Evans joins us to talk about how AI is upending AppSec. CI is losing its place as the control point, coding agents are being forced to regenerate code until it's secure, and business logic flaws might be the next frontier. New episode: piped.video/JKWChbTnkq0
1
1
104
New episode: we dig into Sysdig's "Jade Puffer" report on agentic ransomware. Is this really an LLM adapting on the fly, or a script that looks smart? We break down the evidence and what it means for your threat model. Live now 🎙️ piped.video/o6QtLZ6nTd4
3
2
49
The OWASP Top 10 has been refreshed for 2025. We sat down with Okta's Jose Carlos Chavez to find out why broken access control still tops the list, why injection refuses to die, and why nobody's checking the integrity of the AI skills we're all installing. piped.video/4u8eN2vYh_E
2
5
759
Perhaps the most fun and least-known security podcast around today. You just never know where we'll end up. (This is because we don't know either.)
Most people click "Accept." Matt wants to know exactly how many terms he's about to violate. A discussion about AI somehow turned into an intervention about reading EULAs. 😂 Watch: piped.video/2P6HVn1eFyc #CyberSecurity #InfoSec #TechHumor
2
3
89
Most people click "Accept." Matt wants to know exactly how many terms he's about to violate. A discussion about AI somehow turned into an intervention about reading EULAs. 😂 Watch: piped.video/2P6HVn1eFyc #CyberSecurity #InfoSec #TechHumor
2
2
203
Is the CIA Triad outdated in tackling today's threats? Join the lively debate with Chris, Matt, and Izar at the Security Table! Listen here: piped.video/-donEuQId0o #Cybersecurity #CIAtriad #TheSecurityTablePodcast
2
2
92
Unpacking agile and threat modeling: Can these practices enhance each other? Join us for an insightful discussion on our latest podcast and discover how they can transform your dev process! Check it out here: piped.video/hluwxvgUFRM #Agile #ThreatModeling #Podcast
3
4
116
Tune into the latest episode of the Security Table as we discuss the controversial proposal of cybersecurity "privateers"! Listen now for a thought-provoking exploration of modern-day cybersecurity tactics! piped.video/iq3q_DU6Sxg #CyberCrime #DigitalDefense
2
3
92