"The era of code review is coming to an end."
@manicode on why humans reviewing code will hurt your company, token furnaces, and the one truly new vulnerability class of the AI era.
New episode is live.
#AppSec#AIappsecpodcast.com/why-ai-cod…
My first podcast was on March 17, 2017. I had no idea what I was doing or getting myself into. But as I'm getting ready to celebrate my 500th show, 9 1/2 years later, I wanted to give a special shout out to my first-ever guest: Chris Romeo! @edgeroute#FDSD500
Can AI learn ethics—or can it only learn rules?
A model may know that an action is prohibited without understanding why it is wrong.
Does that distinction matter?
#AISecurity#AIEthics#TheSecurityTable
AI pentesting isn't automatically cheap.
@JamesBerthoty on how token costs balloon fast with frontier models — and why efficiency, not raw capability, may be the real moat for AI-native security vendors.
“If we don’t do something about this, the senior programmers of today will be the last of their kind.”
If AI writes the code, how will the next generation develop the skills needed to understand and review it?
Traditional DAST runs predefined checks.
AI pentesting can generate contextual tests based on how an application actually works.
@JamesBerthoty explores autonomy, token costs, bug bounties, and the future of DAST.
Is traditional DAST finally dead?
buff.ly/H3KKjhT
“Fight the AI.”
Not because AI is bad.
Because hitting “accept” every time AI suggests something is an easy way to stop thinking.
Use AI as a coach.
Ask why. Ask it to teach you.
Make it work for you—not the other way around.
AI security has no shortage of standards.
But are they working together?
Rob van der Veer explores responsible AI, agentic red teaming, OWASP, and the industry's need for more coordination.
Do we need more standards—or better alignment?
AI can generate threats.
But can it generate judgment?
Can it recognize that a system shouldn't exist?
Can it bring experience from something that hasn't happened before?
That's where the human-in-the-loop still matters.
First time reporting to a CEO?
3 simple things to learn:
- admit your mistakes. CEOs make even more of them. They get it.
- end excuses. Those don't work anymore.
- when you bring up a problem, make sure you also bring a solution.
Do just this, you'll excel.
New episode 🎙️ Linus says AI is now a real tool for the Linux kernel. Bug bounty platforms are drowning in submissions. We ask: is bug bounty as we know it already dead?
🚀 Does the whole vulnerability economy need a rebuild?
piped.video/qTGRNiNUv-U
Semgrep CEO Isaac Evans joins us to talk about how AI is upending AppSec. CI is losing its place as the control point, coding agents are being forced to regenerate code until it's secure, and business logic flaws might be the next frontier. New episode: piped.video/JKWChbTnkq0
New episode: we dig into Sysdig's "Jade Puffer" report on agentic ransomware. Is this really an LLM adapting on the fly, or a script that looks smart? We break down the evidence and what it means for your threat model. Live now 🎙️ piped.video/o6QtLZ6nTd4
The OWASP Top 10 has been refreshed for 2025. We sat down with Okta's Jose Carlos Chavez to find out why broken access control still tops the list, why injection refuses to die, and why nobody's checking the integrity of the AI skills we're all installing. piped.video/4u8eN2vYh_E
Most people click "Accept."
Matt wants to know exactly how many terms he's about to violate.
A discussion about AI somehow turned into an intervention about reading EULAs. 😂
Watch: piped.video/2P6HVn1eFyc#CyberSecurity#InfoSec#TechHumor
Most people click "Accept."
Matt wants to know exactly how many terms he's about to violate.
A discussion about AI somehow turned into an intervention about reading EULAs. 😂
Watch: piped.video/2P6HVn1eFyc#CyberSecurity#InfoSec#TechHumor
Unpacking agile and threat modeling: Can these practices enhance each other? Join us for an insightful discussion on our latest podcast and discover how they can transform your dev process! Check it out here: piped.video/hluwxvgUFRM#Agile#ThreatModeling#Podcast
Tune into the latest episode of the Security Table as we discuss the controversial proposal of cybersecurity "privateers"! Listen now for a thought-provoking exploration of modern-day cybersecurity tactics! piped.video/iq3q_DU6Sxg#CyberCrime#DigitalDefense