Open source security

AI Is Learning to Hack. Faster Than We Expected.

AI Is Learning to Hack. Faster Than We Expected.

Dylan Ayrey (Truffle Security) and Feross Aboukhadijeh (Socket) join Joel De La Garza to discuss how AI models are now actively exploiting vulnerabilities, not just finding them. The conversation covers AI's role in software supply chain attacks, leaked credentials, zero-day generation, and the urgent need for adaptation in the face of rapidly shrinking vulnerability discovery-to-exploitation times.

GPT-Red: Can AI read teams stop prompt injections?

GPT-Red: Can AI read teams stop prompt injections?

This podcast explores AI's impact on cybersecurity, discussing OpenAI's GPT-Red for automated red-teaming against prompt injections, the open-source ScamBuster that uses AI to bait scammers for threat intelligence, and Bruce Schneier's insights on the widening gap between skill and ability in the AI era and its ethical implications for the field.

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

This podcast explores the implications of open-weight AI models like GLM-5.2 for cybersecurity, CISA's new four-variable vulnerability prioritization model, the rise of AI-assisted 'vibe hunting,' and the commercial launch of IBM and Red Hat's Lightwell for securing open-source software. It highlights the tension between AI capabilities for attackers and defenders, the challenges of rapid vulnerability remediation, and the need for new "trust infrastructures" in the AI era.

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

Jack Cable discusses the "AI bug apocalypse" driven by advanced AI models finding and exploiting vulnerabilities and AI coding tools increasing attack surfaces. He champions a "secure by design" approach, advocating for systemic changes like using memory-safe languages to prevent common vulnerability classes rather than just patching. He also addresses AI's role in introducing new vulnerabilities, the shift towards autonomous AI in development, and policy recommendations for securing the future of AI-powered coding.