Software supply chain security

The OWASP LLM Top 10 has a few surprises for you

The OWASP LLM Top 10 has a few surprises for you

This podcast episode breaks down the 2026 OWASP LLM Top 10, highlighting a significant rise in concern for 'Excessive Agency' over traditional prompt injection. It explores the discrepancies between practitioner fears and incident data, particularly regarding misinformation, and advocates for viewing security frameworks as tools for operationalization and cyber resilience, not just compliance. The discussion also covers CISA's new SBOM guidance, emphasizing the need to operationalize supply chain data for effective risk reduction, and shares Black Hat 2026 insights on AI agents as a new attack surface, introducing the concept of 'intent collusion' and underscoring the critical need for foundational security principles like least privilege.

AI Is Learning to Hack. Faster Than We Expected.

AI Is Learning to Hack. Faster Than We Expected.

Dylan Ayrey (Truffle Security) and Feross Aboukhadijeh (Socket) join Joel De La Garza to discuss how AI models are now actively exploiting vulnerabilities, not just finding them. The conversation covers AI's role in software supply chain attacks, leaked credentials, zero-day generation, and the urgent need for adaptation in the face of rapidly shrinking vulnerability discovery-to-exploitation times.

Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

Manoj Nair of Snyk reveals alarming data on AI-driven security risks, emphasizing that generative AI and validation systems cannot be the same. He highlights issues like autonomous attacks, rampant vulnerabilities in AI-generated code and skills, and PII leakage. Snyk's solution, Evo, integrates deterministic prevention and remediation to secure the agentic development lifecycle.