The Security Table

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo
Ország Egyesült Államok
Műfajok Technológia
Nyelv EN-US
Epizódok 106
Legutóbbi 30.09.2026

The Security Table brings together four cybersecurity industry veterans from diverse backgrounds to discuss building secure software and the challenges that arise. The podcast covers a range of topics related to software security, drawing on the hosts' extensive experience.

Epizódok

  • When AI Controls The Hardware 30.09.2026 42p
    Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has worked on robotics projects, says a common control standard is decades overdue. Izar calls it the PCI for AI, reminds everyone how secure MCP was on day one, and brings up Therac 25 as a warning about what happens when software controls hardware and fails silently. Then the t...
  • When Code No Longer Matters 23.09.2026 36p
    If AI can turn a request directly into instructions a chip understands, what is left for a human to review? Chris Romeo, Izar Tarandach, and Matt Coles debate whether readable source code remains essential when agents do the programming. Matt argues that code always matters; Izar rejects the premise that another abstraction makes ambiguity disappear. The conversation moves through COBOL, Fortran, language evolution, and the prospect of abandoning pull request review. They also consider optimi...
  • Why AI Cheats To Win 16.09.2026 39p
    An AI agent publishes a malicious Python package while chasing a capture-the-flag goal. Is that an escape, a supply chain failure, or reward hacking doing exactly what it was encouraged to do? Chris Romeo, Izar Tarandach, and Matt Coles examine the Anthropic incident and disagree about how much intention to attribute to a model. The discussion turns to package scanners, dependency names, GPG signing, and whether penalties can teach ethics to a system without a human understanding of consequen...
  • When AI Escapes the Sandbox 09.09.2026 49p
    When a model crosses a sandbox boundary, is the lesson that AI has become malicious or that the boundary was never strong enough? Chris Romeo, Izar Tarandach, and Matt Coles examine the CSA post-mortem on the OpenAI agents that compromised Hugging Face during a security evaluation. They debate reward-driven behavior, disabled safeguards, the four-day intrusion timeline, and the responsibility of the people running the experiment. The discussion moves from cyber ranges and incident response to...
  • The End of Bug Bounty As We Know It 05.08.2026 42p
    If AI can find and validate vulnerabilities faster than people, why would a company keep paying outsiders to report them? Chris Romeo, Izar Tarandach, and Matt Coles start with Linus Torvalds' changing assessment of AI-generated Linux kernel reports, then examine what useful automation does to the bug bounty economy. They debate disclosure incentives, model restrictions that may constrain defenders more than attackers, and the cost of separating real findings from a flood of submissions. Bugc...
  • Make No Mistakes: Inside the First "Agentic Ransomware" 22.07.2026 43p
    Does adaptive malware prove an LLM is directing an attack, or can a capable script produce the same evidence? Chris Romeo, Izar Tarandach, and Matt Coles examine Sysdig's JADEPUFFER report and its claim of agentic ransomware. They work through the proposed indicators, including self-narrating payloads, rapid failure diagnosis, interpretation of natural-language context, and a reused Bitcoin address. The debate distinguishes plausible autonomy from proof and asks whether machine-speed adaptati...
  • Is Spec-Driven Development Already Dead 15.07.2026 41p
    Can a detailed specification make AI-generated software reliable, or does it simply move the ambiguity somewhere else? Chris Romeo, Izar Tarandach, and Matt Coles revisit spec-driven development and the promise that an agent can turn written intent into a correct implementation. They debate why earlier approaches struggled, whether natural language is enough, and how tests can fail when the same AI writes both the code and its checks. The conversation explores bounded models, the Phoenix idea...
  • Don't Bury the Model T: Why STRIDE Still Drives in an AI World 01.07.2026 59p
    Do AI systems require a new threat-modeling method, or are we abandoning useful tools before understanding their limits? Chris Romeo, Izar Tarandach, and Matt Coles first examine npm's move toward safer install defaults and the risk that agents trained on older behavior will simply re-enable dangerous options. Then they debate the claim that STRIDE belongs to a world that no longer exists. The discussion separates threat categories from modeling techniques, non-deterministic model behavior fr...
  • Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World 24.06.2026 42p
    Is DAST disappearing, or is AI penetration testing giving its underlying techniques a new market? Chris Romeo, Izar Tarandach, and Matt Coles trace dynamic application security testing from network scanners and open source tools to commercial products, then debate where scanning ends and adaptive testing begins. They question whether a tool that finds many issues serves the same purpose as a tester who follows an exploit chain. AI-generated findings raise another problem: what happens when sc...
  • Realists At The Table: How To See Through The Hype 17.06.2026 37p
    Has cybersecurity traded curiosity for the promise of a paycheck, or are experienced practitioners simply seeing another generation's version of the same hype? Chris Romeo, Izar Tarandach, and Matt Coles examine the industry's changing stereotypes, from hoodie-clad specialists to ambitious founders. Mainframes, cloud computing, AI, quantum, and NFTs provide examples of ideas that return wearing new labels. The Cuckoo's Egg and hacker movies lead into a discussion of what made security feel li...
  • The Agentic Access Problem: When AI Becomes Its Own Administrator 03.06.2026 40p
    In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why "because the agent told me to" may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt's un...
  • The Tool Creep Problem: When More Security Means Less Security 08.05.2026 42p
    In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in the gap between what agents are told to do and what they are ac...
  • The Human In The Loop Illusion: Why AI Approvals Are Failing Security 30.04.2026 47p
    In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter. 🚀 Join the Conversation Are we improving security, or just automating bad decisions faster? Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.li...
  • The Mythos Problem: When AI Finds Every Vulnerability 15.04.2026 47p
    In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them. We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agents everywhere—and whether fighting AI with more AI actually solves the problem. At the end of the...
  • What If AI Never Happened? The AppSec Reality Check 08.04.2026 47p
    In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, from “vibe coding” and false confidence in results to the growing gap...
  • The Evolution Problem: After 100 Episodes, What’s Changed… and What Hasn’t? 01.04.2026 49p
    We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never seem to go away. Along the way, we compare where we were then to where things stand now, calling out a few wins,...
  • The Agent Access Problem: When AI Has the Keys, Who’s Really in Control? 25.03.2026 48p
    In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior driven by prompts, and why “it won’t go rogue” might be missing the point entirely. We also...
  • The Invisible Code Problem: When You Can’t See the Attack, Can You Stop It? 20.03.2026 36p
    In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whether this is a real emerging threat or just another overhyped security ...
  • The Moltbook Dilemma: What Happens When AI Agents Start Networking 06.02.2026 41p
    In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the rapid advancements in AI and their impact on society. Follow AI ...
  • The Walking Dead of Security: When AI Resurrects the Build vs. Buy Debate 28.01.2026 40p
    Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and potentially reviving the DIY coding culture of pre-open-source days. We also talk about how developers trained on open source are now leveraging AI built from that same foundation, raising questions about innovation and originality in modern programming....

Népszerű itt:

Ez a podcast ezeknek az országoknak a podcast-listáin is szerepel.