Skip to content
Artwork for AI Security Table

AI Security Table

Izar Tarandach, Matt Coles, and Chris Romeo

AI Security Table is a candid roundtable podcast with Chris Romeo, Izar Tarandach, and Matt Coles about securing AI systems and how AI changes software security.

We debate AI agents, secure development, threat modeling, emerging attacks, and the decisions security teams face as AI becomes part of everyday work.

Formerly The Security Table. Same hosts, same conversations, a sharper focus on AI security. The full episode archive remains available.

AI security. On the table.
https://securitytable.ai

Play
  • 25 episodes
  • Avg 42 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S4 · E22
    Wednesday · 41 min

    There Is Determinism, Non-Determinism, and My Determinism

    The Security Table is now the AI Security Table, and the first order of business is naming the AI that gets a seat at it. Then Matt asks what a security engineer actually does once agents are writing the code: real security work, or bot herding? Chris Romeo, Izar Tarandach, and Matt Coles detour through who owns AI generated code and what a patent is worth when a model can rebuild your product in five minutes, then dig into agent identity, SPIFFE, least privilege, and whether access control belongs inside the agent harness itself. Izar argues that guardrails living in the context window are suggestions, not isolation, and that anyone who says AI changed their whole job overnight was putting the weight in the wrong place. It all ends on determinism: run the model once and you get one answer, run it again and you get another. Which leaves three kinds: determinism, nondeterminism, and my determinism. Mentioned in this Episode: ➜ Generative Artificial Intelligence and Copyright Law (CRS Legal Sidebar) ➜ SPIFFE: Secure Production Identity Framework for Everyone Chapters: 00:00:00 - Cold Open: We Are Broadcasters 00:01:06 - A New Name: The AI Security Table 00:02:17 - Naming the AI at the Table 00:03:02 - Stickers, T Shirts, and the Rebrand 00:03:49 - Matt's Setup: Security Engineers or Bot Herders? 00:04:54 - Does Claude Code Write All the Code Now? 00:05:34 - Who Owns AI Generated Code? 00:08:27 - Who Bothers to Steal Code Anymore? 00:08:47 - What's the Point of Patents? 00:11:33 - What the Law Says About AI Authorship 00:12:24 - Hallucinating: 200 Subagents at Once 00:13:34 - Back on Topic: Bots vs. Agents 00:14:18 - Agents Inherit Human Identity 00:14:49 - SPIFFE and Identity at Scale 00:16:35 - Treat Agents Like Bob From Marketing? 00:17:40 - Why? Why? The Five Whys 00:18:48 - Cryptographic Identity for Agents 00:19:37 - Authority Is Always Derived 00:20:59 - Least Privilege: Agents Request Access 00:21:26 - Read, Interpret, Act: Fine Grained Capabilities 00:24:22 - Access Control Inside the Agent Harness 00:26:17 - I Don't Trust the Box: Sandbox Escapes 00:27:34 - Pulling a Maestro: Guardrails vs. Isolation 00:29:43 - What Should Security Engineers Be Doing? 00:30:38 - Is AI Just a Layer Seven Application? 00:31:34 - Pull the Plug: 2001 and WarGames 00:33:29 - Your Job Didn't Change Overnight 00:34:37 - LLM Code Review and the Determinism Problem 00:35:44 - How Many Runs to Get the Circle? 00:38:16 - The Tightest Box Possible 00:39:09 - Twenty Thousand Feet to the Magnifying Glass 00:39:47 - Give Scanning Agents a Threat Model 00:40:32 - There Is My Determinism 00:41:09 - Outro Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E21
    September 30 · 42 min

    When AI Controls The Hardware

    Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has worked on robotics projects, says a common control standard is decades overdue. Izar calls it the PCI for AI, reminds everyone how secure MCP was on day one, and brings up Therac 25 as a warning about what happens when software controls hardware and fails silently. Then the table turns to the new open letter on collective cyber defense, signed by more than 100 organizations, and asks whether a pledge with no accountability means anything at all. Plus: the birth of the Brockman effect. Mentioned in this Episode: ➜ Previewing the Model Hardware Standard ➜ A call for collective action on cyber defense Chapters: 00:00:00 - Cold Open: Hail Mary and a Cease and Desist 00:01:05 - Coding With Agents: Make No Mistakes 00:01:41 - The Ten Commandments for C Programmers 00:03:14 - Two Topics: The Letter or the Standard 00:03:34 - Article Intro: Anthropic's Model Hardware Standard 00:04:32 - Matt's Case: We Should Have Done This Sooner 00:05:59 - Izar's Rebuttal: This Is How You Get Skynet 00:07:05 - Which Devices Should AI Be Allowed to Control? 00:07:46 - MCP, USB, and a Changed Threat Model 00:10:04 - Bad Sci Fi Has Something to Teach Us 00:10:32 - Who Owns the Robotic Arm's Safety Limits? 00:12:33 - Microscopes in a Box 00:14:34 - Onboard Models and Agent to Agent Control 00:15:11 - Self Driving Cars and Maximum Overdrive 00:16:26 - Therac 25: When Limits Fail Silently 00:18:50 - Closing Statements on the Standard 00:19:21 - Article Intro: The Open Letter on Cyber Defense 00:21:37 - Izar's Take: The Dealer Says Drugs Are Bad 00:24:17 - Matt's Case: A Public Commitment Still Counts 00:25:59 - Breaking Down the Letter's Asks 00:28:32 - Companies Do Things to Make Money 00:29:51 - What's Wrong With Signing a Letter? 00:33:52 - Where's the Threat Model? 00:34:37 - Matt Switches Sides 00:38:07 - How Many Signers Sell Security? 00:38:52 - Chris Signs the Letter (Not Really) 00:39:33 - Naming It: The Brockman Effect 00:41:11 - Outro Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E20
    September 23 · 36 min

    When Code No Longer Matters

    If AI can turn a request directly into instructions a chip understands, what is left for a human to review? Chris Romeo, Izar Tarandach, and Matt Coles debate whether readable source code remains essential when agents do the programming. Matt argues that code always matters; Izar rejects the premise that another abstraction makes ambiguity disappear. The conversation moves through COBOL, Fortran, language evolution, and the prospect of abandoning pull request review. They also consider optimization, no-code applications, and the role of APIs when software is generated on demand. Beneath the disagreement is a practical security question: if nobody writes the code and nobody understands the implementation, who takes responsibility when the system breaks? Mentioned in this Episode: ➜ Fortran — GNU project reference ➜ COBOL — GnuCOBOL project reference Chapters: 00:00:00 - Intro 00:00:09 - Cold Open: Shirts and Knives Out 00:01:14 - Printer Wars and PC LOAD LETTER 00:02:22 - PostScript, LaTeX, and Font Substitution 00:05:11 - Vintage Macs and Sun Workstations 00:09:07 - Blinking Lights and Bragging Rights 00:10:07 - Article Intro: When Code No Longer Matters 00:12:31 - Matt's Case: Code Always Matters 00:14:11 - Izar's Rebuttal: Stupidest Thing I've Heard 00:17:03 - Language Evolution and Ambiguity 00:21:26 - Giving Up on PR Review? 00:23:01 - Compute, Optimization, and the AGI Tangent 00:28:53 - No Code Apps in the AI Era 00:32:39 - No Code vs APIs 00:34:05 - Matrix Jokes and Debate Wrap 00:35:03 - Closing Thoughts 00:35:24 - Outro: Subscribe and Rate Us Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E19
    September 16 · 39 min

    Why AI Cheats To Win

    An AI agent publishes a malicious Python package while chasing a capture-the-flag goal. Is that an escape, a supply chain failure, or reward hacking doing exactly what it was encouraged to do? Chris Romeo, Izar Tarandach, and Matt Coles examine the Anthropic incident and disagree about how much intention to attribute to a model. The discussion turns to package scanners, dependency names, GPG signing, and whether penalties can teach ethics to a system without a human understanding of consequences. The trolley problem, robotaxis, and Nick Bostrom's paperclip maximizer push the argument further: what does it mean to trust an agent whose definition of success may conflict with everyone else's? Mentioned in this Episode: ➜ Here’s why AI agents lie and cheat to reach their goals ➜ PyPI: the Python Package Index ➜ GnuPG (GPG) Chapters: 00:00:00 - Cold open 00:01:03 - The Claude PiPie incident: a model that thought it was in a sandbox 00:02:10 - Did the model actually "break out"? 00:04:17 - Reasoning vs. motivation: does AI actually want anything? 00:08:10 - The real failure: package scanners, not the model 00:09:19 - The "IsOdd" experiment and trusting package names 00:11:33 - Would signing packages even stop this? 00:15:36 - The MIT Tech Review piece on reward hacking 00:17:22 - Can you actually inject ethics into a model? 00:20:49 - Teaching ethics without a concept of penalty 00:29:03 - Trolley problem: just make the model answer 00:29:51 - Would you let an LLM drive a robotaxi? 00:33:45 - The paperclip maximizer and the grey goo problem 00:36:57 - Wrap up Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E18
    September 9 · 49 min

    When AI Escapes the Sandbox

    When a model crosses a sandbox boundary, is the lesson that AI has become malicious or that the boundary was never strong enough? Chris Romeo, Izar Tarandach, and Matt Coles examine the CSA post-mortem on the OpenAI agents that compromised Hugging Face during a security evaluation. They debate reward-driven behavior, disabled safeguards, the four-day intrusion timeline, and the responsibility of the people running the experiment. The discussion moves from cyber ranges and incident response to deception tools, network isolation, and controls that limit what an agent can actually do. The recurring question is practical: how do you translate a threat model into enforced permissions instead of relying on instructions to behave? Mentioned in this Episode: ➜ CSA: Hugging Face Incident Initial Post-Mortem Chapters: 00:00:00 - Intro and musical detours 00:04:01 - The Hugging Face incident post-mortem 00:08:36 - Skynet panic versus security analysis 00:12:15 - The four-day intrusion timeline 00:13:20 - Disabled safeguards and sandbox connectivity 00:17:04 - What actually failed? 00:20:10 - Designing a realistic cyber range 00:24:26 - Reduce agency instead of trusting prompts 00:28:02 - Who is responsible for an agent? 00:32:01 - Threat modeling and external controls 00:33:27 - Incident response and visibility 00:36:01 - Deception tools and defensive prompt injection 00:37:25 - Implementing the threat model 00:41:40 - Research versus production 00:43:12 - A chatbot with constrained database permissions 00:45:15 - Controls and security fundamentals Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E17
    August 5 · 42 min

    The End of Bug Bounty As We Know It

    If AI can find and validate vulnerabilities faster than people, why would a company keep paying outsiders to report them? Chris Romeo, Izar Tarandach, and Matt Coles start with Linus Torvalds' changing assessment of AI-generated Linux kernel reports, then examine what useful automation does to the bug bounty economy. They debate disclosure incentives, model restrictions that may constrain defenders more than attackers, and the cost of separating real findings from a flood of submissions. Bugcrowd's reported increase in volume brings the pressure on triage into focus. The conversation asks whether AI validation becomes mandatory, whether internal agents displace public programs, and what remains valuable about human research when both sides can automate the hunt. Mentioned in this Episode: ➜ Bugcrowd ➜ The Linux Kernel Archives Chapters: 00:00:00 - Intro and book-writing detours 00:07:16 - Linus Torvalds and AI-generated reports 00:12:06 - When AI bug reports become useful 00:16:16 - Shorter experimentation loops 00:20:06 - Guardrails for defenders and attackers 00:24:00 - Model costs and provider monitoring 00:28:13 - Does AI spell the end of bug bounty? 00:32:01 - Validating the flood of reports 00:35:25 - Bugcrowd submission volume 00:36:18 - Linux kernel review still matters 00:38:21 - AI books and simulated personalities 00:39:52 - Wrap-up Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E16
    July 22 · 43 min

    Make No Mistakes: Inside the First "Agentic Ransomware"

    Does adaptive malware prove an LLM is directing an attack, or can a capable script produce the same evidence? Chris Romeo, Izar Tarandach, and Matt Coles examine Sysdig's JADEPUFFER report and its claim of agentic ransomware. They work through the proposed indicators, including self-narrating payloads, rapid failure diagnosis, interpretation of natural-language context, and a reused Bitcoin address. The debate distinguishes plausible autonomy from proof and asks whether machine-speed adaptation changes how defenders describe their attackers. Beneath the argument about agency is a familiar exposure: an unpatched Langflow vulnerability. The hosts return to threat modeling, patching, and the danger of treating an old security failure as a completely new problem just because AI is involved. Mentioned in this Episode: ➜ Sysdig: JADEPUFFER — Agentic ransomware for automated database extortion Chapters: 00:00:00 - Intro: AI as automated attacker 00:00:54 - What makes ransomware agentic? 00:04:09 - Adaptive agent or branching script? 00:08:25 - Walking through the database exploit 00:11:32 - Does this change the threat model? 00:16:12 - Evidence one: self-narrating code 00:20:27 - Evidence two: failure diagnosis and correction 00:26:20 - Evidence three: natural-language context 00:28:08 - Evidence four: the payment address 00:32:04 - Repeatable behavior and model defaults 00:36:02 - Patching and compatibility tradeoffs 00:40:14 - Old scripts and new attackers 00:41:35 - The recurring lesson: patch 00:42:24 - Closing thoughts Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E15
    July 15 · 41 min

    Is Spec-Driven Development Already Dead

    Can a detailed specification make AI-generated software reliable, or does it simply move the ambiguity somewhere else? Chris Romeo, Izar Tarandach, and Matt Coles revisit spec-driven development and the promise that an agent can turn written intent into a correct implementation. They debate why earlier approaches struggled, whether natural language is enough, and how tests can fail when the same AI writes both the code and its checks. The conversation explores bounded models, the Phoenix idea of regenerating disposable code, and the choice between patching a defect and rebuilding from the specification. The security question remains: if an architectural flaw survives in the spec, what stops every new implementation from reproducing it? Mentioned in this Episode: ➜ React Chapters: 00:00:00 - Intro: travel and movie reviews 00:07:23 - What is spec-driven development? 00:12:46 - Repeatability and implementation variation 00:14:50 - How do you verify generated code? 00:16:10 - Test-driven development and weak AI tests 00:20:07 - Engineering discipline and historical specs 00:24:36 - Bounding a model for a specific ecosystem 00:27:37 - Is spec-driven development already dead? 00:28:27 - Ephemeral code and the Phoenix idea 00:29:12 - Patch the bug or regenerate the application? 00:32:43 - Who is the better developer? 00:33:54 - What you want versus what you asked for 00:40:05 - Final thoughts Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E14
    July 1 · 59 min

    Don't Bury the Model T: Why STRIDE Still Drives in an AI World

    Do AI systems require a new threat-modeling method, or are we abandoning useful tools before understanding their limits? Chris Romeo, Izar Tarandach, and Matt Coles first examine npm's move toward safer install defaults and the risk that agents trained on older behavior will simply re-enable dangerous options. Then they debate the claim that STRIDE belongs to a world that no longer exists. The discussion separates threat categories from modeling techniques, non-deterministic model behavior from deterministic controls, and unfamiliar failures from familiar security responsibilities. The Model T analogy gives both sides something to argue with: an older framework may need adaptation, but declaring it obsolete does not explain how the replacement improves the analysis. Mentioned in this Episode: ➜ npm install documentation ➜ Microsoft Threat Modeling Tool: STRIDE threats Chapters: 00:00:00 - Intro: deterministic fans 00:01:32 - npm and secure install defaults 00:03:22 - Will AI agents re-enable risky behavior? 00:05:35 - Other package managers and safe defaults 00:10:02 - Checking packages and internal repositories 00:15:26 - Let's Encrypt and code-signing certificates 00:20:04 - Install scripts and compatibility 00:25:05 - The search for the wheat color 00:27:34 - Was STRIDE built for a vanished world? 00:30:04 - Threat categories and modeling methods 00:35:19 - Non-deterministic AI and deterministic controls 00:40:15 - Hallucination and cross-context failures 00:45:04 - STRIDE and the Model T analogy 00:50:34 - Tracing code versus explaining model behavior 00:55:46 - Closing assessment Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E13
    June 24 · 42 min

    Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World

    Is DAST disappearing, or is AI penetration testing giving its underlying techniques a new market? Chris Romeo, Izar Tarandach, and Matt Coles trace dynamic application security testing from network scanners and open source tools to commercial products, then debate where scanning ends and adaptive testing begins. They question whether a tool that finds many issues serves the same purpose as a tester who follows an exploit chain. AI-generated findings raise another problem: what happens when scanner errors combine with model uncertainty? The discussion considers gray-box context, zero-day discovery, and the difference between a technology's usefulness and the business built around it. Along the way, cats perform an unforgettable version of The Final Countdown. Mentioned in this Episode: ➜ Nmap ➜ OWASP Benchmark Chapters: 00:00:00 - Intro and movie detours 00:03:14 - The Final Countdown and the return of DAST 00:05:05 - What do we mean by AI penetration testing? 00:08:02 - The case for DAST becoming stronger 00:10:30 - From open source scanners to a market 00:12:01 - Nmap, misconfiguration, and testing goals 00:16:20 - Where does DAST end and AI testing begin? 00:20:22 - DAST technology versus penetration testing 00:24:14 - Finding many issues versus serious exploit paths 00:28:03 - Definitions and adaptiveness 00:30:47 - Compounding scanner errors and AI uncertainty 00:34:30 - Gray-box context and finding zero days 00:35:38 - Can AI find something nobody has seen? 00:40:10 - Separating the technology from its market Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E12
    June 17 · 37 min

    Realists At The Table: How To See Through The Hype

    Has cybersecurity traded curiosity for the promise of a paycheck, or are experienced practitioners simply seeing another generation's version of the same hype? Chris Romeo, Izar Tarandach, and Matt Coles examine the industry's changing stereotypes, from hoodie-clad specialists to ambitious founders. Mainframes, cloud computing, AI, quantum, and NFTs provide examples of ideas that return wearing new labels. The Cuckoo's Egg and hacker movies lead into a discussion of what made security feel like a community and whether broader adoption changes that appeal. They return to threat modeling, the search for shortcuts, and the garbage-in, garbage-out problem before asking whether AI has a personality worth taking seriously. Mentioned in this Episode: ➜ The Cuckoo's Egg — Cliff Stoll Chapters: 00:00:00 - Intro 00:00:56 - Cybersecurity stereotypes and trust 00:04:13 - Curiosity versus the paycheck 00:09:08 - Founders and the new stereotype 00:12:02 - Mainframes, cloud, and recurring hype cycles 00:16:28 - AI, quantum, blockchain, and NFTs 00:20:00 - The Cuckoo's Egg and security stories 00:24:03 - How hacker movies influenced practitioners 00:28:45 - Threat modeling moves beyond a niche 00:29:34 - The search for shortcuts 00:32:01 - Garbage in, garbage out 00:36:02 - AI personality and closing thoughts Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E11
    June 3 · 40 min

    The Agentic Access Problem: When AI Becomes Its Own Administrator

    In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why "because the agent told me to" may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt's unexpected habit of reading both. 🚀 Join the Conversation If your AI agent requested administrator access right now, would you know whether it actually needed it? Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E10
    May 8 · 42 min

    The Tool Creep Problem: When More Security Means Less Security

    In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in the gap between what agents are told to do and what they are actually capable of. At the end of the day, it comes back to fundamentals: define your agents' boundaries, limit their capabilities to only what they need, and stop confusing tool accumulation with security maturity. 🚀 Join the Conversation If your AI agent were compromised today, would you even know it was the agent and not you? Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E9
    April 30 · 47 min

    The Human In The Loop Illusion: Why AI Approvals Are Failing Security

    In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter. 🚀 Join the Conversation Are we improving security, or just automating bad decisions faster? Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E8
    April 15 · 47 min

    The Mythos Problem: When AI Finds Every Vulnerability

    In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them. We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agents everywhere—and whether fighting AI with more AI actually solves the problem. At the end of the day, it comes back to fundamentals: reduce your attack surface, simplify your systems, and focus on what actually matters. 🚀 Join the Conversation Is this a real shift in security—or just faster chaos? Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E7
    April 8 · 47 min

    What If AI Never Happened? The AppSec Reality Check

    In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, from “vibe coding” and false confidence in results to the growing gap between finding and fixing vulnerabilities. We also get into the tension between human-driven security practices and AI-assisted workflows, and whether the biggest challenges in AppSec are actually technical at all or still rooted in people and process. Plus, things take a turn as we let AI weigh in…and roast us a bit in the process. Per usual, it’s a mix of thoughtful discussion, strong opinions, and a little chaos. Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E6
    April 1 · 49 min

    The Evolution Problem: After 100 Episodes, What’s Changed… and What Hasn’t?

    We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never seem to go away. Along the way, we compare where we were then to where things stand now, calling out a few wins, a few misses, and everything in between. After all this time, are we actually any smarter, or just better at explaining the same problems? This episode is part reflection, part reality check, and a look at what 100 episodes have really taught us. Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E5
    March 25 · 48 min

    The Agent Access Problem: When AI Has the Keys, Who’s Really in Control?

    In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior driven by prompts, and why “it won’t go rogue” might be missing the point entirely. We also question the growing hype around AI governance, whether security teams are actually gaining control or just making more lists, and what happens when agents start talking to each other… and running up your bill. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “maybe just add parental controls.” Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E4
    March 20 · 36 min

    The Invisible Code Problem: When You Can’t See the Attack, Can You Stop It?

    In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whether this is a real emerging threat or just another overhyped security scare. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “just don’t do it. Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

  • S4 · E3
    February 6 · 41 min

    The Moltbook Dilemma: What Happens When AI Agents Start Networking

    In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the rapid advancements in AI and their impact on society. Follow AI Security Table: ➜ Home: https://securitytable.ai/ ➜ X: https://x.com/SecTablePodcast ➜ LinkedIn: https://www.linkedin.com/company/ai-security-table/ ➜ YouTube: https://www.youtube.com/@AISecurityTable

Showing 1–20 of 25 episodes